- You likely have three or more layers of code, that has been compiled and likely recompiled. Source code is simply not available to be assessed
- A Software bill of materials can be helpful, however an SBOM is only a list, and is precisely as accurate, or inaccurate as the data provided by your vendor, and your vendor’s vendor, and your vendor’s vendor’s vendor.
- In most cases, and certainly in the aforementioned scenario an assessment of the compiled binary is the only available source of truth.
