| name | analyzing-sbom-for-supply-chain-vulnerabilities |
| description | Use when parsing Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculating risk scores, identifying transitive vulnerability paths, and generating compliance reports. |
| domain | cybersecurity |
| tags | ["SBOM","CycloneDX","SPDX","NVD","CVE","supply-chain","dependency-analysis","syft","grype"] |
| subdomain | supply-chain-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| atlas_techniques | ["AML.T0010","AML.T0104"] |
| nist_ai_rmf | ["GOVERN-5.2","MAP-1.6","MANAGE-2.2","GOVERN-1.1","GOVERN-4.2"] |
| nist_csf | ["GV.SC-01","GV.SC-03","GV.SC-06","GV.SC-07"] |
Analyzing Sbom For Supply Chain Vulnerabilities
Overview
Cybersecurity skill for analyzing sbom for supply chain vulnerabilities. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"analyzing sbom for supply chain vulnerabilities"
-
"Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to i"
-
A new regulatory requirement (EO 14028, EU CRA) mandates SBOM analysis for software deliveries
-
Security team needs to assess third-party risk by scanning vendor-provided SBOMs
-
CI/CD pipeline requires automated vulnerability checks against generated SBOMs
-
Incident response needs to determine if a newly disclosed CVE affects deployed software
-
Procurement team requires supply chain risk assessment for a software acquisition
Do not use for runtime vulnerability scanning of live systems; use container scanning tools (Trivy, Grype CLI) or host-based vulnerability scanners (Nessus, Qualys) instead.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}