# DARPA Advances CMake Supply-Chain Security

Riverside Research and Kitware enhanced CMake through DARPA’s E-BOSS program so it can generate software inventory metadata natively. The capability is intended to help government and industry identify software dependencies and remediate vulnerabilities with less reliance on external scanning tools. The announcement describes a technology-development effort, not a new solicitation or an award with a stated value; it therefore signals a technical direction rather than an immediate bidding opportunity.

- For procurement teams, the work highlights software inventory and supply-chain visibility as capabilities relevant to secure software development and vulnerability response.
- Contractors developing software security, build-system, or dependency-management capabilities can assess whether native CMake inventory metadata fits their government offerings.
- The signal identifies no solicitation, contract value, or deadline. Firms interested in this area can watch for future E-BOSS integration and software supply-chain security opportunities.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity
**Published:** October 01, 2026

### Government Entities
- Defense Advanced Research Projects Agency (DARPA)

### Vendors
- Riverside Research (E-BOSS technology developer and CMake enhancement collaborator)
- Kitware, Inc. (CMake enhancement developer and E-BOSS technology collaborator)

### Sources
- [Riverside Research and Kitware, Inc. Strengthen Secure Deployment of Software Updates Across Complex Software Ecosystems](https://finance.yahoo.com/technology/ai/articles/riverside-research-kitware-inc-strengthen-144000994.html) - Yahoo Finance