#SoftwareCompositionAnalysis & #SBOM generation in Bytesafe provide easy ways to identify software assets and track #opensource risk.
But what about distribution of the SBOM after it’s been created? Sharing is caring with #RKVST SBOM Hub.
Learn more: https://t.co/gMDOUb4r9L
Thanks automatic algorithm for being so contrite. I’d be happier if someone human had looked into my account and sent something even vaguely context-aware. Pray tell me, what was I recently trying to buy, and how did you work out that it’s so out of character for me?
@thedavidbrumley @joshbressers And also: is this “major” bug major to me? Which of these things can actually be exploited? Updating everything all of the time is impossible so confidently and currently prioritising the real problems is a key benefit we need to be aiming for.
@joshbressers Which is good, because we’ll never have all of these things done in every case. That’s why overall supply chain transparency is so important: know what was done, what that actually proves, and what that means in your specific risk context. “Trust” is extremely subjective… (2/2)
@joshbressers I’m not sure ‘hierarchy’ or strict set of steps quite captures it. All of these things are important in different ways, and the opportunity to do them is more present at various lifecycle stages, but it doesn’t mean you cannot get value from step C if step B was missed (1/2)
@CindyProvin @solcates @bridgetkenyon@gcluley@NiloofarHowe@thegrugq@annie_bdc@e_kaspersky@laparisa@mikko Originally: the chance to work on an endless supply of interesting and challenging puzzles. Now: the belief that every improvement we make to the underlying security and trust of digital infrastructure opens up many opportunities for life to work better, faster, safer, greener.
Meet @brianbehlendorf the Executive Director of Hyperledger Project, @mpiekarska8 the Director of Ecosystem and @jongeater - Hyperledger Board Member at the third #Hyperledger meet up in Prague on November 2. https://t.co/Z0Mz43ChVx
To everyone writing about adverts, microtargeting, the law, Turkey, racists, Jo Cox today, never forget this graph. It's absolutely key. To everyone who says "Does advertising work?" Yes. Yes, it does.
“Using the public cloud can be fine but you need to have the same security controls throughout [...] just using what the cloud provides is not enough [...] you can’t have fragmentation of security tools: you need consistency [...] centrally controlled” Mandeep Singh, Bloomberg
“Every time I get a call in the middle of the night it’s about security. No one ever calls to talk about the latest trends in Agile or something” @CATechnologies