Your SBOM Is Fan Fiction
10 hours ago
- Traditional SBOMs are fictional because they are generated at build time and do not reflect runtime state, missing libraries manually installed, upgraded but not restarted, or dynamically loaded plugins.
- The kernel already contains the real software bill of materials via /proc, including /proc/<pid>/maps, exe, fd, cgroup, and /proc/net/tcp.
- yeet's sys_graph provides a GraphQL interface to query /proc from JavaScript in a sandboxed isolate, eliminating the need to write complex parsers.
- The walk of /proc runs in a Worker isolate to avoid blocking the main page, using postMessage for progress and results.
- yeetkit enables 'use server' functions to enrich the BOM with package manager data (rpm, dpkg) and file hashes, while keeping the isolate network- and file-constrained.
- The yeet service allows a fleet view by routing queries through a hub that aggregates multiple node services, showing live inventory with unreachable nodes indicated.
- yeet:sym Inspector can open ELF binaries and search for specific symbols in memory, enabling correlation of CVEs to actual functions loaded in processes, including statically linked binaries not tracked by package managers.
- The entire tool is open source and available for use on your own machines.