Nexus Repository Best Practices: Cleanup Policies, Part 2

Hi, Ingmar! Sorry for the delayed reply. That’s a very good question.

The arguments for storing your SBOMs separately from artifacts are:

  • SBOMs are not called, used, or distributed in the same way as artifacts
  • Easier access controls: the people who need access to artifacts aren’t identical to the people who need access to SBOMs

But the argument for storing SBOMS alongside artifacts are:

  • Makes security reviews easier
  • Makes scanning with Lifecycle simpler
  • Adds context to your SBOMs
  • Potentially easier to configure with your CI/CD process

To answer your question: in the ideal scenario, you’d keep a copy of the SBOM alongside the artifacts, with another copy in a separate repository for distribution to vendors, regulatory purposes, etc. But it really all depends on what your organization is doing with SBOMs.

1 Like