DOI: 10.1002/appl.70209 ISSN: 2702-4288

SBOM Tooling Ecosystem: A Systematic Literature Review

Mohd Nizam Mohd. Mydin, Delina Mei Yin Beh, Shafiza Mohd. Shariff

ABSTRACT

The software bill of materials (SBOM) has emerged as an important mechanism for software supply chain transparency following high‐profile attacks such as Log4Shell and SolarWinds. However, the practical value of an SBOM depends entirely on its accuracy and completeness, which are shaped by the capabilities and limitations of SBOM generation tools. This systematic literature review synthesizes the current state of SBOM generation methodologies and tools, identifies the key challenges to achieving high‐fidelity SBOMs, and proposes directions for future research. Following the PRISMA framework, 146 records were identified from IEEE Xplore, Scopus, and reference snowballing. After removing duplicates and applying inclusion criteria, 27 peer‐reviewed studies and 5 selected preprints, all published between 2022 and September 2025, were retained for final synthesis. Thematic analysis was applied to categorize generation methodologies, assess tool performance across software ecosystems, and identify persistent challenges. This review synthesizes and extends existing categorizations of SBOM generation methodologies (static analysis, build‐time introspection, binary analysis, and hybrid analysis), provides a cross‐ecosystem analysis of tool performance, and articulates an evidence‐based research agenda for high‐fidelity SBOMs. Four key insights emerge from the synthesis. First, there is a fundamental trade‐off between generation methodologies—static analysis offers speed and scalability, but relies heavily on metadata quality, while build‐time introspection and binary analysis provide higher fidelity but with increased complexity. Second, tool effectiveness varies significantly across ecosystems (Java, Python, JavaScript, and containerized environments) due to differences in dependency management conventions and metadata standards. Third, polyglot systems that combine multiple programming languages exacerbate visibility gaps and expose the limits of single‐ecosystem tools. Fourth, the literature converges on an emerging research agenda prioritizing hybrid analysis techniques, AI‐powered binary analysis, runtime context integration, and improved developer usability. Although the SBOM tooling ecosystem is evolving rapidly, fragmentation and inconsistency in delivering accurate and complete outputs remain significant challenges. Addressing these challenges through hybrid and ecosystem‐aware approaches is essential for the widespread adoption of trustworthy SBOMs and the strengthening of software supply chain security.