Trending

#SPDx

Latest posts tagged with #SPDx on Bluesky

Latest Top
Trending

Posts tagged #SPDx

Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

#SBOM #CYCLONEDX #SPDX #POTATOSECURITY #CRA #EUCRA

1 0 1 0
Post image

Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

#SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

1 0 1 0
Post image

The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

fosdem.org/2026/schedule/event/RFFD...

#SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

2 2 0 0
Preview
Get Involved in the Open Regulatory Compliance Working Group | Open Regulatory Compliance Working Group The open source community is collaborating to establish common specifications for secure software development based on open source best practices.

At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

https://orcwg.org/participate/

#SBOM #CYCLONEDX #SPDX #PURL

0 0 0 0
SBOM Live  - What type of SBOM is required by the EU Cyber Resilience Act (CRA)?
SBOM Live - What type of SBOM is required by the EU Cyber Resilience Act (CRA)? YouTube video by SBOM Europe

The EU Cyber Resilience Act requires manufacturers to have an SBOM - but what does that mean? Last Friday we had a chat about the CRA and SBOMs and it turned out it wasn't easy to figure out.
Check the video at youtu.be/W-E55x8fPyY?...

#SBOM #EUCRA #CRA #SPDX #CYCLONEDX

1 2 0 0
Preview
PEP 770 Software Bill‑of‑Materials (SBOM) data from PyPI, Fedora, and Red Hat This year I authored PEP 770 which proposed a new standardized location for Software Bill-of-Materials (SBOM) data within Python wheel archives. SBOM data can now be stored in (package)-(version).d...

PEP 770 was accepted in April of this year, what has happened since then?

sethmlarson.dev/pep-770-sbom...

#Python #SBOM #CycloneDX #SPDX #auditwheel #cibuildwheel

6 2 0 0
Preview
License scanner for Python A 0.4 update

Updating license_scanner to 0.4! Now #Python package with #SPDX operators AND/OR will also work

medium.com/@nijhof.dns/...

1 0 0 0
Preview
Introducing the SPDX Cryptographic Algorithm List: a Personal View The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.
0 0 0 0
Preview
Introducing the SPDX Cryptographic Algorithm List: a Personal View The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.
0 0 0 0
Preview
Introducing the SPDX Cryptographic Algorithm List: a Personal View The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.
0 0 0 0
Preview
Creating a distribution package Distribution Packages are archives that can be uploaded to a package index such as pypi.org and installed with pip. Structure: A minimal distribution package can look like this, for example: pyproj...

We have now updated our packaging tutorial to include PEP 639, which enables SPDX-compliant licensing: python-basics-tutorial.readthedocs.io/en/latest/pa...
#Python #Packaging #SPDX #Licensing

2 1 0 0
Post image

Transparency is no longer optional in the software supply chain.
SBOM = visibility
SPDX = structure
SCA tools = speed + accuracy

Here’s why suppliers need both ➡️ scatool.com/resources/sb...

#SBOM #SPDX #SCA #Compliance

0 0 0 0
Post image

Your codebase called. It wants full ingredient labels. And it has to be packaged nicely.

New blog: “Understanding SPDX” → the ISO-approved SBOM recipe for cutting license + vuln chaos.

Read: scatool.com/resources/sb...

#SPDX #SBOM #SCATool #Opensoucesoftware

0 0 0 0
Post image

"It's more than just software now, it really is a system"—the insight driving the biggest evolution in supply chain security since SBOMs were invented.

Why SPDX 3.0 redesigne... anchore.com/blog/spdx-3-0-from-softw...

#SPDX #SBOM #SoftwareSupplyChain

0 0 0 0
Post image

You can't secure what you can't see—and traditional SBOMs can't see the connections where tomorrow's vulnerabilities hide.

How SPDX 3.0 transforms software inventory into sys... anchore.com/blog/spdx-3-0-from-softw...

#SPDX #SBOM #SoftwareSupplyChain

0 0 0 0
Post image

Today I found a tool for checking open source licenses 🔥

📜 feluda — Detect license usage restrictions in your project.

💯 Supports Rust, TS, JS, Go, Python & more!

🦀 Written in Rust & built with @ratatui.rs

⭐ GitHub: github.com/anistark/fel...

#rustlang #ratatui #tui #license #spdx #opensource

42 10 2 0
Post image

The most successful standards start by doing almost nothing.

HTTP in 1991: Just GET requests
HTTP today: Powers the entire internet

SBOMs in 2024: "Barely valid"
SBOMs in 2030...
anchore.com/blog/the-sbom-paradox-wh...

#SoftwareSupplyChain #SBOM #SPDX

0 0 0 0
Preview
Anchore Open Source Weekly Report - Week 24, 2025 Anchore Open Source Weekly Report This report covers the community activity in Anchore Open Source Projects from June 9, 2025 to June 13, 2025. Executive Summary The Anchore team wrapped up a busy week with 25 issues and pull requests resolved across the ecosystem. A major highlight was the successful integration of Echo OS support across multiple projects, marking a significant expansion of vulnerability detection capabilities for this emerging Linux distribution. The team also addressed sever...

It was a busy week in the Syft ecosystem! We merged fixes for #SPDX package filtering, resolved some tricky upstream package issues, and improved how we handle database errors.... anchorecommunity.discourse.group/t/anchore-open-source-we...
#SBOM #OpenSource #BugFix

2 0 0 0
Preview
cultivate(MD) Announces SPDx Acquisition: A Game Changer for Surgical Instrument Sterilization cultivate(MD) has acquired Sterile Processing Express (SPDx) by Instrumentum, enhancing surgical sterilization services across multiple states.

cultivate(MD) Announces SPDx Acquisition: A Game Changer for Surgical Instrument Sterilization #USA #Grand_Rapids #cultivate(MD) #SPDx #Instrumentum

0 0 0 0
Post image

Zen of SBOM #4: "Completeness improves the usefulness of the SBOM"

#SBOM #CYCLONEDX #SPDX

0 0 0 0
Post image

Zen of SBOM #3: "DEPENDENCIES are like relationships. You can't choose them, but they're important."

What do you think? Discuss!

#SBOM #ZENSBOM #SPDX #CYCLONEDX

0 0 0 0
Preview
Release 0.1.0-beta.1 · CycloneDX/transparency-exchange-api Tagging beta 1 again with correct version in OpenAPI spec

The OWASP Transparency Exchange API has published our first BETA release for implementors to start implementing the consumer API including the discovery.

Get all the docs including the #openapi specification here:

github.com/CycloneDX/tr...

#OWASP #TEA #SBOM #CYCLONEDX #SPDX

2 2 0 0
Post image

Zen of SBOM #2: "SBOM is not a single process to be completed. It's a lifecycle process".

What do you think? Discuss!

#SBOM #ZENSBOM #SPDX #CYCLONEDX

1 1 0 0
Post image

Join us for a few postings named "The ZEN of SBOM". The first one is "SBOM is not the answer to all software problems, but it sure helps"

What do you think! Let's discuss!

#SBOM #CYCLONEDX #SPDX #SOFTWARETRANSPARENCY

0 0 0 0
Preview
GitHub - microsoft/sbom-tool: The SBOM tool is a highly scalable and… | Adrian Diglio The #Microsoft #opensource #SBOM Tool now supports #SPDX 3.0! Huge kudos to John Wade and team for the work they've done to make this possible. Today, the tool still produces SPDX 2.2 by default ...

"The Microsoft #opensource #SBOM Tool now supports hashtag #SPDX 3.0!"

www.linkedin.com/posts/adrian... #cybersecurity

2 0 0 0
Preview
SciTech Chronicles. . . . . . . . .May 2nd, 2025 Don't stop thinking about tomorrow. Vol II No. 26 383 links Curated Mission Control RSS Feed Wordpress SubStack Comments Buy Me A Coffee ...

SciTech Chronicles. . . . . . . . .May 2nd, 2025

bit.ly/stc050225

#protoplanets#"moment of inertia" #stratification #SPDX #ZTS #Linux #"6.14 kernel" #respiration #electrons #electrochemistry#"geological history" #"Stac Fada Member" #Rodinia #"gastrointestinal diseases" #metagenomic #metaproteomic

0 0 0 0
Dziękujemy za uczestnictwo w zawodach SP DX CONTEST 2025!
Otrzymaliśmy wysłany przez Ciebie dziennik stacji SP7PBC w kategorii MOAB MIXED .
Twój log zawiera 105 łączności.

Dziękujemy za uczestnictwo w zawodach SP DX CONTEST 2025! Otrzymaliśmy wysłany przez Ciebie dziennik stacji SP7PBC w kategorii MOAB MIXED . Twój log zawiera 105 łączności.

105 QSOs in SP DX Contest as a club station SP7PBC, thank you all, 73 #hamradio #spdx

2 0 0 0
Post image

#SPDX 3.0 and the Future of #SBOMs—What's Next? Kate Stewart, a leading force behind SPDX, and Alan Pope of Anchore discuss the latest advancements in SBOMs, regulatory shifts, an... get.anchore.com/future-of-sboms-with-kat... get.anchore.com/future-of-sboms-with-kat...

0 0 0 0
Post image

Works with Vulnetix
#Secrets scanners
#SAST
Linters
#Code test coverage
#IaC
#Containers
Compilers
#DAST
#AttackSurface

+ Anything else that exports #CycloneDX, #SPDX, or #SARIF

Vendor Support for CycloneDX here: cyclonedx.org/about/suppor...

Or SPDX here: spdx.dev/use/spdx-too...

Let's chat

2 1 0 0
Preview
The Linux Foundation、AI部品表「AI BOM」の日本語資料を公開 The Linux Foundationは、AI開発などにおけるソフトウェアなどの部品表(SBOM)の利用について解説した日本語版資料を公開した。

The Linux Foundation、AI部品表「AI BOM」の日本語資料を公開 #ZDNET (Feb 6)

#LinuxFoundation #AIセキュリティ #SBOM #SPDX #AIリスク管理

0 0 0 0