Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.