Modern software often relies on thousands of third-party components, creating dependency networks that complicate security. Current methods for tracking these inventories—relying on external scanners or self-reporting—often introduce gaps in visibility. By embedding metadata directly into the build process, the new CMake enhancements allow for authoritative dependency modeling and deterministic output, ensuring that security data remains as accurate as the build instructions themselves.
In section Releases
Riverside Research and Kitware Automate Software Security via CMake
Updating critical software components in complex ecosystems often resembles performing engine repairs on a vehicle moving at highway speeds. To solve this, Riverside Research and Kitware, Inc. have integrated native software inventory capabilities directly into CMake, allowing organizations to track and patch vulnerabilities with greater precision and minimal operational disruption.

This development stems from the Enhanced Software Bill of Materials (SBOM) for the Optimized Software Sustainment (E-BOSS) program, funded by DARPA. By moving these capabilities into the build system, developers gain access to automated, reproducible results without the need for additional, disconnected tooling. The project aims to streamline vulnerability triage across government and industry, effectively reducing the risk of supply-chain attacks while allowing agencies to tailor their security posture to specific mission requirements.
Comments (0)
No comments yet. Be the first!