The sbomify Blog
Content for software, product, and digital security experts
Announcing sbomify v26.9.0: The One That Speaks SPDX 3
If you generate SBOMs from an embedded Linux build, you have probably had a version of this experience with us: the document uploads,...
Announcing sbomify-action v26.9.0: The One That Runs on Every CI
The action has always claimed to work on any CI system. That was true in the sense that it ran, and false in every sense that matters once...
The CRA Single Reporting Platform Opens Tomorrow: What ENISA Actually Requires
Tomorrow, the Cyber Resilience Act’s reporting obligations stop being a date on a slide. From 11 September 2026, manufacturers of...
Announcing sbomify v26.8.0: The One With Security Advisories
Most vulnerability tooling stops at the moment of discovery. You get a finding, a severity, maybe a fix version, and then you are on your...
Announcing sbomify-action v26.8.0: The One That Went on a Diet
The headline number in this release is that the container image went from 515MB to 106MB. That is the fun part. The part that should...
BSI TR-03183 Is Now Four Documents, and the CRA Clock Runs Out in Three Weeks
If you built your EU Cyber Resilience Act plan around a single BSI document, it is out of date. Not because the SBOM requirements changed,...
Announcing sbomify v26.7.1: The One That Says "Not Affected"
An SBOM tells you what is in your software. A vulnerability scanner tells you which of those components have known CVEs. Neither answers the...
ENISA's New Healthcare Procurement Guidelines Ask for SBOMs Without Saying the Word
In July 2026, the European Union Agency for Cybersecurity (ENISA) published its updated Procurement guidelines for the cybersecurity of...
Announcing sbomify v26.7.0: The One That Gets Quantum-Ready
Most of the SBOM world is focused on one question: what software am I shipping? v26.7.0 adds a second question that is about to matter a...
Announcing sbomify v26.3.0: The One That Ditches the Token
The headline of v26.3.0 is about getting rid of something: the long-lived API token sitting in your CI secrets. With GitHub Actions OIDC...
SPDX 3.0 in Yocto: What Changed and Why It Matters
SPDX 3.0 support was added in the Styhead release (Yocto 5.1) and represents a significant architectural leap. The implementation lives in...
Announcing sbomify v26.2.0: The One That Signs the DoC
In v26.1.0 we shipped the first half of the EU Cyber Resilience Act workflow: figuring out whether you are in scope, and what you need to...