Hidden Dependencies and Component Variants in SBOM-Based Software Composition Analysis

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Rasheed, Shawn, McPhee, Max, Patterson, Lisa, MacDonell, Stephen, Dietrich, Jens
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914500995710976
author Rasheed, Shawn
McPhee, Max
Patterson, Lisa
MacDonell, Stephen
Dietrich, Jens
author_facet Rasheed, Shawn
McPhee, Max
Patterson, Lisa
MacDonell, Stephen
Dietrich, Jens
contents Software Bills of Material (SBOMs) have emerged as an important technology for vulnerability management amid rising supply-chain attacks. They represent component relationships within a software product and support software composition analysis (SCA) by linking components to known vulnerabilities. However, the effectiveness of SBOM-based analysis depends on how accurately SBOMs represent component identities and actual dependencies in software. This paper studies two mismatch patterns: hidden code-level dependencies that are not represented as component-level dependencies, and component variants (clones) that cannot be identified consistently by scanners. We show that these mismatches can lead to inconsistent vulnerability reporting and inconsistent handling of VEX statements across popular SBOM-based vulnerability scanners. These results highlight limitations in current SBOM production and consumption and motivate richer dependency representation and component identity.
format Preprint
id arxiv_https___arxiv_org_abs_2604_21278
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Hidden Dependencies and Component Variants in SBOM-Based Software Composition Analysis
Rasheed, Shawn
McPhee, Max
Patterson, Lisa
MacDonell, Stephen
Dietrich, Jens
Software Engineering
D.2.13
Software Bills of Material (SBOMs) have emerged as an important technology for vulnerability management amid rising supply-chain attacks. They represent component relationships within a software product and support software composition analysis (SCA) by linking components to known vulnerabilities. However, the effectiveness of SBOM-based analysis depends on how accurately SBOMs represent component identities and actual dependencies in software. This paper studies two mismatch patterns: hidden code-level dependencies that are not represented as component-level dependencies, and component variants (clones) that cannot be identified consistently by scanners. We show that these mismatches can lead to inconsistent vulnerability reporting and inconsistent handling of VEX statements across popular SBOM-based vulnerability scanners. These results highlight limitations in current SBOM production and consumption and motivate richer dependency representation and component identity.
title Hidden Dependencies and Component Variants in SBOM-Based Software Composition Analysis
topic Software Engineering
D.2.13
url https://arxiv.org/abs/2604.21278