Skip to main content

New Version of the OpenChain Telco SBOM Guide Validator Available

By 2025-05-09News

In April, the OpenChain Telco Work Group completed work on version 1.1 of the OpenChain Telco SBOM Guide. This document helps to define what is a quality Software Bill of Materials in the context of supply chain management. It uses SPDX, the NTIA Requirements and the experience of the Telco industry to provide a clear, simple and easily adjustable approach.

The following updates were made in version 1.1:

  • Both PackageChecksum and PackageVerificationCode are allowed as package hash.
  • The package hash is RECOMMENDED instead of MANDATORY.
  • ExternalRef is RECOMMENDED instead of MANDATORY.
  • FilesAnalyzed is no longer MANDATORY.
  • Examples are provided for the CISA SBOM Types.
  • A RECOMMENDED syntax is given for CISA SBOM Types.
  • sbomasm is a better example of SBOM merge tool.
  • Add reference to new CISA document.

An SBOM that conforms to version 1.0 of the Guide will also conform to version 1.1 of the Guide. The reverse is not true.

Get the Validator:

Our official validator for the Telco SBOM Quality Guide has been updated for version 1.1 and is available on the OpenChain Telco Work Group GitHub repo.

To install from PyPI, issue:
pip3 install openchain-telco-sbom-validator 
or 
pipx install openchain-telco-sbom-validator.

Coming Next:

Development of the next generation of the guide will occur via the Telco Work Group, and everyone is welcome to contribute.

The OpenChain Telco Work Group mailing list is here: 

The OpenChain Telco Work GitHub (for drafting) is here: 

Related News:

Community Credits:

Huge credit to Marc-Etienne Vargenau for his steady hand in chairing the OpenChain Telco Work Group, and to Jimmy Ahlberg of Ericsson for kicking off that work group, and his continued work as the Chair of the OpenChain Project Governing Board. Special thanks to all of our wonderful community, especially the contributors inside the OpenChain Telco Work Group who made this happen.

And… a big thank you to all of the Nokia team who have created and supported this validator!