Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialI'm gonna see a branch of a tree, I'm gonna see a boat on a lake, but I'm not gonna see the whole landscape, all the things around it. And that's what you have to think about with SBOMs. A satellite above the earth, looking at the whole picture, shifting up in terms of not the complexity, but the completeness of the program itself.
The binoculars are looking at a small piece, which is very similar to a lot of the SBOMs that are being created out there where let's just say you have open source code. And you have an SCA solution. That SCA solution, here let me get my prop back, is going to just basically stare down that open source code.
It's not looking at the first party code, the code you're developing, or the dependencies, or the third party packages and libraries you're including in your application. If you're using that type of approach, you're using binoculars, you're not using a satellite above the whole ecosystem. That way you have full risk.
Cuz last thing we want to do is work busy, work harder to basically create a bunch of SBOMs on a specific component of an application or a compiled package, whatever that is, and then have to put 'em all together. And you may miss something in the copy pasting, formatting, whatever it is. An SBOM needs to be the entire package inclusive of all the things.
It needs to be the satellite above the planet, looking down on the components to provide a Cyclone DX and SPDX, or other industry format for SBOMs. Food for thought. Hope you like the props. I'm Matt Rose. This is ReversingGlass. Thanks for joining.

