• SBOM Completeness: Chainguard Labs examined the degree to which SBOMs generated by a range of tools contain baseline information associated with the so-called NTIA minimum elements. Only one percent of analyzed SBOMs conformed with the NTIA minimum elements, largely due to the fact that most SBOMs lack specified suppliers for their components.
  • SBOM Accuracy: The accuracy of SBOMs plays a crucial role in enabling organizations to identify and remediate vulnerabilities effectively. To evaluate the ability of SBOMs to accurately represent underlying software, Chainguard Labs conducted in-depth analysis of package manager metadata in popular container images. Their research found that popular open source containers are, on average, composed of 63% software dark matter – software that is untracked by package manager metadata and, hence, unlikely to be recorded in a SBOM.