The sbomify Blog

Content for software, product, and digital security experts

Announcing sbomify v26.9.0: The One That Speaks SPDX 3

If you generate SBOMs from an embedded Linux build, you have probably had a version of this experience with us: the document uploads,...

Viktor Petersson • Sep 24. 2026
Read more →

Announcing sbomify-action v26.9.0: The One That Runs on Every CI

The action has always claimed to work on any CI system. That was true in the sense that it ran, and false in every sense that matters once...

Viktor Petersson • Sep 24. 2026
Read more →

The CRA Single Reporting Platform Opens Tomorrow: What ENISA Actually Requires

Tomorrow, the Cyber Resilience Act’s reporting obligations stop being a date on a slide. From 11 September 2026, manufacturers of...

Cowboy Neil • Sep 10. 2026
Read more →

Announcing sbomify v26.8.0: The One With Security Advisories

Most vulnerability tooling stops at the moment of discovery. You get a finding, a severity, maybe a fix version, and then you are on your...

Viktor Petersson • Aug 25. 2026
Read more →

Announcing sbomify-action v26.8.0: The One That Went on a Diet

The headline number in this release is that the container image went from 515MB to 106MB. That is the fun part. The part that should...

Viktor Petersson • Aug 25. 2026
Read more →

BSI TR-03183 Is Now Four Documents, and the CRA Clock Runs Out in Three Weeks

If you built your EU Cyber Resilience Act plan around a single BSI document, it is out of date. Not because the SBOM requirements changed,...

Cowboy Neil • Aug 20. 2026
Read more →

Announcing sbomify v26.7.1: The One That Says "Not Affected"

An SBOM tells you what is in your software. A vulnerability scanner tells you which of those components have known CVEs. Neither answers the...

Viktor Petersson • Jul 30. 2026
Read more →

ENISA's New Healthcare Procurement Guidelines Ask for SBOMs Without Saying the Word

In July 2026, the European Union Agency for Cybersecurity (ENISA) published its updated Procurement guidelines for the cybersecurity of...

Cowboy Neil • Jul 23. 2026
Read more →

Announcing sbomify v26.7.0: The One That Gets Quantum-Ready

Most of the SBOM world is focused on one question: what software am I shipping? v26.7.0 adds a second question that is about to matter a...

Viktor Petersson • Jul 7. 2026
Read more →

Announcing sbomify v26.3.0: The One That Ditches the Token

The headline of v26.3.0 is about getting rid of something: the long-lived API token sitting in your CI secrets. With GitHub Actions OIDC...

Viktor Petersson • Jun 12. 2026
Read more →

SPDX 3.0 in Yocto: What Changed and Why It Matters

SPDX 3.0 support was added in the Styhead release (Yocto 5.1) and represents a significant architectural leap. The implementation lives in...

Joshua Watt • May 19. 2026
Read more →

Announcing sbomify v26.2.0: The One That Signs the DoC

In v26.1.0 we shipped the first half of the EU Cyber Resilience Act workflow: figuring out whether you are in scope, and what you need to...

Viktor Petersson • May 13. 2026
Read more →