Component Quality in sbomqs: Moving Beyond Static Checks to Real Component Health

Hey SBOM community 👋 If you’ve been using sbomqs for a while, you know it does a solid job of telling you what’s in your SBOM, not just that fields exist, but what values they actually hold. Names, versions, licenses, suppliers, checksums, PURLs, CPEs — every field and its corresponding value, laid out right there in your SBOM. And when something’s missing? The score command returns a 0 score on it so you can’t miss it, while the list command shows you exactly which components are empty and which ones have real values. It’s a transparent, no-nonsense way to audit your SBOM’s contents. ...

May 19, 2026 Â· 11 min Â· 2244 words Â· Vivek Sahu

How OwnersBox Used the Interlynk SBOM Platform to Immediately Thwart the Shai-Hulud npm Attack

This blog post describes how OwnersBox quickly mitigated the threat of the “Shai-Hulud” npm supply chain attack in September 2025. The attack involved malicious packages that stole credentials and aggressively self-propagated.

October 27, 2025 Â· 3 min Â· 540 words Â· Cosimo Commisso