Step 01 of 06
Learn the concept
Log4Shell hurt partly because many teams did not know where Log4j was running. The panic was not only the bug; it was the inventory failure. An SBOM is the boring list you wish you already had when a CVE lands on a Friday.
The ideas this is made of
An SBOM is inventory, not a verdict
SPDX and CycloneDX documents list components, versions, relationships, and sometimes licences. They do not say the system is safe. They say what is present. That is still powerful: when CVE-2021-44228 landed, teams with inventories could search for Log4j versions. Teams without inventories searched production by folklore.
Scanners match databases to discovered packages
Grype and Trivy compare the SBOM or image contents with vulnerability databases. The output names a package, installed version, vulnerability ID, severity, and fixed version when known. If the package is not detected, the scanner cannot warn you. If the database is stale, the answer is stale. Tools are evidence, not oracles.
CVSS is a signal, not a pager policy
CVSS scores estimate technical severity. They do not know whether Beacon reaches the vulnerable code path, whether the container is exposed to untrusted input, or whether a fixed image exists. A critical CVE in an unused library and a medium CVE on an internet-facing parser can deserve opposite urgency. Triage beats panic.
Fixed-in matters more than fear
A useful scanner result says which version fixes the issue. If no fix exists, the answer may be mitigation: disable a feature, restrict exposure, or accept documented risk for a short window. Rebuilding the same Dockerfile against the same vulnerable base image changes the timestamp and little else.
syft beacon:runtime -o spdx-json=sbom.spdx.json
grype sbom:sbom.spdx.json --fail-on criticalThe first command creates an inventory file. The second scans that inventory and exits non-zero only for critical matches, which is a policy choice you can state and review.
SBOM formats and scanners
| Tool or format | Purpose | Typical command |
|---|---|---|
SPDX | Legal and package inventory |
|
CycloneDX | Security inventory |
|
Syft | Generate the inventory |
|
Grype | Match CVEs |
|
Trivy | Scan image or SBOM |
|
What these are called on the job
SBOM — Software Bill of Materials: an inventory of components in an artifact.
CVE — A public identifier for a known vulnerability, such as CVE-2021-44228.
CVSS — A scoring system estimating vulnerability severity from technical factors.
EPSS — A probability estimate that a vulnerability will be exploited in the wild.
