Software Bill of Materials (SBOM), offers improved transparency and supply chain security by providing a machine-readable inventory of software components used. With the rise in software supply chain attacks, the SBOM has attracted attention from both academia and industry. This paper presents a study on the practice of SBOM, based on the analysis of 4,786 GitHub discussions from 510 SBOM-related projects. Our study identifies key topics, challenges, and solutions associated with effective SBOM usage. We also highlight commonly used tools and frameworks for generating SBOMs, along with their respective strengths and limitations. Our research underscores the importance of SBOMs in software development and the need for their widespread adoption to enhance supply chain security. Additionally, the insights gained from our study can inform future research and development in this field.
翻译:软件物料清单(SBOM)通过提供机器可读的软件组件清单,提升了透明度与供应链安全性。随着软件供应链攻击的日益增多,SBOM引起了学术界与工业界的广泛关注。本文基于对510个SBOM相关项目中4,786条GitHub讨论的分析,对SBOM实践进行了研究。我们识别了有效使用SBOM的关键主题、挑战与解决方案,并重点介绍了生成SBOM的常用工具与框架及其各自的优势与局限性。本研究强调了SBOM在软件开发中的重要性,以及通过广泛采用SBOM以增强供应链安全性的必要性。此外,研究所得洞见可为该领域的未来研究与发展提供参考。