logo

Why Using SCA to Build Your SBOMs is a Risky Proposition

ID: ad236454-2c32-5b02-83e7-42eac7bfc4ba

STIX ID: report--ad236454-2c32-5b02-83e7-42eac7bfc4ba

Feed Name: ReversingLabs Blog

Date Published: 2025-06-03

Date Updated: 2026-04-29

Author: Dan Petrillo

...
...

ReversingLabs' research finds that SBOMs produced from software manifests capture only ~49.91% of components in final packages, leaving developers and security teams blind to many dependencies, proprietary or commercial code, and late-stage additions; the report argues that manifest-based SCA is insufficient and advocates complex binary analysis (Spectra Assure) to generate complete SBOMs/xBOMs and detect vulnerabilities, malware, tampering, and other risks in shipped binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.