注意差距:SBOM规范歧义如何导致软件物料清单的分歧——一项实证工具研究
Mind the Gap: How SBOM Specification Ambiguities Lead to Divergent Software Bills of Materials. An Empirical Tool Study
浏览论文内容
中文总结 AI 辅助
本研究通过评估三种SBOM生成器在3000多个项目上的表现,揭示其差异主要源于规范歧义而非实现错误,并呼吁未来标准明确依赖范围、来源和表示规则以提升合规性。
中文摘要 AI 辅助
根据欧洲《网络弹性法案》(CRA)[8],软件物料清单(SBOM)将从2027年12月起成为强制性要求。尽管先前的研究已指出SBOM生成器之间存在显著差异,但这些差异的原因仍不明确,也不清楚它们源于实现错误还是有意设计选择。在本文中,我们基于依赖锁文件构建的真实基线,评估了三种广泛使用的SBOM生成器,覆盖超过3000个JavaScript和Rust项目。结果表明,这些工具在依赖覆盖率和SBOM完整性方面存在分歧。重要的是,大多数差异是系统性的而非偶然的:它们源于对依赖范围、命名、来源和表示的不同假设,而其他差异则反映了对SBOM规范中定义字段支持的不一致。这些发现表明,许多观察到的差异无法简单“修复”:它们需要更清晰的标准。随着SBOM生成成为法律合规要求,工具本身的选择可能影响生成的SBOM,从而可能成为未检测到不合规的根源。我们认为,未来的SBOM标准应定义关于依赖范围、来源和表示的规范规则,以提高互操作性和合规性。
英文摘要
Software Bill of Materials (SBOMs) will become mandatory starting in December 2027 under the European Cyber Resilience Act (CRA) [8]. Although previous studies have highlighted significant differences among SBOM generators, the reasons for these discrepancies remain unknown, as does whether they stem from implementation errors or deliberate design choices. In this paper, we evaluate three widely used SBOM generators across more than 3,000 JavaScript and Rust projects, using a groundtruth baseline derived from dependency lockfiles. Our results show that these tools diverge in terms of both dependency coverage and SBOM completeness. Importantly, most of these discrepancies are systematic rather than accidental: they arise from differing assumptions regarding dependency scope, naming, provenance, and representation, while others reflect inconsistent support for fields defined in SBOM specifications. These findings demonstrate that many of the observed discrepancies cannot simply be ''fixed'': they require clearer standardization. As SBOM generation becomes a legal compliance requirement, the choice of tool itself can influence the resulting SBOM, potentially becoming a source of undetected non-compliance. We argue that future SBOM standards should define canonical rules regarding dependency scope, provenance, and representation to improve interoperability and compliance.
发表机构
- Univ. Rennes, Inria, CNRS, IRISA(雷恩大学、法国国家信息与自动化研究所、法国国家科学研究中心、IRISA)
机构由 AI 辅助整理,请以论文原文为准。