Terms

Software Bill of Materials

Follow the latest coverage, related explainers and connected technology stories.

Latest coverage

CN
Homebrew 7.0.0 Adds Built-in Vulnerability Scanning, BrewUI, and Stronger Security Controls

Homebrew 7.0.0 Adds Built-in Vulnerability Scanning, BrewUI, and Stronger Security Controls

The Homebrew project released version 7.0.0 with a built-in vulnerability scanner, an advisory database for the project’s packages, improved security isolation, and the full launch of the BrewUI graphical interface on macOS 26 Tahoe and later.

CN
G7 Group Agrees on Minimum Elements for an “Artificial Intelligence Bill of Materials”

G7 Group Agrees on Minimum Elements for an “Artificial Intelligence Bill of Materials”

The G7 group published a framework defining the minimum elements of an Artificial Intelligence Bill of Materials (AIBOM), with the aim of improving the traceability of AI system components and their relationships with suppliers and supply chains. This comes alongside regulatory and security initiatives in the European Union and in the fields of health data and cybersecurity.

CN
How Ubuntu Is Rebuilding Core System Tools Using Rust

How Ubuntu Is Rebuilding Core System Tools Using Rust

Canonical is taking a selective approach to introducing Rust into Ubuntu’s core tools, beginning with Ubuntu 26.04 LTS and focusing on memory safety, reliability, and maintainability. The plan includes uutils coreutils, sudo-rs, ntpd-rs, and the UPKI project, while keeping legacy tools and fallback options available during the transition.

CN
Chip Security Moves from Compliance to Continuous Defense

Chip Security Moves from Compliance to Continuous Defense

A discussion bringing together experts from Arteris, Cadence, Keysight EDA, Rambus, Siemens EDA, Synaptics, and Synopsys concludes that chip security is no longer a feature added at the end of the design process or a certification obtained for market approval. The expansion of attacks across embedded software, FPGAs, networks, and chiplets requires continuous component visibility, vulnerability tracking, and post-deployment monitoring.

CN
CNCF Announces Cloud Native Buildpacks Graduation After Expanded Adoption in Container Building

CNCF Announces Cloud Native Buildpacks Graduation After Expanded Adoption in Container Building

The Cloud Native Computing Foundation announced the graduation of the Cloud Native Buildpacks project after it reached a level of maturity supported by broad adoption in production environments, vendor-neutral governance, and security practices. The project helps transform source code into OCI-compliant container images by automating language detection, dependency installation, and image-layer creation.