> The SBOM enumerates these components in a product. Um, hasn't that already been nicely handled for decades by all the various package managers that support dependency requirements? The real problem is not that the information doesn't exist, it's that none of the builders/buyers/users *care* about any of that, and are often times incentivized to create black boxes that move fast and break things. @Raggle > Wouldn’t targeting Russia based on IPs also hit neighboring regions that have no part in the current conflict? Not really. To the extent that geolocation of networks (and/or their owners) is accurate in the database, you're going to hit what you're aiming for. The greater problem is all the Russian botnets or cloud services in use that are located outside the country itself. There really is no "no part in the current conflict" so long as Google, Microsoft, and Amazon aren't actively doing anything to eliminate Russian customers/traffic from their services. @TimH > Another gentle reminder: Don’t harm people over actions of their government that they have no control over. Well, as the old saying goes, you are known by the company you keep. I definitely have a great deal of sympathy for Russians that are themselves victims of Putin's ambitions. But there are enough Russians that either agree with him or just don't care about their war with Ukraine (for whatever reason, including misinformation by state-run media) that people of conscience *must* take action. If the Russian government doesn't represent the majority of the Russian people, *they* are responsible for getting it back under control. Same is essentially true for everyone making their day-to-day choices. You have absolute control of where you stand on issues big and small. That said, though, sabotaging software like this is *not* the way to go about it. 2ccb456151148bc4aff848b0f936e457c7eaa4617a23e00df1fdcaf0171670c3