
Replication resources for paper: "A Large Scale Empirical Analysis on the Adherence Gap between Standards and Tools in SBOM" Usage The code repository is at https://github.com/dw763j/SAP, this zenodo includes the generated SBOMs and test code. The all-sboms.zip includes all the 27,795 SBOMs of 3,287 repositories generated by the six tools in either CycloneDX or SPDX standards as described in paper. The run-on-test-sboms.zip includes codes and some SBOMs for fast test purpose. Download and unzip run-on-test-sboms.zip, cd into the dir and run `pip install -r requirements.txt` and then run `python test-run.py`, you will get the analysis results on the test-sboms. If you want to rerun the whole process of SAP on all SBOMs, download and unzip the all-sboms.zip(around 50GB after unzip), and change the dirs in test-run.py(need to follow the language dir structure) and rerun again(clean up of the results dir is recommended).v1.1: minor code refactor. v1.2: minor code refactor.
Software Supply Chain, SBOM Tools, SBOM
Software Supply Chain, SBOM Tools, SBOM
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 1 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
