CycloneDX 1.5 SBOM from SDM system dump

Hi @patricthysell,

just tried it out, very cool, thanks for sharing that!!

Just as question / idea:
as the system dump also contains the hardware information that’s really connected to the PLC, would it be possible and would it make sense to integrate also the hardware firmware variant information to the SBOM?
I know that “S” stands for “Software” :wink: But thinking about firmware as software, maybe it could be useful (or even needed?) to provide this information also when generating a SBOM from a running system?
What do you think, or how is your interpretation of CRA regarding firmware as a software part of a digital product?

BG Alex

1 Like