The Authoritative Guide to AI/ML-BOM from CycloneDX just dropped. Full transparency into your ML supply chain: security, compliance, data lineage, reproducibility. AI regulations are here. Be ready.
#AI#AIBOM#SBOM#OWASP#CycloneDX
https://t.co/Q3ESdPA0GF
Join us on Wed May 28, 2025 in Barcelona for a hands-on hackathon to test Beta 1 of the Transparency Exchange API (TEA) — a new way to securely exchange SBOMs, attestations & more.
Free registration, thanks to @OWASP & @EcmaIntl
https://t.co/kRL2NFVFx6
#CycloneDX#SBOM
We're now accepting sponsorship for our 2024 conference, held at Brisbane State High School on December 7th. Get your brand in front of 450+ developers, testers, managers, and more!
DM or email [email protected] for a copy of our 2024 prospectus.
We are excited to announce that CycloneDX v1.6 has been officially ratified as an Ecma International standard following a decisive vote at the Ecma General Assembly on 26 June.
#SBOM#CycloneDX#OWASP#SoftwareSupplyChain#Ecma#TC54
https://t.co/xEHYl4Eebt
Today is the launch of @Semgrep Academy! Free courses on #AppSec, Secure Coding, #API Security, Functional Programming, and MORE! Please go check it out here:
https://t.co/wwkpXzXxQL
#OWASP CycloneDX v1.6 now available with support for Cryptography Bill of Materials (CBOM), Attestations, and more. Explore whats new in the:
- Authoritative Guide to CBOM
- Authoritative Guide to Attesations
- Authoritative Guide to SBOM, Second Edition
https://t.co/Q3ESdPA0GF
CycloneDX v1.6 has landed with support for tracking cryptographic assets and their dependencies for Post-Quantum Cryptography (PQC) readiness. #CBOM
CycloneDX Attestations provides “compliance as code”
Enhancements to existing AI/ML support…
#SBOM
https://t.co/dtMFPU6G4g
#BSidesBrisbane is back! We're seeking sponsors to help make this year's security conference a success. Email [email protected] for more info, or hit up the website for the prospectus here: https://t.co/sXy4xXzQ9H
Happy New Year to all! Start the year with a bang by securing your seat at the #BSidesBrisbane2024 event. Tickets are on sale now, don't miss out! The first 50 ticket sales using discount code BSIDES-EARLYBIRD will receive 10% off
Grab your tickets here: https://t.co/mMjKosc33a
The Ecma TC54 website is now live!
Visit https://t.co/0B7mKYYMu8 to learn more about the ongoing work the technical committee is pursuing and how to contribute.
#ecma#tc54#owasp#cyclonedx#sbom
Ecma TC54 is holding its first call on Thursday, 13 December at 10:30 U.S. Eastern. Meetings are open to Ecma member organizations.
Reach out to @stevespringett and @littledan for Zoom link.
Thank you SANS for this incredible honor. The Dependency-Track project would not be possible without our amazing community of maintainers, contributors, and the organizations that entrust #OWASP in helping reduce their supply chain risk. #SBOM#CycloneDX#EO14028
The @CycloneDX_Spec (Software Bill of Materials Standard) project took a step further with the convening of a new technical committee at @EcmaIntl. @coderpatros, co-lead of the project, spoke about this at @swisscyberstorm 2021. See his talk here: https://t.co/RAgZK4bPd9
Earlier today, Technical Committee 54 was officially convened within @EcmaIntl as a royalty-free task group. #TC54 is chartered with standardizing #OWASP@CycloneDX_Spec, standards and algorithms that advance transparency and sharing of this information across the supply chain.
We’re proud to announce the immediate availability of the SCVS BOM Maturity Model. The model allows organizations to evaluate #SBOM quality and mature and optimize their investment in software and system transparency.
https://t.co/B9sx3QddLW
#OWASP
Bloomberg is proud to be a founding member of @EcmaIntl's TC54, which will work with @owasp on standardizing #CycloneDX & related technologies to improve software and system transparency, which are critical to securing the #softwaresupplychain for modern applications
#SBOM
@tuckner@allanfriedman I wouldn't typically store it in the repo unless you are manually managing dependencies, and the SBOM. The first place I would store it is as an additional build artifact. And then publish it to something like Dependency-Track as part of the release process.