A structured inventory of software components and relationships associated with a product or artifact, often including versions, suppliers, licenses, and identifiers.
Why it matters
You need a component inventory to assess affected dependencies, license obligations, and supply-chain exposure when software changes or vulnerabilities emerge.
In practice
Generate the SBOM during the trusted build, bind it to the release artifact, verify it in policy checks, and update it whenever dependencies or packaging change.
Common confusion
An SBOM is an inventory, not proof that components are secure, correctly licensed, or actually present unless generation and provenance are trustworthy.
Related terms
Sources
Browse the learning paths to see this term in context — every lesson is free to read.