SBOM generation, CVE scanning, supply chain attack detection, license compliance, dependency pinning, and artifact verification.