# Our Role in Protobom, An Open Source Software Supply Chain Tool

Source: https://www.testifysec.com/blog/protobom

Author: Cole Kennedy

Published: 2024-05-22

Updated: 2026-10-06

TestifySec's contribution to the Protobom project for SBOM generation and management.

From the archive · edited October 6, 2026

Edited by TestifySec Editorial to clarify the historical announcement, restore primary sources, and separate earlier plans from current product support. The published URL and date are retained.

- [Current TestifySec docs →](https://www.testifysec.com/docs)
- [Trust architecture →](https://www.testifysec.com/docs/cilock/trust)

TestifySec participated in the group of companies funded through CISA and the DHS Science and Technology Directorate’s Silicon Valley Innovation Program to develop Protobom. The [OpenSSF launch announcement on April 16, 2024](https://openssf.org/press-release/2024/04/16/cisa-dhs-st-and-openssf-announce-global-launch-of-software-supply-chain-open-source-project/) names the seven participating companies and describes the project’s purpose.

 

## A shared representation for SBOMs

 

Teams receive software bills of materials in different formats. That makes it harder to build tools that read, compare, or exchange inventories. [Protobom](https://github.com/protobom/protobom) provides a protocol-buffers representation and a library for working with SBOM data across supported formats.

 

An inventory is useful, but its format does not establish whether it is complete or accurate. Review the producer, generation method, artifact association, and transformations that produced the document.

 

## Our related experiments

 

At the time of the announcement, we were exploring Protobomit: experimental work connecting SBOMs to in-toto attestations. The goal was to make it easier to examine the evidence behind an inventory, including which artifact and execution it described.

 

Those research plans were not a promise of commercial product availability. The earlier article’s list of experimental features should not be read as a current TestifySec support matrix.

 

## Why the relationship matters

 

A build result, an SBOM, and a vulnerability report answer different questions. Keeping them associated with the same artifact helps a reviewer follow those questions without treating any single document as proof of software safety.

 

For the current open-source project, use the [Protobom repository](https://github.com/protobom/protobom). For commercial capture, gate, and evidence workflows, use the [TestifySec documentation](https://www.testifysec.com/docs).
