Home New Trending Search
About Privacy Terms
#
#CycloneDX
Posts tagged #CycloneDX on Bluesky
Preview
Guides and Resources | CycloneDX Unlock valuable insights and practical guidance to help your organization maximize CycloneDX and reduce supply chain risk.

The Authoritative Guide to AI/ML-BOM from CycloneDX just dropped. Full transparency into your AI supply chain: security, compliance, data lineage, reproducibility. AI regulations are here. Be ready.

#AI #AIBOM #SBOM #OWASP #CycloneDX

cyclonedx.org/guides/

1 1 0 0

Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

#SBOM #CYCLONEDX #SPDX #POTATOSECURITY #CRA #EUCRA

1 0 1 0
Post image

Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

#SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

1 0 1 0
Post image

The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

fosdem.org/2026/schedule/event/RFFD...

#SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

2 2 0 0
Preview
Get Involved in the Open Regulatory Compliance Working Group | Open Regulatory Compliance Working Group The open source community is collaborating to establish common specifications for secure software development based on open source best practices.

At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

https://orcwg.org/participate/

#SBOM #CYCLONEDX #SPDX #PURL

0 0 0 0
Post image

Going to #FOSDEM? Please join us to celebrate our recent success stories in ECMA TC54! #CycloneDX 1.7, Package URL (#PURL) 1.0 and the Common Lifecycle Enumeration 1.0 (#CLE). We are working to improve all of these and complete the Transparency Exchange API […]

[Original post on infosec.exchange]

0 1 0 0
SBOM Live  - What type of SBOM is required by the EU Cyber Resilience Act (CRA)?
SBOM Live - What type of SBOM is required by the EU Cyber Resilience Act (CRA)? YouTube video by SBOM Europe

The EU Cyber Resilience Act requires manufacturers to have an SBOM - but what does that mean? Last Friday we had a chat about the CRA and SBOMs and it turned out it wasn't easy to figure out.
Check the video at youtu.be/W-E55x8fPyY?...

#SBOM #EUCRA #CRA #SPDX #CYCLONEDX

1 2 0 0
Preview
PEP 770 Software Bill‑of‑Materials (SBOM) data from PyPI, Fedora, and Red Hat This year I authored PEP 770 which proposed a new standardized location for Software Bill-of-Materials (SBOM) data within Python wheel archives. SBOM data can now be stored in (package)-(version).d...

PEP 770 was accepted in April of this year, what has happened since then?

sethmlarson.dev/pep-770-sbom...

#Python #SBOM #CycloneDX #SPDX #auditwheel #cibuildwheel

6 2 0 0
Post image

Heading to #PQC2025?

Join IBM, The Linux Foundation, and SCANOSS for the CBOM Hands-On Workshop
28 Oct, 9 AM, Room 1.

#CBOM #CycloneDX #CryptoAgility #OpenSource #SCANOSS

1 0 0 0
IBM is donating its CBOM toolset to the Linux Foundation At IBM Research, we’re inventing what’s next in AI, quantum computing, and hybrid cloud to shape the world ahead.

IBM donated its CBOM tooling to the Linux foundation. Hopefully this will enable CBOMs more widely.

research.ibm.com/blog/cryptog...

#cryptoagility #cbom #cyclonedx #cryptography

0 0 0 0
Post image

Zen of SBOM #4: "Completeness improves the usefulness of the SBOM"

#SBOM #CYCLONEDX #SPDX

0 0 0 0
Post image

Zen of SBOM #3: "DEPENDENCIES are like relationships. You can't choose them, but they're important."

What do you think? Discuss!

#SBOM #ZENSBOM #SPDX #CYCLONEDX

0 0 0 0
Preview
Release 0.1.0-beta.1 · CycloneDX/transparency-exchange-api Tagging beta 1 again with correct version in OpenAPI spec

The OWASP Transparency Exchange API has published our first BETA release for implementors to start implementing the consumer API including the discovery.

Get all the docs including the #openapi specification here:

github.com/CycloneDX/tr...

#OWASP #TEA #SBOM #CYCLONEDX #SPDX

2 2 0 0
Post image

Zen of SBOM #2: "SBOM is not a single process to be completed. It's a lifecycle process".

What do you think? Discuss!

#SBOM #ZENSBOM #SPDX #CYCLONEDX

1 1 0 0
Preview
5 reasons why you need to put SaaSBOMs to work Here's why your organization should consider using SaaSBOMs, key challenges — and how to put CycloneDX's xBOM standard into action.

Here's why your organization should consider using SaaSBOMs (think #SBOM, but for #SaaS), key challenges — & how to put the #CycloneDX xBOM standard into action: www.reversinglabs.com/blog/5-reaso...

0 0 0 0
Post image

Join us for a few postings named "The ZEN of SBOM". The first one is "SBOM is not the answer to all software problems, but it sure helps"

What do you think! Let's discuss!

#SBOM #CYCLONEDX #SPDX #SOFTWARETRANSPARENCY

0 0 0 0
Preview
Rise of the xBOM: The new go-to tool for software security CycloneDX 1.6's ML-BOM, SaaSBOM, and CBOM are non-negotiable visibility requirements in the software supply chain security era.

@owasp.org's #CycloneDX 1.6 calls for the ML-BOM, SaaSBOM, & CBOM - making them non-negotiable visibility requirements that go beyond the #SBOM: www.reversinglabs.com/blog/xbom-to...

0 1 0 0
Preview
Transparency Exchange API (TEA) Hackathon - Barcelona 2025 | CycloneDX Join us in Barcelona to test and shape the Transparency Exchange API, the next evolution in secure supply chain communication.

Join us on Wed May 28, 2025 in Barcelona for a hands-on hackathon to test Beta 1 of the Transparency Exchange API (TEA) — a new way to securely exchange SBOMs, attestations & more.

Free registration, thanks to @owasp.org and Ecma International.

cyclonedx.org/events/hacka...

#CycloneDX #SBOM

7 5 0 2
Post image

We're honored that @defectdojo.bsky.social has chosen Dependency-Track as one of the top #opensource tools in the #SCA category this year.

Here's the press release with all the other great tools on the list.
www.businesswire.com/news/home/20...

#SBOM #CycloneDX #OWASP

3 1 0 0
Preview
GitHub - Santandersecurityresearch/cryptobom-forge: Tools and utilities needed to parse GitHub Multi-Repository Variant Analysis output Tools and utilities needed to parse GitHub Multi-Repository Variant Analysis output - Santandersecurityresearch/cryptobom-forge

There are not many examples of code that build CBOM ( #cryptography bills of material) based on the #CycloneDx python library. Or in general there are not many tools that generate CBOM out there. Nice work from the UK Santander research team. Really helpful. repo: github.com/Santandersec...

1 0 0 0
Post image

Works with Vulnetix
#Secrets scanners
#SAST
Linters
#Code test coverage
#IaC
#Containers
Compilers
#DAST
#AttackSurface

+ Anything else that exports #CycloneDX, #SPDX, or #SARIF

Vendor Support for CycloneDX here: cyclonedx.org/about/suppor...

Or SPDX here: spdx.dev/use/spdx-too...

Let's chat

2 1 0 0
Preview
Socket Joins TC54 to Help Shape the Future of SBOMs, Cyclone... Socket is joining TC54 to help develop standards for software supply chain security, contributing to the evolution of SBOMs, CycloneDX, and Package UR...

🚀 Exciting news: Socket is now part of TC54! We're joining forces to help shape the future of SBOMs, CycloneDX, and PURL, making software supply chains more secure & transparent.

socket.dev/blog/socket-...

#SBOM #CycloneDX #PURL #cybersecurity

4 2 0 0
Preview
Creating SBOM with sbom-tool and CycloneDX on Azure DevOps What is SBOM? [A software bill of materials (SBOM) declares the inventory of components used to...

Just finished writing a blog post about Creating SBOM with sbom-tool and CycloneDX on Azure DevOps.
#Azure #AzurePipelines #SBOM #sbomtool #CycloneDX dev.to/atahanceylan...

2 1 0 0
Post image

The OWASP CycloneDX team will be well represented at @fosdem.bsky.social ! We'll talk in the Security dev room and the SBOM dev room. Find us if you want to chat about CycloneDX, PURL, TEA or other CycloneDX projects.

#SBOM #CYCLONEDX #TEA #PURL

@cyclonedx.bsky.social @owasp.org

7 3 0 0
Post image

Anthony and Olle will be at FOSDEM as part of the @cyclonedx.bsky.social team. We're talking in the SBOM devroom and in the main track (house K).

Let's meet and chat about SBOMs!

#SBOM #CYCLONEDX

1 0 0 0
Post image

OWASP CycloneDX are coming to FOSDEM! We'll speak in many dev rooms and in the main track. Let's meet!

#OWASP #CYCLONEDX #SBOM

0 0 0 0
Post image

If your company creates software that manage Software Bill of Material data - SBOMs - then you want to take part of the standardisation of an ECMA standard API for exchanging software transparency artefacts. Join us on November 25th! http://teaintro.even #SPDX #SBOM #INTOTO #CYCLONEDX #OWASP

5 2 0 0
Post image

CycloneDX v1.6, advances software supply chain security with cryptographic bill of materials, CycloneDX Attestations, and assessing the environmental impact of AI. #CycloneDX #OWAS #SBOM" jpmellojr.blogspot.com/2024/04/owas...

0 0 0 0
Post image

One of the new features of #CycloneDX v1.6 is Attestations, enabling organizations to communicate and assert veracity of standards, claims, and evidence in support of requirements.

Read about all the new features here: cyclonedx.org/news/c...

0 0 0 0
Post image

#CycloneDX v1.6 has been released! Among the new features is support for Cryptographic Bill of Materials (CBOMs), allowing inventory of cryptographic algorithms in use, informing future migration to post-quantum algorithms. Read all the details here: cyclonedx.org/news/c...

0 0 0 0