#SBOM
All CosmicBytez Labs articles tagged #SBOM, across news, security advisories, how-to guides, and projects.
- HOWTO
Software Bill of Materials (SBOM) Generation with Syft and Grype
Generate a complete inventory of every package, library, and dependency in your containers and codebases with Syft, then scan that inventory for known...
- News
Chainguard Surpasses 1 Billion Container Build Manifests With Factory 2.0
Chainguard doubled its build volume to over 1 billion manifests in six months, powered by an automated factory rebuilding images at scale.
- News
Chainguard Doubles Output to 1 Billion Build Manifests in Six Months
Chainguard's container image factory doubled its rebuild output from 500 million to over 1 billion manifests, driven by a new agentic pipeline.
- Project
Container Supply Chain Security: SBOMs and Keyless Signing with Syft, Grype, and Cosign
Build a CI pipeline that generates SBOMs with Syft, scans them for vulnerabilities with Grype, and signs container images keylessly with Cosign — closing...
- News
Growing Up The Hard Way: Open Source Security's Painful Maturation
Chainguard's essay argues that open source software has been forced into an overdue adulthood — from XZ Utils to the EU Cyber Resilience Act — and what...
- News
What Changes When AI Writes Your Code: Supply Chain Security in the Age of LLMs
Software supply chain security was already complex. Now that AI coding assistants are writing production code, security teams face new questions about...
- News
The State of Trusted Open Source Report: Key Findings for 2025
Chainguard's first-ever State of Trusted Open Source report reveals critical insights into open source consumption patterns across container images,...