claim
While there is no direct mandate for open source software (OSS) to include an SBOM, federal agencies are effectively required to demand an SBOM before utilizing OSS components.

Authors

Sources

Referenced by nodes (1)