You Built and Signed Your SBOM. Now What? Store, Verify, Manage

Javier Martinez published a sharp piece on September 24, 2026: Why are SBOMs failing to stop supply chain attacks? I agree with his analysis. I recommend reading it before continuing here. TLDR of the Sysdig Article Martinez starts from a simple idea. An SBOM plus signatures and attestations should give us attribution (who built it), provenance (where it comes from) and content (what is inside). In a Kubernetes flow that means verifying attestations before deploy, then generating and signing your own SBOM when you ship. ...

October 6, 2026 · 11 min · 2326 words · Matteo Bisi