Skip to main navigation Skip to search Skip to main content

Enhancing Visibility of Components and Dependencies Across Diverse IT Environments with Open-Source Software-Bill-of-Materials Generation Tools

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper explores the escalating adoption of Open-Source Software (OSS) and its implications on traditional software assets inventory practices. While OSS offers undeniable benefits in terms of flexibility and cost, it also introduces complexities, especially in managing intricate dependency structures within the software supply chain. In response to this, the concept of Software Bill of Materials (SBOM) is proposed as a potential solution, aiming to bring transparency by documenting software components and dependencies. This paper presents an empirical study that evaluates the effectiveness and efficiency of a set of SBOM generation tools across diverse IT infrastructures and software inventory tools. It highlights SBOM's tools advantages, such as discovering OSS components installed without reliance on OS package managers, and providing component dependencies' information. By addressing this, we aim to deepen the understanding of SBOM's significance in modern software management practices and provide insights for optimizing SBOM generation tools usage.

Original languageEnglish
Title of host publicationProceedings - 2024 12th International Conference in Software Engineering Research and Innovation, CONISOFT 2024
EditorsReyes Juarez-Ramirez, Carlos Alberto Fernandez y Fernandez, Samantha Paulina Jimenez Calleros, Alan Ramirez-Noriega, Cesar Arturo Guerra-Garcia, Guillermo Licea Sandoval, Maria Alejandra Menendez-Ortiz, Jorge Octavio Hernandez-Ocharan
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages165-174
Number of pages10
ISBN (Electronic)9798331532116
DOIs
Publication statusPublished - 2024
Event12th International Conference in Software Engineering Research and Innovation, CONISOFT 2024 - Puerto Escondido, Mexico
Duration: 28 Oct 20241 Nov 2024

Publication series

NameProceedings - 2024 12th International Conference in Software Engineering Research and Innovation, CONISOFT 2024

Conference

Conference12th International Conference in Software Engineering Research and Innovation, CONISOFT 2024
Country/TerritoryMexico
CityPuerto Escondido
Period28/10/241/11/24

Keywords

  • Open-Source Soft-ware
  • SBOM
  • Software Engineering
  • Software Inventory

Fingerprint

Dive into the research topics of 'Enhancing Visibility of Components and Dependencies Across Diverse IT Environments with Open-Source Software-Bill-of-Materials Generation Tools'. Together they form a unique fingerprint.

Cite this