<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Posts on SBOM Insights</title>
    <link>https://sbom-insights.dev/posts/</link>
    <description>Recent content in Posts on SBOM Insights</description>
    <image>
      <title>SBOM Insights</title>
      <url>https://sbom-insights.dev/apple-touch-icon.png</url>
      <link>https://sbom-insights.dev/apple-touch-icon.png</link>
    </image>
    <generator>Hugo -- 0.150.0</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 26 Mar 2026 22:17:11 +0530</lastBuildDate>
    <atom:link href="https://sbom-insights.dev/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SBOM Compliance Series (Part 4): Understanding BSI TR-03183-2 v2.0, 🇩🇪 Germany Compliance</title>
      <link>https://sbom-insights.dev/posts/bsi-tr-03183-v2.0-compliance/</link>
      <pubDate>Wed, 25 Mar 2026 10:00:00 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/bsi-tr-03183-v2.0-compliance/</guid>
      <description>Understand BSI TR-03183-2 v2.0, Germany SBOM compliance framework. Learn its required, additional, and optional fields, why they exist, and how to validate your SBOM using sbomqs.</description>
    </item>
    <item>
      <title>SBOM Compliance Series (Part 3): Understanding BSI TR-03183-2 v1.1, Germany Compliance</title>
      <link>https://sbom-insights.dev/posts/bsi-tr-03183-v1.1-compliance/</link>
      <pubDate>Mon, 23 Mar 2026 10:00:00 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/bsi-tr-03183-v1.1-compliance/</guid>
      <description>Understand BSI TR-03183-2 v1.1, Germany SBOM compliance framework. Learn its required and additional fields, why they exist, and how to validate your SBOM using sbomqs.</description>
    </item>
    <item>
      <title>SBOM Compliance Series (Part 2): Understanding Framing Software Component Transparency (FSCT)</title>
      <link>https://sbom-insights.dev/posts/fsct/</link>
      <pubDate>Mon, 09 Feb 2026 18:38:10 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/fsct/</guid>
      <description>Learn how FSCT (Framing Software Component Transparency) goes beyond NTIA minimum elements to measure SBOM completeness, declaration quality, and trust.</description>
    </item>
    <item>
      <title>SBOM Compliance Series (Part 1): Understanding NTIA Minimum Elements</title>
      <link>https://sbom-insights.dev/posts/ntia-minimum-elements-2021-compliance/</link>
      <pubDate>Wed, 28 Jan 2026 22:50:46 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/ntia-minimum-elements-2021-compliance/</guid>
      <description>Understand NTIA minimum elements for SBOM compliance. Learn the required fields, why they matter, and how to check if your SBOM meets the standard.</description>
    </item>
    <item>
      <title>Stop Comparing CVE Counts: How SBOM deltas explain upstream vs hardened image security</title>
      <link>https://sbom-insights.dev/posts/upstream-vs-hardened-image-cves-why-numbers-dont-match/</link>
      <pubDate>Thu, 11 Dec 2025 23:10:15 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/upstream-vs-hardened-image-cves-why-numbers-dont-match/</guid>
      <description>Why do CVE counts differ between upstream and hardened container images? Use SBOM deltas to understand what packages changed, not just vulnerability numbers.</description>
    </item>
    <item>
      <title>sbomqs:v1.x.x Vs sbomqs:v2.x.x: What Changed?</title>
      <link>https://sbom-insights.dev/posts/sbomqs-v1-vs-sbomqs-v2-highlights/</link>
      <pubDate>Sat, 29 Nov 2025 14:40:15 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/sbomqs-v1-vs-sbomqs-v2-highlights/</guid>
      <description>Compare sbomqs v1 and v2 scoring models. See what changed in the new release, from separated compliance checks to a cleaner quality scoring approach.</description>
    </item>
    <item>
      <title>SBOM scoring into the Dependency-Track</title>
      <link>https://sbom-insights.dev/posts/sbomqs_scoring_dtrack_sbom/</link>
      <pubDate>Tue, 25 Nov 2025 14:40:15 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/sbomqs_scoring_dtrack_sbom/</guid>
      <description>Score SBOM quality directly within Dependency-Track using sbomqs. Ensure your SBOMs are complete and accurate before feeding them to your SBOM platform.</description>
    </item>
    <item>
      <title>Why SBOMs Are Becoming Essential for QA in Regulated Industries - Part 1</title>
      <link>https://sbom-insights.dev/posts/why-sboms-are-becoming-essential-for-qa-in-regulated-industries/</link>
      <pubDate>Sun, 16 Nov 2025 10:08:14 -0800</pubDate>
      <guid>https://sbom-insights.dev/posts/why-sboms-are-becoming-essential-for-qa-in-regulated-industries/</guid>
      <description>A concise guide for QA leads in regulated industries on how SBOMs strengthen software quality, compliance, and risk management across the SDLC.</description>
    </item>
    <item>
      <title>OWASP A03:2025: Why Supply Chain Security Is Now Ranked #3 (and What Operators Must Do)</title>
      <link>https://sbom-insights.dev/posts/supply-chain-security-voted-a-top-concern-in-2025/</link>
      <pubDate>Tue, 11 Nov 2025 19:47:27 -0800</pubDate>
      <guid>https://sbom-insights.dev/posts/supply-chain-security-voted-a-top-concern-in-2025/</guid>
      <description>OWASP ranked software supply chain failures as the #3 risk in 2025. Learn why operators must act now with SBOMs, CI/CD hardening, and dependency controls.</description>
    </item>
    <item>
      <title>SBOM Generator Recommendations and Workflows</title>
      <link>https://sbom-insights.dev/posts/sbom-generator-recommendations-and-workflows/</link>
      <pubDate>Wed, 05 Nov 2025 11:23:58 -0800</pubDate>
      <guid>https://sbom-insights.dev/posts/sbom-generator-recommendations-and-workflows/</guid>
      <description>This guide helps you choose the right SBOM (Software Bill of Materials) generator for your project based on your technology stack and requirements</description>
    </item>
    <item>
      <title>How OwnersBox Used the Interlynk SBOM Platform to Immediately Thwart the Shai-Hulud npm Attack</title>
      <link>https://sbom-insights.dev/posts/how_ownersbox_used_the_interlynk_sbom_platform_to_immediately_thwart_the_shai_hulud_npm_attack/</link>
      <pubDate>Mon, 27 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://sbom-insights.dev/posts/how_ownersbox_used_the_interlynk_sbom_platform_to_immediately_thwart_the_shai_hulud_npm_attack/</guid>
      <description>How OwnersBox used the Interlynk SBOM platform to detect and mitigate the Shai-Hulud npm supply chain attack within hours of its discovery in September 2025.</description>
    </item>
    <item>
      <title>Interlynk&#39;s Response to CISA&#39;s 2025 SBOM Minimum Elements Request for Comments</title>
      <link>https://sbom-insights.dev/posts/interlynk-feedback-2025-cisa-minimum-element-for-sbom/</link>
      <pubDate>Mon, 29 Sep 2025 10:24:57 -0700</pubDate>
      <guid>https://sbom-insights.dev/posts/interlynk-feedback-2025-cisa-minimum-element-for-sbom/</guid>
      <description>Interlynk&amp;#39;s formal response to CISA&amp;#39;s request for public comments on the 2025 Minimum Elements for a Software Bill of Materials (SBOM)</description>
    </item>
    <item>
      <title>sbomqs and SBOM Policies: Turning Transparency Into Action</title>
      <link>https://sbom-insights.dev/posts/sbomqs-sbom-policies-turning-transparency-into-action/</link>
      <pubDate>Tue, 23 Sep 2025 17:36:55 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/sbomqs-sbom-policies-turning-transparency-into-action/</guid>
      <description>Turn SBOM transparency into action with sbomqs policies. Define rules for licenses, vulnerabilities, and suppliers to automate supply chain risk decisions.</description>
    </item>
    <item>
      <title>sbomasm Enriches Licenses Using ClearlyDefined Datasets</title>
      <link>https://sbom-insights.dev/posts/sbomasm-enriches-licenses-using-clearlydefined-datasets/</link>
      <pubDate>Tue, 23 Sep 2025 17:12:44 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/sbomasm-enriches-licenses-using-clearlydefined-datasets/</guid>
      <description>Enrich SBOM license data automatically using sbomasm and ClearlyDefined datasets. Fill NOASSERTION gaps and boost SBOM quality at scale.</description>
    </item>
    <item>
      <title>Lean, Clean, and Compliance Ready: sbomasm&#39;s removal capabilities</title>
      <link>https://sbom-insights.dev/posts/lean-clean-and-compliance-ready-sbomasm-new-removal-capabilities/</link>
      <pubDate>Tue, 23 Sep 2025 17:01:06 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/lean-clean-and-compliance-ready-sbomasm-new-removal-capabilities/</guid>
      <description>Remove unwanted fields, components, and sensitive data from SBOMs using sbomasm. Keep your SBOM lean, private, and compliance-ready in SPDX or CycloneDX.</description>
    </item>
    <item>
      <title>sbomqs Scoring Support for BSI 1.1 and BSI 2.0 in a Summarized Way</title>
      <link>https://sbom-insights.dev/posts/sbomqs-scoring-support-for-bsi-1.1-and-bsi-2.0-in-a-summarized-way/</link>
      <pubDate>Tue, 23 Sep 2025 16:49:26 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/sbomqs-scoring-support-for-bsi-1.1-and-bsi-2.0-in-a-summarized-way/</guid>
      <description>sbomqs now supports BSI TR-03183 v1.1 and v2.0 compliance scoring alongside NTIA. Get a summarized SBOM quality scorecard across multiple frameworks.</description>
    </item>
    <item>
      <title>Monitoring External GitHub Repos for SBOMs</title>
      <link>https://sbom-insights.dev/posts/monitoring-external-github-repos-for-sboms/</link>
      <pubDate>Tue, 23 Sep 2025 16:39:52 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/monitoring-external-github-repos-for-sboms/</guid>
      <description>Monitor external GitHub repos for new SBOM releases with sbommv daemon mode. Automatically fetch and forward SBOMs from open-source dependencies.</description>
    </item>
    <item>
      <title>Modular SBOM Automation: Now With AWS S3 Support</title>
      <link>https://sbom-insights.dev/posts/modular-sbom-automation-now-with-aws-s3-support/</link>
      <pubDate>Tue, 23 Sep 2025 15:30:57 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/modular-sbom-automation-now-with-aws-s3-support/</guid>
      <description>sbommv now supports AWS S3 as both input and output for SBOM automation. Fetch, store, and move SBOMs between S3 buckets and security platforms seamlessly.</description>
    </item>
    <item>
      <title>What’s Missing in Your SBOM? sbomqs List Can Help You in Inspecting...</title>
      <link>https://sbom-insights.dev/posts/whats-missing-in-your-sbom-sbomqs-list-can-help/</link>
      <pubDate>Tue, 23 Sep 2025 15:19:04 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/whats-missing-in-your-sbom-sbomqs-list-can-help/</guid>
      <description>Use sbomqs list to inspect your SBOM against NTIA, BSI, and other compliance frameworks. Find exactly what fields are missing and fix them before sharing.</description>
    </item>
    <item>
      <title>Folder Monitoring: SBOM Automation That Never Sleeps</title>
      <link>https://sbom-insights.dev/posts/folder-monitoring-sbom-automation-that-never-sleeps/</link>
      <pubDate>Tue, 23 Sep 2025 14:40:15 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/folder-monitoring-sbom-automation-that-never-sleeps/</guid>
      <description>Automate SBOM workflows with sbommv folder monitoring. Detect, validate, and ship SBOMs to platforms like Dependency-Track in real time using daemon mode.</description>
    </item>
    <item>
      <title>GitHub Releases Are Where SBOMs Go to Die</title>
      <link>https://sbom-insights.dev/posts/github-releases-are-where-sboms-goto-die/</link>
      <pubDate>Tue, 23 Sep 2025 14:09:20 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/github-releases-are-where-sboms-goto-die/</guid>
      <description>SBOMs stuck in GitHub Releases slow down security teams. See how sbommv automates SBOM transfers to platforms like Dependency-Track seamlessly.</description>
    </item>
    <item>
      <title>What is an SBOM and Why is it Required?</title>
      <link>https://sbom-insights.dev/posts/what-is-sbom-why-required/</link>
      <pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://sbom-insights.dev/posts/what-is-sbom-why-required/</guid>
      <description>Understanding Software Bill of Materials (SBOM): What it is, why it is essential for modern software development, and how it enhances security and compliance</description>
    </item>
  </channel>
</rss>
