From SBOMs to AI BOMs: Why SPDX 3.0 Matters

From SBOMs to AI BOMs: Why SPDX 3.0 Matters

Software bill of materials (SBOM) strategies are rapidly evolving. What began as a way to track open source components for compliance and vulnerability management is quickly expanding into something much larger: a ...
When AI Writes Code, Who Governs the Dependencies?

When AI Writes Code, Who Governs the Dependencies?

The Department of War'sCall for Solutions on AI-enabled coding capabilities (CDAO_26-01) arrives at exactly the right moment. Today's AI coding assistants have moved beyond experiments in productivity to becoming the basis for ...
Transforming Software Compliance with AI SBOM Management

Transforming Software Compliance with AI SBOM Management

If your software serves federal missions, you face twin pressures to move faster and prove exactly what's in your software ...
SBOM Manager New Features Accelerate Compliance and Security at Scale

SBOM Manager New Features Accelerate Compliance and Security at Scale

Effective management of software bills of materials (SBOMs) is now crucial for ensuring security, achieving compliance, and optimizing operational efficiency ...

SBOM Best Practices: What Global Leaders Are Asking and Doing

The software bill of materials (SBOM) drives the shift from compliance checkbox to cornerstone of modern software security, equipping organizations to navigate supply chain threats, evolving regulations, and the complexity of AI-generated ...
How SBOMs drive a smarter SCA strategy

How SBOMs drive a smarter SCA strategy

Modern software is largely assembled from open source components, constituting up to 90% of today's codebases. Managing the security and compliance risks associated with this external code is no longer optional — ...
Preparing for PCI DSS 4.0: How Sonatype SBOM Manager can streamline and accelerate your transition

Preparing for PCI DSS 4.0: How Sonatype SBOM Manager can streamline and accelerate your transition

Payment Card Industry Data Security Standard (PCI DSS) was developed to strengthen payment account data security and standardize globally the necessary security controls. The transition from PCI DSS 3.2.1 and earlier versions ...
Demystifying VEX: Simplifying SBOMs with Sonatype SBOM Manager

Demystifying VEX: Simplifying SBOMs with Sonatype SBOM Manager

Ever wondered what VEX really is and why it's crucial for your software supply chain? You're not alone ...
Securing your software supply chain with CISA's new SBOM guidance

Securing your software supply chain with CISA’s new SBOM guidance

With new and increasing cyber threats abound, navigating global software regulations and staying informed and compliant can seem like an unending task. To help mitigate risks within the software applications organizations use ...
A proactive defense: Utilize SBOMs and continuous monitoring

A proactive defense: Utilize SBOMs and continuous monitoring

Navigating the complexities of software supply chain security demands proactive measures to identify and manage vulnerabilities and compliance issues effectively ...