Shipped https://t.co/EhpbA25An4 v0.1.20 🚀
This one's all about EU Cyber Resilience Act (CRA) readiness.
- New cra-docs command, generates your Annex V Declaration of Conformity straight from the SBOM - Full CSAF v2.0 round-trip
- Article 24 OSS steward profile for maintainers
- CRA standards-drift detection in `watch`
- 14 compliance levels now, including CNSA 2.0 and NIST PQC
If you're staring down CRA deadlines, this should make life easier.
https://t.co/AVxz4QPojh
🚀https://t.co/EhpbA25An4 v0.1.19 is out: the first open-source CLI/TUI to score CBOM quality, not just parse crypto inventory.
This release puts real weight on PQC readiness and compliance, with scoring aligned to CNSA 2.0 + NIST PQC guidance, and grade caps when there’s zero post-quantum migration.
Full details: https://t.co/bn1j9oLWgC
🪄✨https://t.co/7zYdVwLlFD v0.1.18 is out
This release brings a major diff engine upgrade, enrichment support across multi-SBOM commands, a full TUI refresh across all 10 tabs, and new Go + Swift bindings (thanks to @MCh0rfa).
Release notes: https://t.co/KdMklKlOhv
Just shipped "Shai-Hulud Scan" 🐛an educational tool to visualize and analyze the massive Shai-Hulud 2.0 supply chain attack.Check if your deps are affected instantly (runs 100% in-browser!)
https://t.co/KudhT3jNWn
#Cyber#SupplyChainSecurity#Dagger#DevSecOps#OSS#dagger#NPM
Hitting a context/token limit shouldn’t break your flow. All major AI Providers—@OpenAI@AnthropicAI@GoogleAI@xai —should **auto-handoff**: warn users early, summarize work, and guide session continuation. Seamless workflows, no interruptions! #AI#UX#DX#CX
Hello @Azure
Is there a way to verify a ml or llm model signature before instantiate or deploy it. Within the new service azure for openai.
Assuming the llm model have already it's MLBoM and processed within the @sigstore ecosystem
Want to build the world's laziest control plane ⁉️
Yes you read that correctly...‼️
Let's see how far @ppog_penguin can push the limits of control plane laziness in his lastest blog https://t.co/Iy6CSLKVt4
#WebAssembly#Wasm#Severless