OSPO Alliance · @OSPOAlliance
70 followers · 30 posts · Server mastodon.opencloud.lu

Building a successful with the Good Governance Initiative Handbook (aka ).
At the upcoming @EclipseFdn @yakaceme will introduce the latest release of the Good Governance Handbook, v1.2

📅 17 Oct
⏰ 16:50
🌒 eclipsecon.org/node/4282

This talk is part of the track session called " Best Practices" covering a lot of topics of interest if you're dealing with an ( etc)

#SBOM #licensing #security #supplychain #innersource #duediligence #ip #opensource #eclipsecon2023 #ggi #ospo

Last updated 1 year ago

αxel simon ↙︎↙︎↙︎ · @axx
319 followers · 2092 posts · Server mstdn.fr

There is now a lot of info on how to generate an , but not much on how to use the SBOM's you've generated, and barely anything on visualising your massive SBOM json and making sense of it, it seems.

Any clues, fedifriends?

#SBOM

Last updated 1 year ago

Curtis "Ovid" Poe · @ovid
928 followers · 2230 posts · Server fosstodon.org

Writing a parser for the parser.

Because it might be eventually useful in the core (unsure due to vagueness with upcoming EU CRA regulations), I can't use a standard validator and I'm crafting it by hand with core Perl.

It's fun, but much harder!

#cyberdx #SBOM #json #perl #openapi

Last updated 1 year ago

Kushal Das :python: :tor: · @kushal
2457 followers · 8092 posts · Server toots.dgplug.org

After solved problems, now is solving all security issues.

#blockchain #security #SBOM

Last updated 1 year ago

BSI · @bsi
21485 followers · 823 posts · Server social.bund.de

Wir haben Teil 2 der Technischen Richtlinie TR-03183 "Cyber-Resilienz-Anforderungen" veröffentlicht. Das Dokument definiert formelle und fachliche Vorgaben für Software-Stücklisten (). Damit bieten wir als BSI Softwareherstellern eine Empfehlung zur Gestaltung von SBOMs, die der Erhöhung der Sicherheit in der Software-Lieferkette (Software Supply Chain Security) dienen.

bsi.bund.de/dok/1093154

#SBOM

Last updated 1 year ago

Matthias Schmidt · @mattication
28 followers · 241 posts · Server cloud-native.social
jesterchen42 · @jesterchen
354 followers · 1302 posts · Server social.tchncs.de

Hey there!

I'm looking for any ​s on ​s. Could you help me out?

Thank you.

#comic #SBOM

Last updated 1 year ago

Dave Lester · @davelester
374 followers · 55 posts · Server fosstodon.org

Video from CISA’s 2023 SBOM-a-Rama event is now online! youtube.com/playlist?list=PL-B

#SBOM

Last updated 1 year ago

Seth Michael Larson · @sethmlarson
961 followers · 745 posts · Server fosstodon.org

📰 New article: Developer-in-Residence Weekly Report #4

Discussed @projectsigstore signatures of releases and PEP 710 for provenance of distributions and applicability to .

sethmlarson.dev/security-devel

#security #python #SBOM

Last updated 1 year ago

Kathy Reid · @KathyReid
3552 followers · 2121 posts · Server aus.social

Great post from the @osi arguing that Meta's new , #, is not .

I agree, *and*, we don't know where the data comes from .. data and models need to be considered separately from an perspective.

linkedin.com/posts/open-source

#llm #llama2 #opensource #SBOM

Last updated 1 year ago

Seth Michael Larson · @sethmlarson
961 followers · 736 posts · Server fosstodon.org

environments to using draft PEP 710 👀

#python #SBOM

Last updated 1 year ago

Seth Michael Larson · @sethmlarson
960 followers · 729 posts · Server fosstodon.org

PEP 710: Provenance of installed packages authored by @fridex 🎉

discuss.python.org/t/pep-710-r

Can inspect an already existing environment about where packages where installed from. Part 1/2 for being able to create an from an existing Python environment 👀

#python #SBOM

Last updated 1 year ago

Florian Heubeck ⌨☕🌩 · @heubeck
75 followers · 130 posts · Server mastodon.green

:vulkan_salute:

update for all the upstream tools used by our handling GitHub app at once. perfect end of week.

github.com/MediaMarktSaturn/te

#SBOM

Last updated 1 year ago

· @jpmellojr
6 followers · 88 posts · Server noc.social

CycloneDX is one of the most popular standards for describing the components of an application. With the latest release of the specification, the projec is expanding it even further to encompass hardware, operations, manufacturing, and artificial intelligence.
jpmellojr.blogspot.com/2023/07

#SBOM

Last updated 1 year ago

FOSSlife · @fosslife
1901 followers · 176 posts · Server fosstodon.org
Seth Michael Larson · @sethmlarson
954 followers · 716 posts · Server fosstodon.org

Second weekly report for the Developer-in-Residence role. I wrote about bundled libraries in wheels, , Trusted Publisher metrics, and @GitHub Push Protection for @pypi API tokens:

sethmlarson.dev/security-devel

#security #python #SBOM

Last updated 1 year ago

Nico Rikken · @nicorikken
233 followers · 577 posts · Server mastodon.nl

"De opeenvolging van een aantal grote supply chain incidenten zoals SolarWinds en Log4J heeft de afgelopen jaren pijnlijk duidelijk gemaakt dat veel organisaties onvoldoende zicht hebben op de afhankelijkheden binnen hun software supply chain. De Software Bill Of Materials (SBOM) is een belangrijke bouwsteen om dit probleem aan te pakken." Lees verder in de goede startersgids van het ncsc.nl/documenten/publicaties

#ncsc #SBOM

Last updated 1 year ago

Dave Lester · @davelester
359 followers · 40 posts · Server fosstodon.org

Everyone is talking about Software Bill of Materials ! Last week was CISA's SBOM-a-Rama event in LA that was all about SBOMs; I've compiled a list of articles covering the event and shared the links on my blog. blog.davelester.org/post/72068

#SBOM

Last updated 1 year ago

FOSSlife · @fosslife
1777 followers · 153 posts · Server fosstodon.org
devguy :verified: · @developerguy
354 followers · 551 posts · Server hachyderm.io

I was so excited (still I'm) about the v0.11 release of the @Docker ✨With that release, creating an and provenance for your builds has been never been easy!
I'm so glad to see that @openpolicyagent project uses these🥳✨
github.com/open-policy-agent/g

#buildkit #SBOM #SLSA #gatekeeper

Last updated 1 year ago