BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software Systems
Trevor Stalnaker, Nathan Wintersgill, Oscar Chaparro, Massimiliano Di Penta, Daniel M. Germán, Denys Poshyvanyk
摘要
Software Bills of Materials (SBOMs) have emerged as tools to facilitate the management of software dependencies, vulnerabilities, licenses, and the supply chain. While significant effort has been devoted to increasing SBOM awareness and developing SBOM formats and tools, recent studies have shown that SBOMs are still an early technology not yet adequately adopted in practice. Expanding on previous research, this paper reports a comprehensive study that investigates the current challenges stakeholders encounter when creating and using SBOMs. The study surveyed 138 practitioners belonging to five stakeholder groups (practitioners familiar with SBOMs, members of critical open source projects, AI/ML, cyberphysical systems, and legal practitioners) using differentiated questionnaires, and interviewed 8 survey respondents to gather further insights about their experience. We identified 12 major challenges facing the creation and use of SBOMs, including those related to the SBOM content, deficiencies in SBOM tools, SBOM maintenance and verification, and domain-specific challenges. We propose and discuss 4 actionable solutions to the identified challenges and present the major avenues for future research and development. CCS CONCEPTS • Software and its engineering → Software creation and management.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- "The Law Doesn't Work Like a Computer": Exploring Software Licensing Issues Faced by Legal PractitionersNathan Wintersgill, Trevor Stalnaker, Laura A. Heymann, Oscar Chaparro 等FSE 2024 · 被引用 6 次
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines 等ICSE 2026 · 被引用 5 次
- Trustworthy and Confidential SBOM ExchangeEman Abu Ishgair, Chinenye Okafor, Marcela S. Melara, Santiago Torres-AriasUSENIX Security 2026 · 被引用 1 次
- Demystifying the Evolution of Neural Networks with BOM Analysis: Insights from a Large-Scale Study of 55,997 GitHub RepositoriesXiaoning Ren, Yuhang Ye, Xiongfei Wu, Yueming Wu 等ASE 2025 · 被引用 1 次
- JBomAudit: Assessing the Landscape, Compliance, and Security Implications of Java SBOMsYue Xiao, Dhilung Kirat, Douglas Lee Schales, Jiyong Jang 等NDSS 2025
它引用的顶会 Paper7
- Robust Speech Recognition via Large-Scale Weak SupervisionAlec Radford, Jong Wook Kim, Tao Xu, Greg Brockman 等ICML 2023 · 被引用 6,966 次
- Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSKai Chen, Xueqiang Wang, Yi Chen, Peng Wang 等S&P 2016 · 被引用 111 次
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu 等ICSE 2023 · 被引用 82 次
- Practical Automated Detection of Malicious npm PackagesAdriana Sejfia, Max SchäferICSE 2022 · 被引用 65 次
- Towards Understanding Third-party Library Dependency in C/C++ EcosystemWei Tang, Zhengzi Xu, Chengwei Liu, Jiahui Wu 等ASE 2022 · 被引用 64 次
相关 Paper
- Software Architecture in Practice: Challenges and OpportunitiesZhiyuan Wan, Yun Zhang, Xin Xia, Yi Jiang 等FSE 2023 · 被引用 29 次
- An Industry Interview Study of Software Signing for Supply Chain SecurityKelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias 等USENIX Security 2025
- Robotics software engineering: a perspective from the service robotics domainSergio García, Daniel Strüber, Davide Brugali, Thorsten Berger 等FSE 2020 · 被引用 76 次
- DeepSCA: Dependency-Aware Software Composition Analysis for C/C++ Based on a Curated Code Feature DatabaseMeiqiu Xu, Xibin Zhao, Wenxuan Yu, Zhiliang Zhu 等ISSTA 2026
- Software Vulnerability Management in the Era of Artificial Intelligence: An Industry PerspectiveM. Mehdi Kholoosi, Triet Huynh Minh Le, M. Ali BabarICSE 2026
