{"id":11989,"date":"2026-05-15T05:01:41","date_gmt":"2026-05-15T05:01:41","guid":{"rendered":"https:\/\/virconlegal.com\/term\/yazilim-malzeme-listesi-sbom\/"},"modified":"2026-05-15T05:10:07","modified_gmt":"2026-05-15T05:10:07","slug":"yazilim-malzeme-listesi-sbom","status":"publish","type":"term","link":"https:\/\/virconlegal.com\/tr\/term\/yazilim-malzeme-listesi-sbom\/","title":{"rendered":"Yaz\u0131l\u0131m Malzeme Listesi (SBOM)"},"content":{"rendered":"<h3>TLDR:<\/h3>\n<p>Yaz\u0131l\u0131m Malzeme Listesi (Software Bill of Materials, SBOM), bir yaz\u0131l\u0131m \u00fcr\u00fcn\u00fc olu\u015fturmak i\u00e7in kullan\u0131lan t\u00fcm yaz\u0131l\u0131m bile\u015fenleri, k\u00fct\u00fcphaneler ve ba\u011f\u0131ml\u0131l\u0131klar\u0131n\u2014\u00fc\u00e7\u00fcnc\u00fc taraf a\u00e7\u0131k kaynak bile\u015fenleri, s\u00fcr\u00fcmleri ve lisanslar\u0131 dahil\u2014resmi, makine okunabilir bir envanteridir. SBOM&#8217;lar tedarik zinciri g\u00fcvenli\u011fi, a\u00e7\u0131k y\u00f6netimi ve lisans uyumu i\u00e7in temeldir.<\/p>\n<h3>SBOM&#8217;lar Neden \u00d6nemli<\/h3>\n<p>Modern yaz\u0131l\u0131m kapsaml\u0131 a\u00e7\u0131k kaynak ba\u011f\u0131ml\u0131l\u0131klardan in\u015fa edilir\u2014tipik bir uygulama y\u00fczlerce veya binlerce \u00fc\u00e7\u00fcnc\u00fc taraf k\u00fct\u00fcphane i\u00e7erir. Yayg\u0131n olarak kullan\u0131lan bir bile\u015fende bir a\u00e7\u0131k ortaya \u00e7\u0131kt\u0131\u011f\u0131nda (2021 sonunda Log4Shell milyonlarca uygulamay\u0131 etkiledi), kurulu\u015flar\u0131n hangi \u00fcr\u00fcnlerin etkilendi\u011fini h\u0131zl\u0131ca belirlemesi gerekir. SBOM&#8217;lar olmadan bu analiz g\u00fcnler veya haftalar al\u0131r; SBOM&#8217;larla, dakikalar i\u00e7inde yap\u0131labilir. SBOM&#8217;lar ayr\u0131ca lisans uyum do\u011frulamas\u0131n\u0131 m\u00fcmk\u00fcn k\u0131lar\u2014istenmeyen y\u00fck\u00fcml\u00fcl\u00fckler dayatabilecek GPL lisansl\u0131 kodu tan\u0131mlama.<\/p>\n<h3>Formatlar ve Standartlar<\/h3>\n<p>\u0130ki b\u00fcy\u00fck SBOM format\u0131 bask\u0131nd\u0131r: SPDX (Software Package Data Exchange, <a href=\"https:\/\/virconlegal.com\/tr\/term\/tesvik-edici-hisse-senedi-opsiyonu-iso\/\">ISO<\/a>\/IEC 5962:2021, Linux Foundation taraf\u0131ndan desteklenir) ve CycloneDX (zengin a\u00e7\u0131k takibi ile OWASP taraf\u0131ndan geli\u015ftirilen). Her ikisi de makine okunabilir (JSON, XML, vb.) ve otomatik ara\u00e7lar\u0131 destekler. \u00dcretim birden \u00e7ok noktada yap\u0131labilir: kaynak d\u00fczeyi (kaynak kodu ba\u011f\u0131ml\u0131l\u0131klar\u0131n\u0131 analiz etme), derleme zaman\u0131 (derlemelerde ger\u00e7ekten neler dahil oldu\u011funu yakalama) ve ikili d\u00fczey (derlenmi\u015f eserleri analiz etme).<\/p>\n<h3>D\u00fczenleyici ve M\u00fc\u015fteri Gereksinimleri<\/h3>\n<p>SBOM gereksinimleri h\u0131zla \u00e7o\u011falm\u0131\u015ft\u0131r: ABD Y\u00fcr\u00fctme Emri 14028 (May\u0131s 2021) federal yaz\u0131l\u0131m sat\u0131c\u0131lar\u0131 i\u00e7in SBOM gerektirir; AB Siber Dayan\u0131kl\u0131l\u0131k Yasas\u0131 dijital \u00f6\u011feleri olan \u00fcr\u00fcnler i\u00e7in SBOM zorunlu k\u0131lar (Aral\u0131k 2027&#8217;den itibaren y\u00fcr\u00fcrl\u00fc\u011fe giri\u015f); FDA t\u0131bbi cihazlar i\u00e7in SBOM gerektirir; b\u00fcy\u00fck kurulu\u015flar sat\u0131n almada giderek artan bi\u00e7imde SBOM gerektirir. \u00dcretim ara\u00e7lar\u0131 Syft, Trivy, Anchore ve platforma \u00f6zg\u00fc ara\u00e7lar\u0131 (npm, Maven, pip SBOM&#8217;lara d\u00f6n\u00fc\u015ft\u00fcr\u00fclebilecek yerel ba\u011f\u0131ml\u0131l\u0131k manifestleri \u00fcretir) i\u00e7erir.<\/p>\n<h3>T\u00fcrk Pazar\u0131 \u0130\u00e7in \u00d6nemi<\/h3>\n<p>T\u00fcrk yaz\u0131l\u0131m \u015firketleri i\u00e7in, AB&#8217;ye ihracat art\u0131\u015f\u0131 SBOM gereksinimlerini \u00f6ne \u00e7\u0131kar\u0131r. T\u00fcrkiye&#8217;nin kendi siber g\u00fcvenlik d\u00fczenlemesi olgunla\u015ft\u0131k\u00e7a benzer gereksinimler beklenmelidir.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TLDR: Yaz\u0131l\u0131m Malzeme Listesi (Software Bill of Materials, SBOM), bir yaz\u0131l\u0131m \u00fcr\u00fcn\u00fc olu\u015fturmak i\u00e7in kullan\u0131lan t\u00fcm yaz\u0131l\u0131m bile\u015fenleri, k\u00fct\u00fcphaneler ve ba\u011f\u0131ml\u0131l\u0131klar\u0131n\u2014\u00fc\u00e7\u00fcnc\u00fc taraf a\u00e7\u0131k kaynak bile\u015fenleri, s\u00fcr\u00fcmleri ve lisanslar\u0131 dahil\u2014resmi, makine okunabilir bir envanteridir. SBOM&#8217;lar tedarik zinciri g\u00fcvenli\u011fi, a\u00e7\u0131k y\u00f6netimi ve lisans uyumu i\u00e7in temeldir. SBOM&#8217;lar Neden \u00d6nemli Modern yaz\u0131l\u0131m kapsaml\u0131 a\u00e7\u0131k kaynak ba\u011f\u0131ml\u0131l\u0131klardan in\u015fa edilir\u2014tipik [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"categories":[],"class_list":["post-11989","term","type-term","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/term\/11989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/term"}],"about":[{"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/types\/term"}],"author":[{"embeddable":true,"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/comments?post=11989"}],"version-history":[{"count":1,"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/term\/11989\/revisions"}],"predecessor-version":[{"id":12291,"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/term\/11989\/revisions\/12291"}],"wp:attachment":[{"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/media?parent=11989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/virconlegal.com\/tr\/wp-json\/wp\/v2\/categories?post=11989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}