Zięba-Kozarzewski 2026: "No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild" arxiv.org/abs/2607.22140 "52.9% of SBOMs declare no edges at all, 8.8% declare a dependency block yet leave the majority of components isolated, and 38.3% form well-connected graphs."

arXiv logoarXiv.orgNo Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the WildSoftware Bills of Materials (SBOMs) are consumed not only as component inventories but as dependency graphs: vulnerability triage, reachability filtering, and impact analysis all traverse the edges an SBOM declares. We present the first large-scale characterization of the declared dependency graph across 78,612 real-world SBOM files from the Wild SBOMs dataset (77,092 parseable). We find that the population splits into three regimes: 52.9% of SBOMs declare no edges at all (failing the NTIA minimum-elements requirement of dependency relationships), 8.8% declare a dependency block yet leave the majority of components isolated (degenerate regime; among such SBOMs with at least 50 components the median orphan share is 93%, and our 11 Syft-generated container-image SBOMs fall in this regime at 95-98% orphans), and 38.3% form well-connected graphs. Edge emission is determined by the generator, not the described software (0%-100% no-edge rates across tools), and the specification-level mechan

Replying to @⁨andrewnez@mastodon.social⁩

@andrewnez @gvwilson @fedora is planning to use

fedoraproject.org/wiki/Changes

which is at the very least SBOM adjacent.

We find that otherwise each packaging ecosyatem has its own way of specifying dependencies, and this makes it harder for security teams to flag issues accurately

fedoraproject.orgChanges/Adopt PURL Metadata - Fedora Project Wiki
en