Live data from Hacker News

Open source projects could sell SBOM fragments

thomas-huehn.com

11–20 of 64 posts

Re: Open source projects could sell SBOM fragments

#12
post #2

This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?

For private usage no one gives a shit about SBOM, but for enterprise usage it's absolutely required.

Re: Open source projects could sell SBOM fragments

#16
post #2

This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?

For private usage no one gives a shit about SBOM, but for enterprise usage it's absolutely required.

Enterprise also doesn't really care. It is just another box to tick and an excel sheet to fill out, correctness isn't actually required. You just need something to put in the list, so you may as well purchase something wrong but authoritative-looking in bulk.

Re: Open source projects could sell SBOM fragments

#17
post #2

This doesn't make much sense to me. Why would someone want to pay each and every open source project to see the SBoM when they could pay a single provider or use an open source tool to get that info for all of their dependencies?

Right. A significant part of the reason open source wins so handily isn't that the money for a proprietary solution is always more than it's worth, it's that you can just pull open source dependencies without going through purchasing.

Exactly. Going from $0 purchase cost to $0.01 is a nearly impossible problem in many organizations. Paradoxically, they'll find a way to waste $100k on an "enterprise" stack to do the same though.

Re: Open source projects could sell SBOM fragments

#18
post #15

it could never work with corporate using micro transactions like that

Not yet, which is why OpenSSF is disbursing millions in small amounts, on behalf of large corporates, https://openssf.org/download-the-2024-openssf-annual-report/. But digital payments are progressing as slowly and steadily as SBOMs, so they could potentially converge in the future.

Re: Open source projects could sell SBOM fragments

#20
The providence of the SBOM is important. If you can't say "I made this" in reference to the SBOM then it's pretty much worthless.

Or, flip the script, if you're concerned enough about supply chain security to mandate an SBOM, you probably don't trust the supplier anyway.

There's the "but I signed it" crowd, but the wheels fall off when they've signed compromised artifacts too.

I just don't see a scenario where an SBOM that cannot be inspected and verified would be useful. If you have the infrastructure to do it, you're generating SBOMs anyway.

Post reply on HN