Not that I know what you would do with that information.
My scenario was to give an example of a supply chain attack where even a fully accurate SBOM would give no signal.
Fundamentally, if you are using FOSS distributed for no cost, and with no contractual relationship with the developers, then how complete and useful will a SBOM really be?
To be absolutely clear, I don't mean to dismiss the idea. But I remember Y2K when companies sent Y2K compliance request to vendors in their supply chain, including open source projects that had no obligation to the company, which struck me then as presumptuous. I don't like the assumption that because company X decides to use your free/open source software that obligates you to be aligned with industrial requirements.