BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software Systems
Trevor Stalnaker, Nathan Wintersgill, Oscar Chaparro, Massimiliano Di Penta, Daniel M. Germán, Denys Poshyvanyk
Abstract
Software Bills of Materials (SBOMs) have emerged as tools to facilitate the management of software dependencies, vulnerabilities, licenses, and the supply chain. While significant effort has been devoted to increasing SBOM awareness and developing SBOM formats and tools, recent studies have shown that SBOMs are still an early technology not yet adequately adopted in practice. Expanding on previous research, this paper reports a comprehensive study that investigates the current challenges stakeholders encounter when creating and using SBOMs. The study surveyed 138 practitioners belonging to five stakeholder groups (practitioners familiar with SBOMs, members of critical open source projects, AI/ML, cyberphysical systems, and legal practitioners) using differentiated questionnaires, and interviewed 8 survey respondents to gather further insights about their experience. We identified 12 major challenges facing the creation and use of SBOMs, including those related to the SBOM content, deficiencies in SBOM tools, SBOM maintenance and verification, and domain-specific challenges. We propose and discuss 4 actionable solutions to the identified challenges and present the major avenues for future research and development. CCS CONCEPTS • Software and its engineering → Software creation and management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 82e117c9-c534-46aa-95ae-5a28623159afCited by top-tier papers6
- "The Law Doesn't Work Like a Computer": Exploring Software Licensing Issues Faced by Legal PractitionersNathan Wintersgill, Trevor Stalnaker, Laura A. Heymann, Oscar Chaparro et al.FSE 2024 · 6 citations
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines et al.ICSE 2026 · 5 citations
- Trustworthy and Confidential SBOM ExchangeEman Abu Ishgair, Chinenye Okafor, Marcela S. Melara, Santiago Torres-AriasUSENIX Security 2026 · 1 citation
- Demystifying the Evolution of Neural Networks with BOM Analysis: Insights from a Large-Scale Study of 55,997 GitHub RepositoriesXiaoning Ren, Yuhang Ye, Xiongfei Wu, Yueming Wu et al.ASE 2025 · 1 citation
- JBomAudit: Assessing the Landscape, Compliance, and Security Implications of Java SBOMsYue Xiao, Dhilung Kirat, Douglas Lee Schales, Jiyong Jang et al.NDSS 2025
Builds on7
- Robust Speech Recognition via Large-Scale Weak SupervisionAlec Radford, Jong Wook Kim, Tao Xu, Greg Brockman et al.ICML 2023 · 6,966 citations
- Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSKai Chen, Xueqiang Wang, Yi Chen, Peng Wang et al.S&P 2016 · 111 citations
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu et al.ICSE 2023 · 82 citations
- Practical Automated Detection of Malicious npm PackagesAdriana Sejfia, Max SchäferICSE 2022 · 65 citations
- Towards Understanding Third-party Library Dependency in C/C++ EcosystemWei Tang, Zhengzi Xu, Chengwei Liu, Jiahui Wu et al.ASE 2022 · 64 citations
Related papers
- Software Architecture in Practice: Challenges and OpportunitiesZhiyuan Wan, Yun Zhang, Xin Xia, Yi Jiang et al.FSE 2023 · 29 citations
- An Industry Interview Study of Software Signing for Supply Chain SecurityKelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias et al.USENIX Security 2025
- Robotics software engineering: a perspective from the service robotics domainSergio García, Daniel Strüber, Davide Brugali, Thorsten Berger et al.FSE 2020 · 76 citations
- DeepSCA: Dependency-Aware Software Composition Analysis for C/C++ Based on a Curated Code Feature DatabaseMeiqiu Xu, Xibin Zhao, Wenxuan Yu, Zhiliang Zhu et al.ISSTA 2026
- Software Vulnerability Management in the Era of Artificial Intelligence: An Industry PerspectiveM. Mehdi Kholoosi, Triet Huynh Minh Le, M. Ali BabarICSE 2026
