发表机构
Ritsumeikan University; Notre Dame Seishin University; The University of Fukuchiyama; Toshiba Corporation(立命馆大学; 圣母圣心女子大学; 福知山公立大学; 东芝株式会社)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
sbom-unifier是异构SBOM的集成框架,通过PURL识别组件等方法提升SBOM完整性,在90个开源项目上使SPDX 2.3字段完全覆盖率提8个百分点、缺失率降11个百分点。
AI 中文摘要
软件物料清单(SBOM)是一种机器可读的软件组件清单,越来越多地被要求用于漏洞管理和许可证合规性。然而,现有的SBOM生成工具常常会遗漏许多SPDX定义的字段或仅部分填充这些字段,因为不同工具会产生异构输出,且字段级覆盖情况参差不齐。我们提出了sbom-unifier,这是一个通过多工具输出的字段级集成与补充、以及文件级丰富来提高SBOM完整性的框架。与现有仅拼接SBOM而不识别指向同一组件记录的工具不同,sbom-unifier通过包URL(PURL)识别组件,采用确定性的基于优先级的策略补充缺失字段值,重建截面引用,并进一步丰富文件级字段。在9种编程语言的90个开源项目中,sbom-unifier对必填字段保持了高完整性;在39个SPDX 2.3必填和可选字段上,与各自表现最佳的单个工具相比,其完全覆盖比率提高了8个百分点,完全缺失比率降低了11个百分点。sbom-unifier可在此https URL获取。
英文摘要
A Software Bill of Materials (SBOM) is a machine-readable inventory of software components, increasingly required for vulnerability management and license compliance. However, existing SBOM generation tools often leave many SPDX-defined fields missing or only partially populated, because different tools produce heterogeneous outputs with uneven field-level coverage. We present sbom-unifier, a framework that improves SBOM completeness through field-level integration and complementation of multiple tool outputs and file-level enrichment. Unlike existing tools that simply concatenate SBOMs without identifying records referring to the same component, sbom-unifier identifies components via Package URL (PURL), complements missing field values by a deterministic priority-based strategy, reconstructs cross-section references, and further enriches file-level fields. Across 90 open-source projects in 9 programming languages, sbom-unifier preserves high completeness for required fields and, over the 39 SPDX 2.3 required and optional fields, raises the fully covered rate by 8 percentage points and reduces the totally missing rate by 11 percentage points over the respective best-performing individual tools. sbom-unifier is available at https://github.com/MoriwakiYusuke/sbom-unifier.
CommentsAccepted to ICSME 2026 Tool Demonstrations Track