Why Using SCA to Build Your SBOMs is a Risky Proposition
ID: ad236454-2c32-5b02-83e7-42eac7bfc4ba
STIX ID: report--ad236454-2c32-5b02-83e7-42eac7bfc4ba
Feed Name: ReversingLabs Blog
ReversingLabs' research finds that SBOMs produced from software manifests capture only ~49.91% of components in final packages, leaving developers and security teams blind to many dependencies, proprietary or commercial code, and late-stage additions; the report argues that manifest-based SCA is insufficient and advocates complex binary analysis (Spectra Assure) to generate complete SBOMs/xBOMs and detect vulnerabilities, malware, tampering, and other risks in shipped binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
