
Author
Viktor Petersson
Serial entrepreneur and cybersecurity innovator, currently focused on shaping the future of software security and compliance. As the founder of sbomify, he simplifies Software Bill of Materials (SBOM) management, helping organizations navigate emerging cybersecurity regulations such as the Cyber Resilience Act (CRA). Viktor co-led the CISA SBOM Working Group on SBOM generation and is an invited expert to ECMA TC54. He shares insights and industry trends through his podcast, Nerding Out With Viktor.
Posts by Viktor Petersson
Trivy Compromise: How We Are Hardening sbomify-action
The last few weeks have been turbulent in the world of supply chain security. Perhaps the most high-profile compromise has been in Aqua...
SBOM Adoption on PyPI Is at 1.58%. We Can Do Better.
This wasn’t a research project. We were building TEA support into sbomify-action and wanted a way to pull in real SBOM data from a...
PEP 770: SBOMs Are Now a First-Class Citizen in Python Packages
Python now has an official standard for shipping SBOMs inside packages. PEP 770, authored by Seth Larson (Python Security...
Announcing sbomify-action v0.14: The One With Yocto
What started as github-action has outgrown its name. With v0.14, we are officially renaming the project to sbomify-action to reflect what it...
Why We're Bullish on TEA, And Why You Should Be Too
Imagine you’re standing in an electronics store, holding a product in your hand. Using a TEA app, you could automatically scan the...
Announcing sbomify v0.27: The One with TEA
We have been working towards this release for a while. sbomify v0.27 brings full Transparency Exchange API (TEA) support, SPDX 3.0...
Announcing sbomify v0.26: The One Where Bootstrap Moved Out
A Faster, More Accessible UI The first thing you will notice is that sbomify feels faster. Pages load more quickly, transitions are...
Announcing sbomify-action v0.13: The One Where We Go to FOSDEM
We timed the sbomify-action v0.13 release for FOSDEM 2026, where we presented on CRA-ready SBOM generation. FOSDEM 2026: CRA-Ready SBOMs...
Announcing sbomify v0.25: The One with Attestations
Software supply chain security is not just about knowing what is in your software. It is about proving that knowledge is authentic and has...
Announcing sbomify-action v0.11: The One Where They Go to PyPI
With v0.11, sbomify-action is no longer tied to your CI/CD pipeline. Install it anywhere with pip install sbomify-action and generate...
Announcing sbomify v0.24: The One with All the Plugins
Today marks a pivotal release for sbomify. With v0.24, we are laying the foundation for what will become a fully extensible, plugin-based...
FDA Medical Device SBOM Requirements: What the New Cybersecurity Guidance Means for Manufacturers
On June 27, 2025, the FDA issued updated guidance on “Cybersecurity in Medical Devices: Quality System Considerations and Content of...