{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:05:20Z","timestamp":1783789520232,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"DOI":"10.1145\/3800506.3803490","type":"proceedings-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:24:42Z","timestamp":1781281482000},"page":"255-268","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-1222-6815","authenticated-orcid":false,"given":"Li","family":"Zhou","sequence":"first","affiliation":[{"name":"King Abdullah University of Science and Technology, Thuwal, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3206-2030","authenticated-orcid":false,"given":"Marc","family":"Dacier","sequence":"additional","affiliation":[{"name":"King Abdullah University of Science and Technology, Thuwal, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3825-3930","authenticated-orcid":false,"given":"Charalambos","family":"Konstantinou","sequence":"additional","affiliation":[{"name":"King Abdullah University of Science and Technology, Thuwal, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Agency for Healthcare Research and Quality. 2019. Alert Fatigue. https:\/\/psnet.ahrq.gov\/primer\/alert-fatigue. Accessed on 2025-09-27."},{"key":"e_1_3_2_1_2_1","volume-title":"2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT). IEEE, 1-7.","author":"Alkhadra Rahaf","year":"2021","unstructured":"Rahaf Alkhadra, Joud Abuzaid, Mariam AlShammari, and Nazeeruddin Mohammad. 2021. Solar winds hack: In-depth analysis and countermeasures. In 2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT). IEEE, 1-7."},{"key":"e_1_3_2_1_3_1","volume-title":"Syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems. https:\/\/github.com\/anchore\/syft Accessed: 2024-12-03.","year":"2023","unstructured":"Anchore. 2023. Syft: CLI tool and library for generating a Software Bill of Materials from container images and filesystems. https:\/\/github.com\/anchore\/syft Accessed: 2024-12-03."},{"key":"e_1_3_2_1_4_1","volume-title":"Grype: A Vulnerability Scanner for Container Images and Filesystems. https:\/\/github.com\/anchore\/grype Accessed: 2025-04-30.","author":"Inc. Anchore.","year":"2025","unstructured":"Inc. Anchore. 2025. Grype: A Vulnerability Scanner for Container Images and Filesystems. https:\/\/github.com\/anchore\/grype Accessed: 2025-04-30."},{"key":"e_1_3_2_1_5_1","volume-title":"uv: An extremely fast Python package installer and resolver. https:\/\/github.com\/astral-sh\/uv. Accessed","year":"2025","unstructured":"astral-sh. 2025. uv: An extremely fast Python package installer and resolver. https:\/\/github.com\/astral-sh\/uv. Accessed: 10 Dec 2025."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2023.3302956"},{"key":"e_1_3_2_1_7_1","unstructured":"Olivier Beg. 2023. Why 2023 is the Year for Software Supply Chain Attacks. https:\/\/hadrian.io\/blog\/why-2023-is-the-year-for-software-supply-chain-attacks Accessed: 2024-12-03."},{"key":"e_1_3_2_1_8_1","volume-title":"The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach. arXiv preprint arXiv:2409.06390","author":"Benedetti Giacomo","year":"2024","unstructured":"Giacomo Benedetti, Serena Cofano, Alessandro Brighente, and Mauro Conti. 2024. The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach. arXiv preprint arXiv:2409.06390 (2024)."},{"key":"e_1_3_2_1_9_1","unstructured":"Alex Birsan. 2021. Dependency Confusion: How I Hacked Into Apple Microsoft and Dozens of Other Companies. Medium post \/ disclosure and writeup. https:\/\/medium.com\/@alex.birsan\/dependency-confusion-how-i-hacked-into-apple-microsoft-and-dozens-of-other-companies-4a5d60fec610 Public writeup demonstrating dependency\/substitution attacks that motivated supply-chain mitigations (relevant to vendoring decisions)."},{"key":"e_1_3_2_1_10_1","unstructured":"Brett Cannon and Nathaniel Smith. 2016. PEP 518 - Specifying Minimum Build System Requirements for Python Projects. Python Enhancement Proposals (PEPs). https:\/\/peps.python.org\/pep-0518\/ Accessed: 2025-12-16."},{"key":"e_1_3_2_1_11_1","volume-title":"2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, 427-434","author":"Cofano Serena","year":"2024","unstructured":"Serena Cofano, Giacomo Benedetti, and Matteo Dell'Amico. 2024. SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis. In 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, 427-434."},{"key":"e_1_3_2_1_12_1","unstructured":"Intel Corporation. 2025. CVE Binary Tool: Scan Binaries for Known Vulnerabilities. https:\/\/github.com\/intel\/cve-bin-tool Accessed: 2025-04-30."},{"key":"e_1_3_2_1_13_1","unstructured":"Russ Cox. 2018. Defining Go Modules (Go & Versioning Part 6). Online article \/ blog. https:\/\/research.swtch.com\/vgo-module ''The End of Vendoring'' discussion and vendor directory rationale."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3664476.3669975"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9589-y"},{"key":"e_1_3_2_1_16_1","unstructured":"Robert J Ellison John B Goodenough Charles B Weinstock and Carol Woody. 2010. Evaluating and mitigating software supply chain security risks. Software Engineering Institute Tech. Rep. CMU\/SEI-2010-TN-016 (2010)."},{"key":"e_1_3_2_1_17_1","unstructured":"Fraunhofer FKIE. 2025. cwe-checker: Detects Vulnerable Patterns in Binary Executables. https:\/\/github.com\/fkie-cad\/cwe_checker Accessed: 2025-04-30."},{"key":"e_1_3_2_1_18_1","volume-title":"JBOM: Runtime and Static SBOM Generator for Java Applications. https:\/\/github.com\/eclipse-jbom\/jbom Accessed: 2025-04-30.","author":"Foundation Eclipse","year":"2025","unstructured":"Eclipse Foundation. 2025a. JBOM: Runtime and Static SBOM Generator for Java Applications. https:\/\/github.com\/eclipse-jbom\/jbom Accessed: 2025-04-30."},{"key":"e_1_3_2_1_19_1","unstructured":"OWASP Foundation. 2025b. dep-scan: Next-Generation Security and Risk Audit Tool. https:\/\/github.com\/owasp-dep-scan\/dep-scan Accessed: 2025-04-30."},{"key":"e_1_3_2_1_20_1","unstructured":"Jatin Garg. 2025. Using Grype in CI\/CD Pipelines for Automated Security Checks. https:\/\/www.gocodeo.com\/post\/using-grype-in-ci-cd-pipelines-for-automated-security-checks. Accessed: 2025-09-22."},{"key":"e_1_3_2_1_21_1","unstructured":"GitHub. 2025a. About the Dependency Graph. https:\/\/docs.github.com\/en\/code-security\/supply-chain-security\/understanding-your-software-supply-chain\/about-the-dependency-graph Accessed: 2025-04-30."},{"key":"e_1_3_2_1_22_1","unstructured":"Inc. GitHub. 2025b. GitHub Actions. https:\/\/github.com\/features\/actions. https:\/\/github.com\/features\/actions Continuous integration \/ continuous deployment workflow automation."},{"key":"e_1_3_2_1_23_1","unstructured":"GitLab Docs. 2025. Container scanning. https:\/\/docs.gitlab.com\/user\/application_security\/container_scanning\/ Accessed: 2025-09-22."},{"key":"e_1_3_2_1_24_1","volume-title":"Dependency Scanning SBOM (Software Bill of Materials). https:\/\/docs.gitlab.com\/user\/application_security\/dependency_scanning\/dependency_scanning_sbom\/. Accessed","author":"GitLab Inc.","year":"2025","unstructured":"GitLab Inc., 2025. Dependency Scanning SBOM (Software Bill of Materials). https:\/\/docs.gitlab.com\/user\/application_security\/dependency_scanning\/dependency_scanning_sbom\/. Accessed: 10 Dec 2025."},{"key":"e_1_3_2_1_25_1","unstructured":"Ravie Lakshmanan. 2023. PyTorch Machine Learning Framework Compromised with Malicious Dependency. https:\/\/thehackernews.com\/2023\/01\/pytorch-machine-learning-framework.html Accessed: 2024-12-03."},{"key":"e_1_3_2_1_26_1","volume-title":"On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ. arXiv preprint arXiv:2404.08987","author":"Lins Mario","year":"2024","unstructured":"Mario Lins, Ren\u00e9 Mayrhofer, Michael Roland, Daniel Hofer, and Martin Schwaighofer. 2024. On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ. arXiv preprint arXiv:2404.08987 (2024)."},{"key":"e_1_3_2_1_27_1","unstructured":"JFrog Ltd. 2025. build-info-go: Go Library and CLI for Generating Build Information. https:\/\/github.com\/jfrog\/build-info-go Accessed: 2025-04-30."},{"key":"e_1_3_2_1_28_1","unstructured":"Microsoft. 2025. SBOM Tool. https:\/\/github.com\/microsoft\/sbom-tool Accessed: 2025-04-30."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE)","author":"C. Miller","year":"2023","unstructured":"C. Miller et al., 2023. ''We Feel Like We're Winging It:'' A Study on Navigating Open-Source Dependency Abandonment. Proceedings of the ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE) (2023). https:\/\/www.cs.cmu.edu\/ ckaestne\/pdf\/fse23.pdf Empirical study of developer practices around dependency abandonment, vendoring and mitigation strategies."},{"key":"e_1_3_2_1_30_1","first-page":"7","volume-title":"First International Workshop on Emerging Trends in FLOSS Research and Development (FLOSS'07: ICSE Workshops","author":"Mockus Audris","year":"2007","unstructured":"Audris Mockus. 2007. Large-scale code reuse in open source software. In First International Workshop on Emerging Trends in FLOSS Research and Development (FLOSS'07: ICSE Workshops 2007). IEEE, 7-7."},{"key":"e_1_3_2_1_31_1","unstructured":"Inc. Moderne. 2025. OpenRewrite: Automated Refactoring Ecosystem. https:\/\/docs.openrewrite.org\/ Accessed: 2025-04-30."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3365137.3365402"},{"key":"e_1_3_2_1_33_1","volume-title":"NTIA","volume":"12","author":"Muir'i \u00c9amonn","year":"2019","unstructured":"\u00c9amonn \u00d3 Muir'i. 2019. Framing software component transparency: Establishing a common software bill of material (SBOM). NTIA, Nov, Vol. 12 (2019)."},{"key":"e_1_3_2_1_34_1","unstructured":"National Telecommunications and Information Administration. 2021. Software Bill of Materials. https:\/\/www.ntia.gov\/page\/software-bill-materials Accessed: 2024-12-03."},{"key":"e_1_3_2_1_35_1","unstructured":"National Telecommunications and Information Administration (NTIA). 2021. Vulnerability-Exploitability eXchange (VEX) - An Overview. One-page summary \/ Technical overview. U.S. Department of Commerce. https:\/\/www.ntia.gov\/files\/ntia\/publications\/vex_one-page_summary.pdf Accessed: 2025-09-24."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3689944.3696164"},{"key":"e_1_3_2_1_37_1","volume-title":"2024 IEEE International Conference on Software Analysis, Evolution and Reengineering-Companion (SANER-C). IEEE, 134-140","author":"O'Donoghue Eric","year":"2024","unstructured":"Eric O'Donoghue, Ann Marie Reinhold, and Clemente Izurieta. 2024. Assessing security risks of software supply chains using software bill of materials. In 2024 IEEE International Conference on Software Analysis, Evolution and Reengineering-Companion (SANER-C). IEEE, 134-140."},{"key":"e_1_3_2_1_38_1","volume-title":"Scan SBOM with Ostorlab. https:\/\/docs.ostorlab.co\/tutorials\/scan_sbom.html. Accessed","year":"2025","unstructured":"Ostorlab. 2025. Scan SBOM with Ostorlab. https:\/\/docs.ostorlab.co\/tutorials\/scan_sbom.html. Accessed: 10 Dec 2025."},{"key":"e_1_3_2_1_39_1","unstructured":"OWASP Foundation. 2024. CycloneDX: The International Standard for Bill of Materials (ECMA-424). https:\/\/cyclonedx.org\/ Accessed: 2024-12-03."},{"key":"e_1_3_2_1_40_1","unstructured":"CycloneDX Project. 2025a. cdxgen: CycloneDX Bill of Materials Generator. https:\/\/github.com\/CycloneDX\/cdxgen Accessed: 2025-04-30."},{"key":"e_1_3_2_1_41_1","unstructured":"CycloneDX Project. 2025b. CycloneDX Maven Plugin: Generates SBOMs from Maven Projects. https:\/\/github.com\/CycloneDX\/cyclonedx-maven-plugin Accessed: 2025-04-30."},{"key":"e_1_3_2_1_42_1","unstructured":"CycloneDX Project. 2025c. cyclonedx-node-module: Meta-package for CycloneDX SBOM Generators. https:\/\/github.com\/CycloneDX\/cyclonedx-node-module Accessed: 2025-04-30."},{"key":"e_1_3_2_1_43_1","unstructured":"Jenkins Project. 2025d. Jenkins. https:\/\/www.jenkins.io. https:\/\/www.jenkins.io Open source automation server."},{"key":"e_1_3_2_1_44_1","unstructured":"OSS Review Toolkit Project. 2025 e. OSS Review Toolkit (ORT). https:\/\/oss-review-toolkit.org\/ort\/ Accessed: 2025-04-30."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.14"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605098.3635927"},{"key":"e_1_3_2_1_47_1","volume-title":"2023 IEEE international conference on cyber security and resilience (CSR). IEEE, 28-35","author":"Reinhold Ann Marie","year":"2023","unstructured":"Ann Marie Reinhold, Travis Weber, Colleen Lemak, Derek Reimanis, and Clemente Izurieta. 2023. New version, new answer: Investigating cybersecurity static-analysis tool findings. In 2023 IEEE international conference on cyber security and resilience (CSR). IEEE, 28-35."},{"key":"e_1_3_2_1_48_1","volume-title":"Trivy: Vulnerability Scanner for Containers and Other Artifacts. https:\/\/github.com\/aquasecurity\/trivy Accessed: 2024-12-03.","author":"Security Aqua","year":"2023","unstructured":"Aqua Security. 2023. Trivy: Vulnerability Scanner for Containers and Other Artifacts. https:\/\/github.com\/aquasecurity\/trivy Accessed: 2024-12-03."},{"key":"e_1_3_2_1_49_1","volume-title":"Analytics Global Conference. Springer, 40-51","author":"Sehgal Vandana Verma","year":"2023","unstructured":"Vandana Verma Sehgal and PS Ambili. 2023. A Taxonomy and Survey of Software Bill of Materials (SBOM) Generation Approaches. In Analytics Global Conference. Springer, 40-51."},{"key":"e_1_3_2_1_50_1","volume-title":"Muhammad Ali Babar, and Liming Zhu","author":"Shahin Mojtaba","year":"2017","unstructured":"Mojtaba Shahin, Muhammad Ali Babar, and Liming Zhu. 2017. Continuous integration, delivery and deployment: a systematic review on approaches, tools, challenges and practices. IEEE access, Vol. 5 (2017), 3909-3943."},{"key":"e_1_3_2_1_51_1","volume-title":"https:\/\/docs.snyk.io\/developer-tools\/snyk-cli\/commands\/sbom. Accessed","author":"Software SBOM","year":"2025","unstructured":"Snyk. 2025. SBOM (Software Bill of Materials). https:\/\/docs.snyk.io\/developer-tools\/snyk-cli\/commands\/sbom. Accessed: 10 Dec 2025."},{"key":"e_1_3_2_1_52_1","volume-title":"SPDX: The Software Package Data Exchange. https:\/\/spdx.dev\/ Accessed: 2024-12-03.","author":"Data Exchange Software Package","year":"2024","unstructured":"Software Package Data Exchange. 2024. SPDX: The Software Package Data Exchange. https:\/\/spdx.dev\/ Accessed: 2024-12-03."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2012.38"},{"key":"e_1_3_2_1_54_1","unstructured":"The Farama Foundation. 2022. Announcing The Farama Foundation. https:\/\/farama.org\/Announcing-The-Farama-Foundation"},{"key":"e_1_3_2_1_55_1","volume-title":"Guidelines for the creation of interoperable software identification (SWID) tags. US Department of Commerce","author":"Waltermire David","unstructured":"David Waltermire, Brant A Cheikes, Larry Feldman, David Waltermire, and Greg Witte. 2016. Guidelines for the creation of interoperable software identification (SWID) tags. US Department of Commerce, National Institute of Standards and Technology."},{"key":"e_1_3_2_1_56_1","volume-title":"2024 54th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 29-36","author":"Yu Sheng","year":"2024","unstructured":"Sheng Yu, Wei Song, Xunchao Hu, and Heng Yin. 2024. On the correctness of metadata-based SBOM generation: A differential analysis approach. In 2024 54th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 29-36."},{"key":"e_1_3_2_1_57_1","volume-title":"CovSBOM: Enhancing Software Bill of Materials with Integrated Code Coverage Analysis. In 2024 IEEE 35th International Symposium on Software Reliability Engineering (ISSRE). IEEE, 228-237","author":"Zhao Yunze","year":"2024","unstructured":"Yunze Zhao, Yuchen Zhang, Dan Chacko, and Justin Cappos. 2024. CovSBOM: Enhancing Software Bill of Materials with Integrated Code Coverage Analysis. In 2024 IEEE 35th International Symposium on Software Reliability Engineering (ISSRE). IEEE, 228-237."}],"event":{"name":"CODASPY '26: Sixteenth ACM Conference on Data and Application Security and Privacy","location":"Frankfurt am Main Germany","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Sixteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:27:06Z","timestamp":1781281626000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3800506.3803490"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":57,"alternative-id":["10.1145\/3800506.3803490","10.1145\/3800506"],"URL":"https:\/\/doi.org\/10.1145\/3800506.3803490","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}