Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Codenotary Extends SBOM.sh for AI Supply Chain Visibility


Codenotary Extends SBOM.sh for AI Supply Chain Visibility
  • by: Source Logo
  • |
  • January 22, 2026

Codenotary has expanded its free SBOM.sh service to include AI applications, treating datasets as key software supply chain artifacts to boost visibility, security, and compliance.

Quick Intel

  • Codenotary updates free SBOM.sh service to support AI software supply chains by analyzing datasets as artifacts.
  • New features address gaps in traditional SBOMs that overlook data in AI applications.
  • Service handles massive scale with 3 million weekly API requests and over 100 million SBOMs analyzed historically.
  • Average SBOM shows 21 vulnerabilities, highlighting ongoing software supply chain risks.
  • Capabilities include data provenance, model lineage, inference operations, and ownership tracking for AI artifacts.
  • SBOM.sh enables free upload, analysis, and sharing for developers, DevOps, and security teams.

Closing the Security Gap in AI-Driven Software Supply Chains

Codenotary, a leader in software supply chain protection, announced enhancements to its free SBOM.sh service that extend support to AI applications. By treating datasets as essential software supply chain artifacts, the update evolves SBOM practices to match modern AI-driven system development, deployment, and operations. This closes a significant gap in security and compliance for organizations relying on AI technologies.

Traditional SBOM tools primarily focus on source code dependencies, leaving critical data components in AI applications unexamined. As Moshe Bar, CEO and co-founder, Codenotary, stated: “Traditional SBOM tools were built for an earlier era – focusing primarily on source code to improve visibility into the software supply chain. Security teams are swimming in SBOMs, but they’re not getting the actionable clarity they need — especially as AI transforms software with AI applications built on datasets which are entirely ignored by traditional SBOMs.”

Proven Scale and Real-World Impact of SBOM.sh

SBOM.sh has demonstrated strong adoption over three years, processing more than 100 million SBOMs at an average of 3 million API requests per week. Each analyzed SBOM typically reveals 21 vulnerabilities, underscoring persistent risks in software supply chains.

New AI-Focused Capabilities for Better Governance and Compliance

The enhanced service introduces targeted capabilities to strengthen AI governance and compliance. These include documentation of dataset sources, licensing terms, and governance controls to improve audit readiness and reduce compliance risks. It also captures model lineage details such as base-model origins, fine-tuning history, version identifiers, and update pathways for greater training transparency. Additional visibility covers inference endpoints, access controls, runtime integrations, and monitoring mechanisms. Ownership, approval, and accountability details are embedded throughout AI artifacts to support accountability.

Free and Accessible Tool for the Entire Ecosystem

SBOM.sh remains a straightforward, free tool for uploading, analyzing, and sharing both traditional SBOMs and AI software supply chain information, making advanced visibility accessible to developers, DevOps teams, and security organizations.

This update positions SBOM.sh as a vital resource for teams building AI-native applications, enabling better risk management, regulatory adherence, and overall trust in AI-powered software ecosystems.

About Codenotary

Used by hundreds of customers worldwide – including the world’s leading banks, governments, and defense organizations – Codenotary delivers technology that protects the entire software development lifecycle. Codenotary brings easy-to-use trust and integrity into modern software pipelines through advanced AI models that recognize attack patterns instantaneously. Codenotary can be deployed in minutes and integrates with modern CI/CD platforms.

  • AI SecuritySoftware Supply ChainDev Sec OpsAI Cybersecurity
News Disclaimer
  • Share