saascode

Sbomdrift

A provenance-capture layer that links AI coding sessions to dependency changes, vulnerability context, and signed Cyber Resilience Act evidence.

Genesis score6.76/10
Make Sbomdrift real.0/500
500 more votes and Sbomdrift is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The opportunity
Sep 11, 2026CRA Article 14 deadline
The case

An ordinary SBOM can list the dependency in the product, but it cannot explain which AI coding session introduced it, under what prompt, or what was known about it at that moment. That gap matters when an enterprise open-source steward must move from inventory to vulnerability evidence and regulatory reporting. Without capture at the session boundary, the team reconstructs provenance later from commits and model histories that were never designed to line up.

Who pays — and why

The enterprise open-source steward or product-security owner responsible for SBOM provenance and Cyber Resilience Act vulnerability evidence, although budget ownership for this emerging role still needs validation.

What it unlocks
Dependency provenance tied to the AI session and actor that introduced the change
A continuous path from dependency delta through known vulnerability context to signed evidence
An attribution history that ordinary post-build SBOM generation cannot reconstruct
How Genesis scored it
6.76across seven criteria
tension 8temporal 8blindspot 6buyer 6leverage 8convergence 5why-not 7
8
Productive tension

The product converts opaque AI-introduced dependencies into the provenance evidence regulation and security review now demand.

8
Temporal window

The September 11, 2026 Article 14 deadline is a named and imminent trigger.

5
Convergence

Multiple inbound and connected ideas support the family, though the overall echo remains moderate.

Why it scored well

An imminent CRA deadline converges with a confirmed gap in AI-session dependency provenance, creating a novel capture mechanism with strong software leverage.

What's holding it back

The open-source steward's budget authority is still emerging, instrumentation depends on changing coding-assistant extension surfaces, and SBOM incumbents can move toward richer provenance.

Signals detected4 sources crossed
SignalEU Cyber Resilience Act sources cited in Genesis research

SignalLineageLens repository

SignalForgeProof repository

SignalSPDX 3.0.1 specification

Direction briefsbomdrift.md
sbomdrift.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.