Why Are SBOMs Failing to Stop Supply Chain Attacks?
Sysdig, Thursday, September 24th, 2026
Sysdig examines why software bills of materials haven't stopped supply chain attacks despite their potential.
A software bill of materials (SBOM) functions like an ingredients list for software and, combined with signatures and attestations, could prevent most supply chain attacks.
Because modern software is built from chains of dependencies, a flaw in a small component like OpenSSL can become a global security risk.
Software attestations, structured data that can include SBOMs, vulnerability lists and origin information, can be signed by developers and repositories and verified against container image digests.
However, this verification only catches tampering after the fact and cannot detect a compromise of the repository or its signing keys themselves.