Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 3IT NewsSecurity

Why SBOMs, Signing, and Provenance Still Don't Tell You if Software Is Safe

Help Net Security, Monday, July 13th, 2026

SBOMs, signing, and provenance reveal what software contains but not what it does at runtime, calling for behavioral verification.

Ken Ammon argues that SBOMs, code signing, and provenance tracking are real progress but answer only three of four critical questions about software trust.

They show what software contains, verify its origin, and confirm build integrity, yet cannot predict harmful actions during execution.

A package can have a clean dependency tree and still perform dangerous actions, exposing the limits of composition-based trust.

As AI accelerates malicious code generation and modification, organizations should adopt a Zero Trust for Code model that evaluates behavioral capabilities before deployment.

This matters most for high-risk artifacts such as third-party packages and AI-generated code.

more →  ·  More from Security →