The concept of a software bill of materials (commonly referred to as an SBOM) is foundational to supply chain security. Yet actually having the right tools to easily develop SBOMs has often been a challenge. That challenge might be getting just a bit easier today.

In a collaborative effort to strengthen software security and software supply chain risk management, the Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security Science and Technology Directorate (DHS S&T) and Open Source Security Foundation (OpenSSF) have partnered to develop and launch the open source Protobom SBOM tool.

Protobom is designed to simplify the creation, reading and translation of  SBOM data across the various industry standard formats. An SBOM acts as a nested inventory that lists all the components making up a software product, including relationships between open source and commercial components used.

“There are a variety of different SBOM formats being used today,” Omkhar Arasaratnam, GM at OpenSSF, told SDxCentral. “Protobom allows users to store SBOM information in a native (protobuf) format which can easily be exported to one of the industry standards as required.”

Protobom joins a growing chorus of SBOM projects at the OpenSSF

The OpenSSF has been working on multiple efforts in recent years to help improve supply chain security via SBOMs.

Among the numerous efforts is the supply chain levels for software artifacts (SLSA) effort originally started by Google in 2021 and now managed by the OpenSSF which released version 1.0 in April 2023. More recently, just last month in March, the graph for understanding artifact composition (GUAC) joined the OpenSSF.

The Linux Foundation, which the OpenSSF is a part of, is also home to the Software Package Data Exchange (SPDX) project, which is one of the formats that organizations have long been using to represent systems in an SBOM. SPDX isn't the only format used for SBOMs, with other popular formats including CycloneDX, which is backed by the OWASP Foundation.

The fact that there are multiple formats for SBOMs can potentially lead to confusion and challenges, which is the issue that Protobom aims to help solve.

“Protobom offers a robust framework for ingesting and writing into diverse SBOM formats,” Arasaratnam said. “By furnishing this capability, Protobom aids both open and closed source projects in accurately producing and consuming SBOMs.”

What exactly is a Protobom?

Understanding a software's supply chain components and associated vulnerabilities through an SBOM is crucial for managing cyber risks. However, the existence of multiple SBOM formats has made adoption challenging for many organizations.

Protobom solves this by offering a format-neutral data layer that allows applications to work seamlessly with any SBOM format. It can integrate into commercial and open source apps, promoting broader SBOM usage by making creation and consumption easier and more cost-effective.

Technically speaking, Protobom is a protocol buffers representation of SBOM data. Protocol Buffers (Protobuf) is a cross-platform data format used for serializing structured data originally developed by Google.

To spur SBOM adoption, CISA and DHS S&T funded seven startup companies to develop Protobom: AppCensus, Chainguard, Deepbits, Manifest Cyber, Scribe Security, TestifySec and Veramine.

The OpenSSF, which collaborates on open source supply chain security, will now host the Protobom project to facilitate its open source development and an open contributor community around it. By enabling easy SBOM translation across formats, Protobom aims to remove barriers to SBOM adoption. When integrated with applications that link SBOM data to external vulnerability databases, it can provide information on available security patches and mitigations.

“To defend against increasing software attacks, innovative tools that create supply chain transparency are critical,” Melissa Oh, DHS Silicon Valley Innovation Program managing director, wrote in a statement. “Protobom will shine a light on supply chain risks.”