SBOM explained: CycloneDX, SPDX and VEX in practice
Learn what an SBOM is, how CycloneDX and SPDX differ, where VEX fits, which minimum elements matter and how to build a trustworthy CI/CD process.
All articles in the Software Supply Chain category on the Breachroad blog: analyses, guides and recommendations for businesses.
Learn what an SBOM is, how CycloneDX and SPDX differ, where VEX fits, which minimum elements matter and how to build a trustworthy CI/CD process.
AI found hundreds of potential flaws across major open-source projects, but triage, reproduction, safe patches and maintainer review remain essential.
Signing without key management (Sigstore) and verifiable build provenance (SLSA) are the new supply chain defense. We translate Fulcio, Rekor, cosign and SLSA levels.
Technical analysis of the March 2026 supply-chain wave: hijacked Trivy and KICS tags, LiteLLM .pth execution, axios, CI/CD secrets and recovery.
Book a free consultation. We'll talk about your infrastructure and real priorities.