Computer Security: The road to SBOM
CERN is advancing its Software Bill of Materials strategy to improve software transparency, security, and reproducibility across its systems and research workflows.
Software Bill of Materials (SBOM) inventories, which list software components and dependencies, are often avoided due to their complexity despite offering significant benefits. These include security enhancements, strategic upgrade planning, licence compliance, and support for open science by enabling reproducible experiments. SBOMs automate the identification of vulnerable components and streamline licence checks, reducing manual effort in IT management.
CERN has already implemented SBOM-related initiatives, such as dependency and security scans in its GitLab service and SBOM generation for OpenStack-managed containers. The Accelerators and Technologies Sector uses an advanced inventory to prevent software obsolescence during data-taking runs, ensuring operational continuity.
To further strengthen its SBOM strategy, CERN will conduct an inventory this autumn led by an external researcher from Ruhr University Bochum. The study aims to assess the benefits and drawbacks of SBOMs across different areas of deployment, identifying necessary support for effective implementation.
The upcoming inventory is part of CERN’s broader effort to enhance software visibility and security. Developers can already generate SBOMs or run vulnerability scans via the ‘Artefacts’ tab in their projects, with additional resources available through CERN’s security reporting and support channels.