Hi, Ingmar! Sorry for the delayed reply. That’s a very good question.
The arguments for storing your SBOMs separately from artifacts are:
- SBOMs are not called, used, or distributed in the same way as artifacts
- Easier access controls: the people who need access to artifacts aren’t identical to the people who need access to SBOMs
But the argument for storing SBOMS alongside artifacts are:
- Makes security reviews easier
- Makes scanning with Lifecycle simpler
- Adds context to your SBOMs
- Potentially easier to configure with your CI/CD process
To answer your question: in the ideal scenario, you’d keep a copy of the SBOM alongside the artifacts, with another copy in a separate repository for distribution to vendors, regulatory purposes, etc. But it really all depends on what your organization is doing with SBOMs.