Skip to main content
Sweet Security
Visibility and Risk Prioritization

Runtime SBOM (Supply Chain)

A package inventory with runtime context: what is loaded, executed and vulnerable

The SBOM page lists every package detected in the environment and narrows them down through a funnel: all, loaded into memory, executed, vulnerable, critical. Each package carries its version and package manager (e.g. npm, PyPI), vulnerability counts by severity, the number of images and workloads it appears in, and the Executed, Loaded, Ingress and Egress indicators. The runtime-built SBOM is complemented by package reputation checks that help catch malicious or hijacked dependencies, such as the Shai-Hulud npm campaigns covered on our blog. Results can be exported for compliance reports and ticketing systems.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • A package funnel: total, loaded, executed, vulnerable, critical
  • Runtime indicators per package: Executed, Loaded, Ingress, Egress
  • Each package linked to the container images and workloads it runs in
  • A runtime-built SBOM plus package reputation checks
  • Export for reports, audits and ticketing integrations

Business benefits

  • Priority for packages that are vulnerable, executed and exposed to network traffic at the same time
  • A fast answer to "do we use package X" during a supply chain incident
  • Impact assessment from package to specific images and workloads
  • A bill of materials (SBOM) for customers and regulators
  • A complement to CI scanners (e.g. Aikido) with a picture of what actually runs in production
Sweet Security

Why Sweet Security?

Sweet Security is a Runtime CNAPP that detects and blocks attacks on cloud infrastructure, workloads, applications and AI agents while the attack is still under way. A lightweight eBPF sensor and cloud logs build a behavioral baseline of the environment, and a single detection engine correlates events across every layer to cut MTTR to minutes, according to Sweet Security data.

All products

Need Runtime SBOM (Supply Chain) in your organization?

As a certified Sweet Security partner, we'll help you deploy and configure the solution.

Book a free consultation