TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

BOMtotal – software bill of materials from binary executables

10 pointsby rayshanabout 10 years ago

3 comments

ctonicabout 10 years ago
Found out about this in the Microsoft VS Code thread but turns out it can process Docker base images too (after exporting them to tar files). Here is a component list for the nginx:latest base image: <a href="http:&#x2F;&#x2F;www.bomtotal.com&#x2F;#9ab3777ec051c1f8db85d0513b032e91" rel="nofollow">http:&#x2F;&#x2F;www.bomtotal.com&#x2F;#9ab3777ec051c1f8db85d0513b032e91</a> Pretty neat stuff!
评论 #9464621 未加载
svimesabout 10 years ago
The whole software bill of materials, BOM, is a nice idea. If you buy a carton of milk, the contents are printed on the back. Why shouldn&#x27;t this apply to software as well? Of course a lot of the software does not come in a shrink-wrapped package, so you need something like BOMtotal to keep you informed.
evilonabout 10 years ago
It will be interesting to see how the industry picks this up. The amount of vulnerable libraries (and many of them) in software, even in security software, is rather mind boggling.