Challenges of Producing Software Bill Of Materials for Java

Musard Balliu,Benoit Baudry,Sofia Bobadilla,Mathias Ekstedt,Martin Monperrus,Javier Ron,Aman Sharma,Gabriel Skoglund,César Soto-Valero,Martin Wittlinger
DOI: https://doi.org/10.1109/MSEC.2023.3302956
2023-06-08
Abstract:Software bills of materials (SBOM) promise to become the backbone of software supply chain hardening. We deep-dive into 6 tools and the accuracy of the SBOMs they produce for complex open-source Java projects. Our novel insights reveal some hard challenges for the accurate production and usage of SBOMs.
Software Engineering,Cryptography and Security
What problem does this paper attempt to address?