<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Sbom - Tag - vo.rs</title><link>https://vo.rs/tags/sbom/</link><description>Sbom - Tag - vo.rs</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.</copyright><lastBuildDate>Fri, 21 Nov 2025 07:00:00 +0000</lastBuildDate><atom:link href="https://vo.rs/tags/sbom/" rel="self" type="application/rss+xml"/><item><title>SBOM: Software Bill of Materials and Why You Should Care About Your Dependencies</title><link>https://vo.rs/story/sbom-software-bill-of-materials-and-why-you-should-care-about-your-dependencies/</link><description>&lt;p&gt;Every time a serious supply-chain vulnerability lands, the same scramble begins. Someone in a chat channel asks &amp;ldquo;are we affected?&amp;rdquo; and the honest answer, for most teams, is &amp;ldquo;give us a few days and we&amp;rsquo;ll tell you.&amp;rdquo; That few days is the gap an SBOM is meant to close. A Software Bill of Materials is just an inventory — a machine-readable list of every component that went into a build — but having one ready before the panic is the difference between an afternoon and a fortnight.&lt;/p&gt;</description><pubDate>Fri, 21 Nov 2025 07:00:00 +0000</pubDate></item></channel></rss>