One thing I wasn’t able to work into the Q&A was Cisco’s leadership in a cool new open source project: @gitBOM https://t.co/nDc9ickOII We see this as a complement to the work happening in the SBOM space and encourage folks to get involved.
@gitbom I like that #GitBOM identifiers enable any metadata in the software supply chain (#SBOM#CSAF) to reference the specific software artifact(s) that they describe.