Claim vs. Capability: A Comparative Analysis of the SBOM Generation Tools for Rust Projects

Md Fazle Rabbi, Arifa Islam Champa, Minhaz F. Zibran · 2025

As software supply chains grow increasingly complex with the extensive use of third-party components, the automatic generation of accurate Software Bills of Materials (SBOMs) becomes critical for managing security risks. In this study, we evaluate the effectiveness of seven SBOM generation tools that claim to produce accurate SBOMs from Rust projects. Specifically, we examine whether these tools can correctly identify component names, versions, and dependencies among components within 50 popular open-source Rust projects. Additionally, we assess whether any significant differences exist among the tools' automatic SBOM generation in the two popular formats, CycloneDX and SPDX. The findings from this study inform both practitioners and researchers about the current capabilities and limitations of existing SBOM tools and help in the selection of appropriate tools for better management of software dependencies and security risks.

Read the paper · More papers on PaperTik