The SBOM Gap: Adoption and Compliance in Open Source Software
This program is tentative and subject to change.
Software supply chain attacks are rising rapidly, and Software Bills of Materials (SBOMs) have emerged as an important mechanism for enhancing transparency and traceability in software ecosystems. Despite growing regulatory interest and tool support, SBOM adoption within open-source software (OSS) projects is still not well understood. This paper presents a large-scale empirical study of SBOM adoption across over 3,100 OSS repositories on GitHub. We identify and validate 261 SBOM-enabled projects and compare them against a representative sample of non-SBOM projects. We use technical, social, and organizational features from these repositories and apply bootstrapped logistic regression to reveal key adoption patterns. Our results show that project maturity and coordination mechanisms such as structured branching and active forking correlate more strongly with SBOM adoption than development activity or code complexity. We also perform a compliance audit of 287 SBOMs and find widespread gaps between SBOM availability and their readiness for security analysis. We conclude with implications for OSS maintainers, tool developers, security stakeholders, and researchers to guide effective SBOM use in practice.
This program is tentative and subject to change.
Fri 20 MarDisplayed time zone: Athens change
14:00 - 15:30 | Session 7B - Software Architecture, Dependencies, and Industry InnovationJournal First Track / Research Track | ||
14:00 18mTalk | Detecting and removing bloated dependencies in CommonJS packages Journal First Track Yuxin Liu KTH Royal Institute of Technology, Deepika Tiwari KTH Royal Institute of Technology, Cristian Bogdan KTH Royal Institute of Technology, Benoit Baudry Université de Montréal | ||
14:18 18mTalk | Beyond Lexical: Functional Semantics and Fusion for Precise Architecture Recovery Research Track Chunguang Zhang Southeast University, Bixin Li Southeast University, Yan Xiao Sun Yat-sen University | ||
14:36 18mTalk | The SBOM Gap: Adoption and Compliance in Open Source Software Research Track Md Fazle Rabbi Idaho State University, Asif Kamal Turzo University of Massachusetts Dartmouth, Arifa Islam Champa Idaho State University, Minhaz Zibran Idaho State University | ||
14:54 18mTalk | Innovating Industry With Research: eknows and Sysparency Journal First Track Verena Geist Software Competence Center Hagenberg GmbH, Michael Moser Software Competence Center Hagenberg GmbH, Josef Pichler University of Applied Sciences Upper Austria, Florian Schnitzhofer Sysparency GmbH | ||
15:12 18mTalk | Industry 4.0/IIoT Platforms for manufacturing systems - A systematic review contrasting the scientific and the industrial side Journal First Track Holger Eichelberger University of Hildesheim, Christian Sauer University of Hildesheim, Amir Shayan Ahmadian University of Koblenz, Christian Kröher University of Hildesheim | ||