Introducing KBOM – Kubernetes Bill of Materials
ID: cc1335c3-e2c8-54b3-9a83-246df00c8a34
STIX ID: report--cc1335c3-e2c8-54b3-9a83-246df00c8a34
Feed Name: Aqua Security Blog
This document introduces the Kubernetes Bill of Materials (KBOM), a manifest listing the components, versions, and images that compose a Kubernetes cluster (control plane, node components, and addons). It explains how KBOM differs from workload SBOMs, outlines Trivy's initial CycloneDX-based KBOM capability and passive discovery approach, compares it to proactive tools like kube-hunter, and discusses accuracy, testing across distributions, applicability to managed Kubernetes, and planned future enhancements for broader discovery and vulnerability matching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
