sbom-provenance

Installation
SKILL.md

SBOM and Provenance

Security Requirement

All releases of AI software MUST include a Software Bill of Materials (SBOM) to provide transparency about the components and dependencies included in the software.

What an SBOM Contains

Component Details
Direct dependencies All libraries and packages directly used
Transitive dependencies Dependencies of dependencies
Versions Exact versions of all components
Licenses License information for each component
Hashes Cryptographic hashes for integrity verification
Supplier information Who provides each component

Standard Formats

Installs
2
GitHub Stars
52
First Seen
Jul 18, 2026
sbom-provenance — redhatproductsecurity/prodsec-skills