Skip to content
AITroveRead. Build. Understand.
Make this comfortable

SBOM binding: keep the inventory attached to the tested digest

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

A build can produce an image, tests can run against it, and a later job can generate an SBOM from a mutable tag that has already moved. The resulting document may parse correctly while describing different bytes. Bind the inventory subject to the immutable image digest, verify that digest again at promotion, and require the inventory to be retrievable in the destination registry or evidence store. An inventory is a claim about a subject, not a replacement for verifying the subject itself.

Operational decision

A document-export service builds one image and records its manifest digest. The verification job runs tests against that digest, creates an SBOM from the same digest, and stores a signed mapping of tested digest, SBOM digest, build run, and source revision. A promotion job copies the image by digest into a production registry, resolves the destination digest, and checks it against the tested subject before copying the SBOM. If registry conversion changes the manifest digest while preserving layers, treat that as a new subject requiring an explicit equivalence review; do not silently relabel the old document. Attempt a race in a disposable registry: move the release tag after tests but before inventory generation, then show that digest-based retrieval still selects the tested artifact. Delete the tag and confirm the SBOM remains retrievable by its subject digest. Keep promotion results in an append-only release record so a future incident can identify both the deployed image and the inventory version used for its risk decision. For a multi-platform index, record whether the document covers the index or a particular child manifest.

Output
Document-export release binding
Test subject: immutable image digest
SBOM subject: same digest and platform scope
SBOM artifact: own digest and generation run
Promotion: destination manifest digest verified
Deployment: digest recorded from workload specification
Race test: mutable release tag moved after tests

Cost and verification

Verification is a small number of digest lookups plus any image scan needed to produce the inventory; scanning the same image repeatedly can dominate pipeline time. Retaining an SBOM for each release adds storage proportional to release count and inventory size. Measure releases without a subject-matched inventory, promotion mismatches, and time to retrieve historical evidence. The strongest scanner result does not help if deployment points at a different digest.

Common Mistakes

  • Do not generate an SBOM from a tag after testing a digest.
  • Do not assume a registry copy preserved the manifest digest without checking.
  • Do not lose the inventory when the human-readable tag is cleaned up.

Connected lessons

Practice and check

devops
supply-chain
Storage details