|
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
|
| Volume 187 - Issue 56 |
| Published: November 2025 |
| Authors: Sri Sowmya Nemani |
10.5120/ijca2025925990
|
Sri Sowmya Nemani . Adaptive Risk Based Enforcement Using SBOM Automation for Secure Software Supply Chains. International Journal of Computer Applications. 187, 56 (November 2025), 61-63. DOI=10.5120/ijca2025925990
@article{ 10.5120/ijca2025925990,
author = { Sri Sowmya Nemani },
title = { Adaptive Risk Based Enforcement Using SBOM Automation for Secure Software Supply Chains },
journal = { International Journal of Computer Applications },
year = { 2025 },
volume = { 187 },
number = { 56 },
pages = { 61-63 },
doi = { 10.5120/ijca2025925990 },
publisher = { Foundation of Computer Science (FCS), NY, USA }
}
%0 Journal Article
%D 2025
%A Sri Sowmya Nemani
%T Adaptive Risk Based Enforcement Using SBOM Automation for Secure Software Supply Chains%T
%J International Journal of Computer Applications
%V 187
%N 56
%P 61-63
%R 10.5120/ijca2025925990
%I Foundation of Computer Science (FCS), NY, USA
Nowadays, many developers rely on third-party and open-source libraries that integrate directly into production software. However, it is critical to understand what is being integrated and who maintains it. The hidden security and governance risks within unmanaged dependencies continue to expose organizations to software supply chain attacks and compliance violations. Software Bills of Materials (SBOMs) in formats such as SPDX and CycloneDX — provide visibility into third-party components. This paper discusses how SBOMs can be automatically generated from development code and integrated into CI/CD pipelines for continuous risk assessment. The model proposed in this study ensures that every building produces an auditable SBOM, allowing the security team to continuously review, mitigate, or apply compensating controls for identified risks.