If I recall, k8s is producing SBOM files somewhere, we should ensure that our check works for it. @jeefy can look at this