Sbomdrift
A provenance-capture layer that links AI coding sessions to dependency changes, vulnerability context, and signed Cyber Resilience Act evidence.
An ordinary SBOM can list the dependency in the product, but it cannot explain which AI coding session introduced it, under what prompt, or what was known about it at that moment. That gap matters when an enterprise open-source steward must move from inventory to vulnerability evidence and regulatory reporting. Without capture at the session boundary, the team reconstructs provenance later from commits and model histories that were never designed to line up.
The enterprise open-source steward or product-security owner responsible for SBOM provenance and Cyber Resilience Act vulnerability evidence, although budget ownership for this emerging role still needs validation.
The product converts opaque AI-introduced dependencies into the provenance evidence regulation and security review now demand.
The September 11, 2026 Article 14 deadline is a named and imminent trigger.
Multiple inbound and connected ideas support the family, though the overall echo remains moderate.
An imminent CRA deadline converges with a confirmed gap in AI-session dependency provenance, creating a novel capture mechanism with strong software leverage.
The open-source steward's budget authority is still emerging, instrumentation depends on changing coding-assistant extension surfaces, and SBOM incumbents can move toward richer provenance.
Discussion
No comments yet — be the first to weigh in.
