SBOM getting started: generate, use, and capture compliance value

SBOM getting started: what SPDX/CycloneDX contain, how to generate them in CI, and how they help vulnerability response and compliance audits. For engineering and compliance—use SBOMs rather than archive them, and understand their relationship to SCA gates. Confirm details against official docs and the current product version.