Skip to content

Publishing SBOMs of webservers? #1415

Discussion options

You must be logged in to vote

@DrakezulsMinimalism I think you're describing a possible concern that SBOM is a roadmap to the attacker. Take a look at https://www.ntia.gov/files/ntia/publications/sbom_faq_-_20201116.pdf.

Publishing the SBOM to /.well-known/sbom helps consumers (organizations that use Dependency-Track), especially those organizations with multiple instances and versions of Dependency-Track deployed, as it provides a common URL in which to get the SBOM for their specific versions. This information is extremely useful to defenders.

The Dependency-Track project has published its SBOM for every release since v3.8. All SBOMs are available publicly from GitHub releases. https://github.com/DependencyTrack/dep…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by DrakezulsMinimalism
Comment options

You must be logged in to vote
1 reply
@stevespringett
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants