Red Hat's contextual SBOM pattern extends traditional SBOMs by establishing hierarchical relationships between container images and their parent/builder images using SPDX 2.3 relationships. Instead of flat package lists, it tracks package provenance through DESCENDANT_OF and BUILD_TOOL_OF relationships, enabling teams to

15m read timeFrom developers.redhat.com
Post cover image
Table of contents
Traditional vs. contextual SBOMThe contextual SBOM pattern in vulnerability managementUse case 1: Parent image vulnerability remediationUse case 2: Builder stage vulnerability remediationHow to create a contextual SBOMLimitations of package matchingBuilder content identificationConclusion

Sort: