claim
While there is no direct mandate for open source software (OSS) to include an SBOM, federal agencies are effectively required to demand an SBOM before utilizing OSS components.
Authors
Sources
- Cyber Insights 2025: Open Source and Software Supply Chain ... www.securityweek.com via serper