En SBOM (software bill of materials) listar mjukvarukomponenter så att sårbarheter i beroenden kan spåras och åtgärdas.