Software Bill of Materials
Software Bill of Materials
Simplebooklet Marketing Inc. | Effective December 1, 2024
Simplebooklet does not currently maintain a formal Software Bill of Materials (SBOM) in a standardised machine-readable format (such as CycloneDX or SPDX). As a small SaaS organisation, we have not yet implemented automated SBOM generation as part of our build pipeline.
However, we are able to provide the following on request:
- A list of our primary open source and third-party dependencies including version information, sourced directly from our package manifest files (package.json / package-lock.json or equivalent)
- Information on our major frameworks, runtime environments, and infrastructure components
- Details of our dependency vulnerability scanning practices via GitHub Dependabot and npm audit
We recognise that formal SBOM generation and disclosure is an emerging industry standard, accelerated by recent supply chain security guidance and executive-level policy direction. Automated SBOM generation is on our security roadmap as we mature our development pipeline.
Updated on: 08/09/2026
Thank you!
