Loading…
Tuesday October 6, 2026 17:20 - 17:38 CEST
Software Bills of Materials (SBOMs) are increasingly used as authoritative software inventories but popular generators use techniques that may not expose every input that ends up in or influences a build artifact. This paper presented SBOMit, an OpenSSF project that generates and enriches SBOMs using evidence collected while the software build workflow executes. \texttt{witness-ebpf} uses low-overhead tracing methods to record inputs like filesystem and network activity as in-toto attestations, which are later processed into package identities for an enriched SBOM. We evaluate SBOMit across 98 CNCF projects, measuring a median runtime overhead of 12.4% without requiring any modifications to the project source. We further compare SBOMit with static SBOM generation methods to identify build inputs and contexts that static methods fail to recover. Our results show that build-time observation is practical at scale and provide a more trusthworthy and auditable source of information for SBOMs.
Speakers
SS

Sanchit Sahay

Computer Science PhD student, New York University
Sanchit is a Computer Science PhD student at New York University's Secure Systems Lab where he works on software supply-chain security and operating systems research. Prior to NYU, he worked at Commvault Systems' Virtualization team securing private cloud infrastructure. Come say... Read More →
Tuesday October 6, 2026 17:20 - 17:38 CEST
South Hall 3A

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link