Comment by LoganDark

Comment by LoganDark 9 hours ago

1 reply

> what is it that SBOM is used for that lockfiles aren’t?

Compliance. The article mentions "the EU’s Cyber Resilience Act will push vendors toward providing SBOMs", and having package managers generate SBOMs directly would certainly be convenient for that.

jlubawy 8 hours ago

The FDA also requires SBOMs as of a few years ago for medical device software.