The sbomify Blog

Content for software, product, and digital security experts

Announcing sbomify v26.8.0: The One With Security Advisories

Most vulnerability tooling stops at the moment of discovery. You get a finding, a severity, maybe a fix version, and then you are on your...

Viktor Petersson Aug 25. 2026
Read more →

Announcing sbomify-action v26.8.0: The One That Went on a Diet

The headline number in this release is that the container image went from 515MB to 106MB. That is the fun part. The part that should...

Viktor Petersson Aug 25. 2026
Read more →

BSI TR-03183 Is Now Four Documents, and the CRA Clock Runs Out in Three Weeks

If you built your EU Cyber Resilience Act plan around a single BSI document, it is out of date. Not because the SBOM requirements changed,...

Cowboy Neil Aug 20. 2026
Read more →

Announcing sbomify v26.7.1: The One That Says "Not Affected"

An SBOM tells you what is in your software. A vulnerability scanner tells you which of those components have known CVEs. Neither answers the...

Viktor Petersson Jul 30. 2026
Read more →

ENISA's New Healthcare Procurement Guidelines Ask for SBOMs Without Saying the Word

In July 2026, the European Union Agency for Cybersecurity (ENISA) published its updated Procurement guidelines for the cybersecurity of...

Cowboy Neil Jul 23. 2026
Read more →

Announcing sbomify v26.7.0: The One That Gets Quantum-Ready

Most of the SBOM world is focused on one question: what software am I shipping? v26.7.0 adds a second question that is about to matter a...

Viktor Petersson Jul 7. 2026
Read more →

Announcing sbomify v26.3.0: The One That Ditches the Token

The headline of v26.3.0 is about getting rid of something: the long-lived API token sitting in your CI secrets. With GitHub Actions OIDC...

Viktor Petersson Jun 12. 2026
Read more →

SPDX 3.0 in Yocto: What Changed and Why It Matters

SPDX 3.0 support was added in the Styhead release (Yocto 5.1) and represents a significant architectural leap. The implementation lives in...

Joshua Watt May 19. 2026
Read more →

Announcing sbomify v26.2.0: The One That Signs the DoC

In v26.1.0 we shipped the first half of the EU Cyber Resilience Act workflow: figuring out whether you are in scope, and what you need to...

Viktor Petersson May 13. 2026
Read more →

A Deep Dive into Yocto's SPDX 2.2 Pipeline

The SPDX 2.2 implementation in the Yocto Project has been stable since the Honister release (Yocto 3.4, October 2021). It is the...

Joshua Watt May 12. 2026
Read more →

How Yocto Generates SBOMs Behind the Scenes: A Deep Dive into SPDX 2.2 and SPDX 3.0

If you are building embedded Linux products with the Yocto Project, you are sitting on one of the most mature and sophisticated SBOM...

Joshua Watt May 5. 2026
Read more →

Announcing sbomify v26.1.0: The One Where We Switch to CalVer

If you have been following along, you may have noticed the version number just made a fairly dramatic jump, going from v0.27 straight to...

Viktor Petersson Apr 2. 2026
Read more →