A software bill of materials (SBOM) lists every package in an image with its version and a package URL (purl), in a standard format: SPDX (from the Linux Foundation) or CycloneDX (from OWASP). When the next critical advisory appears, an SBOM answers "which of our images contain that package?" without rescanning anything. Anchore 391,549 's Syft 9,619 (github.com/anchore/syft (https://github.com/anchore/syft 9,619 ), 1.52.0, Apache-2.0) generates one, and Grype 12,938 can scan the SBOM instead of the image:
syft -q l3-booknest-api:latest -o spdx-json=booknest-api.spdx.json
jq -r '.spdxVersion, (.packages | length)' booknest-api.spdx.json
jq -r '.packages[] | select(.name == "express" or .name == "pg") | .externalRefs[]
| select(.referenceType == "purl") | .referenceLocator' booknest-api.spdx.json
grype -q sbom:booknest-api.spdx.json -o json | jq '.matches | length'SPDX-2.3 319 pkg:npm/express@5.2.1 pkg:npm/pg@8.23.0 228
The SBOM lists 319 packages, Debian 319 's and npm 2,036 's together, and scanning it found the same 228 matches as Grype's image scan, without unpacking anything. BuildKit 10,294 can also attach an SBOM to the image as an attestation (docker buildx build --sbom=true --push). Store SBOMs with each release, next to its signature (cosign Signing).