TestifySec participated in the group of companies funded through CISA and the DHS Science and Technology Directorate’s Silicon Valley Innovation Program to develop Protobom. The OpenSSF launch announcement on April 16, 2024 names the seven participating companies and describes the project’s purpose.
A shared representation for SBOMs
Teams receive software bills of materials in different formats. That makes it harder to build tools that read, compare, or exchange inventories. Protobom provides a protocol-buffers representation and a library for working with SBOM data across supported formats.
An inventory is useful, but its format does not establish whether it is complete or accurate. Review the producer, generation method, artifact association, and transformations that produced the document.
Our related experiments
At the time of the announcement, we were exploring Protobomit: experimental work connecting SBOMs to in-toto attestations. The goal was to make it easier to examine the evidence behind an inventory, including which artifact and execution it described.
Those research plans were not a promise of commercial product availability. The earlier article’s list of experimental features should not be read as a current TestifySec support matrix.
Why the relationship matters
A build result, an SBOM, and a vulnerability report answer different questions. Keeping them associated with the same artifact helps a reviewer follow those questions without treating any single document as proof of software safety.
For the current open-source project, use the Protobom repository. For commercial capture, gate, and evidence workflows, use the TestifySec documentation.