A software bill of materials (SBOM) declares the inventory of components used to build a software artifact such as a software application - Wikipedia
Inventory of libraries used in software artifact
Scan for vulnerabilities
Scan for licenses of libraries
Linux Foundation’s Software Package Data Exchange (SPDX)
Anchore syft Aqua Security trivy docker-sbom BuildKit >=0.11.0-rc1 Kubernetes bom Microsoft sbom-tool
Anchore grype Aqua Security trivy
docker-setup --tags=sbom plan
SBoM generation
SBoM scanning