
On Friday, July 17 at 10 AM, CREATE SE4AI hosted another edition of Trainee Talks, featuring MASc candidate Kawsar Ahmed Bhuiyan, a member of the REALISE Lab at Concordia University under the supervision of Prof. Diego Elias Costa. Kawsar presented his work titled "Beyond Compliance: A Large-scale Study on the Completeness and Consistency of the GitHub SBOMs."
Abstract:
Modern software development relies heavily on open-source components. Reusing components accelerates innovation but increases exposure to supply-chain attacks exploiting known vulnerabilities. Software Bills of Materials (SBOMs) improve software supply chain transparency by enumerating components, their versions, and their provenance. GitHub, the largest open-source development hosting platform, now automatically generates SBOMs for repositories, providing valuable metadata for risk assessment.
During the talk, Kawsar presented the findings of a large-scale analysis of 10,000 GitHub repositories across ten programming language ecosystems, evaluating GitHub SBOMs against three other popular SBOM generators: Syft, Trivy, and the Microsoft SBOM Tool. The study found a lack of NTIA compliance in GitHub SBOMs, although core metadata was consistently present. It also showed that the availability of component version and license information depends heavily on the programming ecosystem. Compared with the other three tools, GitHub produced results similar to the Microsoft SBOM Tool and often outperformed Syft and Trivy in providing version and license information. The presentation concluded with a discussion of potential shortcomings of the GitHub SBOM Tool related to how different programming ecosystems manage their dependencies.
The video is now available to view on our CREATE SE4AI YouTube channel.