OpenSSF project
Protobom / SBOM Tools
A shared library and toolset for generating, translating, and consuming Software Bills of Materials in standard formats such as SPDX and CycloneDX.
How each persona uses Protobom / SBOM Tools
Software Developer / Maintainer Developer
Integrates SBOM generation tools into their local build process to automatically document the components used in their software.
Open Source Professional (OSPO) OSPO
Mandates the use of standard SBOM formats and tools like Protobom to maintain a comprehensive inventory of third-party software assets.
Security Engineer / Architect Security
Analyzes ingested SBOMs to rapidly identify and triage vulnerable components across the organization's application portfolio.
CI/CD DevOps & Tooling Integrator DevOps
Embeds Protobom into the automated release pipeline to seamlessly generate and attach SBOMs to every compiled artifact.
Package & Repository Manager Package Manager
Distributes generated Software Bill of Materials (SBOMs) alongside packages to provide consumers with a transparent component inventory.
Executive / End-User Consumer Executive
Demands SBOMs as trust signals to assess post-release risk and make informed consumption decisions.
Problems Protobom / SBOM Tools helps with
Dependency & SBOM Visibility Visibility
Generates and translates SBOMs in standard formats so the component inventory travels with the artefact.