Syft and Trivy reported 43.78% and 32.71% of lockfile packages across 2,050 JavaScript repositories in an Inria and ANSSI study, against 98.72% for cdxgen. The tool, its version and its flags decide what an SBOM lists, so that recipe belongs under version control.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
From 11 September 2026, an actively exploited vulnerability starts a 24-hour early warning, a 72-hour notification and a 14-day final report, all timed from awareness. The artifact that decides whether you make it is your SBOM archive.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence60
Swift Build became the default in Swift Package Manager with the September 15 release, so the engine under every package changed even for teams adopting none of 6.4's interop work. Everything else in the release waits for a source edit.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives62
- Confidence55
Two or three of the 95 were genuine, and reviewers had to read all of them to find out. The EU's 24-hour ENISA clock starts on September 11, 2026, and only evidence of active exploitation starts it.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+35
- Incentives88
- Confidence62
"Use .h5 or .keras instead of pickle" is not a mitigation. Scanning pipelines built on the pickle-only model of executable artifacts have a hole in them.
Reality
- Evidence46
- Adoption14
- Hype gap+12
- Incentives82
- Confidence41