@prbh.bsky.social(@_prbh) 's Twitter Profile Photo

What a pleasant surprise to see my project used by Daniel Cuthbert to generate an SBOM. Please feel free to update to 10.4.1 as well as use depscan. github.com/Santandersecur…

account_circle
Cybersecurity and Infrastructure Security Agency(@CISAgov) 's Twitter Profile Photo

With OpenSSF and DHS S&T, we announced Protobom, a new and innovative open source software supply chain tool which enables all orgs to read/generate and file data, as well as translate this data across standard industry SBOM formats. openssf.org/projects/proto…

With @openssf and @dhsscitech, we announced Protobom, a new and innovative open source software supply chain tool which enables all orgs to read/generate #SBOMs and file data, as well as translate this data across standard industry SBOM formats. openssf.org/projects/proto…
account_circle
Beth Pariseau(@PariseauTT) 's Twitter Profile Photo

An effort to standardize data exchange is now governed by the @OpenSSF, and there's more to come under a Homeland Security program. Omkhar Arasaratnam Katie Norton techtarget.com/searchitoperat… via @techtargetnews

account_circle
Interlynk(@InterlynkIo) 's Twitter Profile Photo

Why is not the prevention yet still a vital part of remediation for backdoor

... and other lessons from

link.medium.com/OYsAuOzyNIb

account_circle
Sam Stepanyan(@securestep9) 's Twitter Profile Photo

Looking forward to running the OWASP London Chapter Meetup tonight! Learn about SCA, SBOM & Software Supply Chain Security. The raffle prize will be a Meta Quest2 VR headset generously sponsored by Checkmarx

Last few seats remaining!
Register here:
👇
meetup.com/owasp-london/e…

Looking forward to running the @OWASPLondon Chapter Meetup tonight! Learn about SCA, SBOM & Software Supply Chain Security. The raffle prize will be a Meta Quest2 VR headset generously sponsored by @Checkmarx  

Last few seats remaining!
Register here:
👇
meetup.com/owasp-london/e…
account_circle
OpenSSF(@openssf) 's Twitter Profile Photo

Adolfo García Veytia (puerco), Staff Software Engineer from stacklok, delves into the emerging challenges in open source software. He discusses the new foundations of SBOM and outlines the next steps for the SBOM ecosystem.

Adolfo García Veytia (@puerco), Staff Software Engineer from @StackLokHQ, delves into the emerging challenges in open source software. He discusses the new foundations of SBOM and outlines the next steps for the SBOM ecosystem. 
#SOSScommunity
account_circle
Tweag(@tweagio) 's Twitter Profile Photo

It's certainly been our observation that SBOMs have been a big topic in the industry even before the XZ Utils backdoor discovery. As for us, we've been developing, with the support of NLNet, in a tool to generate SBOMs from Nix packages: Genealogos github.com/tweag/genealog… .

account_circle
Allan is @allanfriedman on bsky & infosec.exchange(@allanfriedman) 's Twitter Profile Photo

After 2.5 months pleasantly at home, back on the road again. Heading to Seattle for the North American Open Source Summit. If you’re around, and want to talk SW supply chain or , let me know. And come see my talk rolling out our new work on EOL/EOS software-Wed at 1pm.

After 2.5 months pleasantly at home, back on the road again. Heading to Seattle for the North American Open Source Summit. If you’re around, and want to talk SW supply chain or #SBOM, let me know. And come see my talk rolling out our new work on EOL/EOS software-Wed at 1pm.
account_circle
Global Cyber Threat Intel(@cipherstorm) 's Twitter Profile Photo

Why you need an SBOM (Software Bill Of Materials): SBOMs are security analysis artifacts becoming required by more companies due to internal policies and government regulation. If you sell or buy software, you should know the what, why, and how of the… securityboulevard.com/2024/04/why-yo…

Why you need an SBOM (Software Bill Of Materials): SBOMs are security analysis artifacts becoming required by more companies due to internal policies and government regulation. If you sell or buy software, you should know the what, why, and how of the… securityboulevard.com/2024/04/why-yo…
account_circle
SPDX SBOM(@SPDX_SBOM) 's Twitter Profile Photo

We are thrilled to announce the release of SPDX 3.0, introducing a comprehensive set of updates, encompassing the model, specification, and license list, with the new addition of SPDX profiles to handle modern system use cases.

Read the announcement:
hubs.la/Q02s_TLM0

We are thrilled to announce the release of SPDX 3.0, introducing a comprehensive set of updates, encompassing the model, specification, and license list, with the new addition of SPDX profiles to handle modern system use cases.

Read the announcement:
hubs.la/Q02s_TLM0
account_circle
OpsMatters(@opsmatters_uk) 's Twitter Profile Photo

The latest update for includes 'Why you need an (Software Bill Of Materials)' and 'Managing Secrets Security at any Scale: introducing the GitGuardian Needs Quiz'.

opsmtrs.com/3XY1xZb

account_circle
ところてん(@tokoroten) 's Twitter Profile Photo

SBOM管理が進む

株式市場や会計団体が「依存しているソフトウェアに対する貢献(コードを利用する、コードを書く)」を「エシカリティ」として計上、株式の格付けに使われる

現在の人的資本開示や、GHGプロトコルと同じような流れで、ソフトウェア資産は人類の資産であるとする流れあるかなー

account_circle