• bom: the Kubernetes SBOM tool, bom, now supports SPDX 2.3 both when generating and ingesting SBOMs. 2.3 is now the default version when generating and is also supported when visualizing and querying SPDX documents.
  • ko: if you build your images with ko, you have been getting free SBOMs for some time now. If you use ko at HEAD, you will now get an SPDX 2.3 SBOM describing your image and dependencies.
  • apko: the popular image builder from Chainguard, now generates SPDX 2.3 SBOMs describing your image and the operating system dependencies that are baked into it.