SPDX looks Flat. But can it really represent a Hierarchical SBOM?

Hey SBOM enthusiasts 馃憢, If you鈥檝e been working with SBOMs for a while, you already know that merging multiple SBOMs isn鈥檛 just about dumping all the components into one file. The real challenge is preserving the semantics meaning of each merge strategy. Are they dependencies? Are they sub-components of another component? Are they independent products being assembled together? Or are we simply trying to flatten everything into one unified component list? ...

August 25, 2026 路 9 min 路 1878 words 路 Vivek Sahu

Understanding SBOM Merge Strategies: A Complete Guide

Hey SBOM enthusiasts 馃憢, If your organization is dealing with multiple SBOMs and you鈥檙e wondering how to combine them into a single Unified SBOM Document, you鈥檙e not alone. Merging SBOMs sounds simple in theory, just combine the files, but in practice, it鈥檚 not that straightforward. One of the challenges is that those SBOMs can come from very different sources: platform-specific builds, multi-service architectures, microservices, or scan results that need enriching. Each source calls for a different way of merging. Without the right strategy, you end up with duplicate components, broken dependency chains, or SBOMs that simply don鈥檛 validate. ...

June 1, 2026 路 14 min 路 2980 words 路 Vivek Sahu