#SBOM alone may not encode enough detail to separate non-exploitable vulnerabilities from exploitable ones writes Surendra Pathak in our latest guest blog on VDR, VEX, OpenVEX & CSAF https://t.co/J1pEqC0VOC
Cisco announces SBOMs for recent @cisco products. Great @jefschut blog highlighting 1) the importance of transparency, 2) acknowledging that #SBOM implementation will be a journey, but that 3) we all have to start now for better #supplychain security https://t.co/tnbxa0QajZ
.@SPDX_SBOM v3.0 is in the works, and it's expected to include several major changes from the current v2.3. Get an early look at what to expect — such as support for emerging BOM use cases like AI and data — in our new blog. #SBOM@SPDXTeam
https://t.co/t0M5m8w4Nu
Fun! A think tank analysis combines my passion for both Taylor Swift and #SBOM.
Nice job by @DFRLab & @AtlanticCouncil@CyberStatecraft for unpacking some of the common (and dare we say imperfect) concerns about SBOM from beltway lobbyists.
https://t.co/jCv8b8tKAI
I look forward to attending the SBOM-a-rama next week in Los Angeles, hosted by the
@CISAgov.
@theopenssf and @spdxteam believe SBOMs are a core part of securing our Open Source supply chain. Let me know if you'll be there!
https://t.co/aX6v2VpHyx
📢bom v0.5.1 the @kubernetesio SPDX SBOM tool is out!
This release embeds the @SPDXTeam license list to generate SBOMs in airgapped envs, adds support for apk packages + lots of bug fixes
Big thanks to @sbs0x@developerguyba@rosejudge5 and @comedordexis for contributing!
🎉Excited to see that an SPDX SBOM can now be generated by a push of an export button! Thanks for making things easier for all the open source developers on @github! Awesome work @jhutchings0