home.social

#cyclonedx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyclonedx, aggregated by home.social.

fetched live
  1. Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд

    Выходит новость о критической уязвимости, и первый вопрос: какие из наших продуктов её тянут и что чинить первым? С 11 сентября 2026 года Cyber Resilience Act требует сообщать об активно эксплуатируемых уязвимостях в течение 24 часов, так что вопрос получил срок. Под него хорошо подходил Minefield — граф SBOM на roaring bitmaps от BitBom, заархивированный в 2025 году. Я продолжил его под именем Sapper, добавил отчёт с приоритетами по CISA KEV и EPSS и по дороге нашёл, что граф строился задом наперёд, а псевдоверсии Go превращали любую версию в уязвимую. Рассказываю, как это нашлось и как проверить, что исправление действительно исправление. Читать дальше

    habr.com/ru/articles/1086502/

    #sbom #cyclonedx #spdx #osv #cve #cisa_kev #epss #cyber_resilience_act #roaring_bitmaps #go

  2. Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд

    Выходит новость о критической уязвимости, и первый вопрос: какие из наших продуктов её тянут и что чинить первым? С 11 сентября 2026 года Cyber Resilience Act требует сообщать об активно эксплуатируемых уязвимостях в течение 24 часов, так что вопрос получил срок. Под него хорошо подходил Minefield — граф SBOM на roaring bitmaps от BitBom, заархивированный в 2025 году. Я продолжил его под именем Sapper, добавил отчёт с приоритетами по CISA KEV и EPSS и по дороге нашёл, что граф строился задом наперёд, а псевдоверсии Go превращали любую версию в уязвимую. Рассказываю, как это нашлось и как проверить, что исправление действительно исправление. Читать дальше

    habr.com/ru/articles/1086502/

    #sbom #cyclonedx #spdx #osv #cve #cisa_kev #epss #cyber_resilience_act #roaring_bitmaps #go

  3. After many years of work with a great team, the OWASP Transparency Exchange API is now on the way to become an ECMA standard. Yesterday the ECMA TC54 approved TEA and it's now on its way to the ECMA general assembly for approval as an official ECMA standard.
    When I started working with SBOMs, the lack of automation was a big gap and the CycloneDX team agreed and we rebooted the BOM exchange API project Koala and created this new API.
    You can read our approved draft at
    ecma-tc54.github.io/ECMA-xxx-T
    #SBOM #TEA #CYCLONEDX #OWASP

  4. After many years of work with a great team, the OWASP Transparency Exchange API is now on the way to become an ECMA standard. Yesterday the ECMA TC54 approved TEA and it's now on its way to the ECMA general assembly for approval as an official ECMA standard.
    When I started working with SBOMs, the lack of automation was a big gap and the CycloneDX team agreed and we rebooted the BOM exchange API project Koala and created this new API.
    You can read our approved draft at
    ecma-tc54.github.io/ECMA-xxx-T
    #SBOM #TEA #CYCLONEDX #OWASP

  5. After many years of work with a great team, the OWASP Transparency Exchange API is now on the way to become an ECMA standard. Yesterday the ECMA TC54 approved TEA and it's now on its way to the ECMA general assembly for approval as an official ECMA standard.
    When I started working with SBOMs, the lack of automation was a big gap and the CycloneDX team agreed and we rebooted the BOM exchange API project Koala and created this new API.
    You can read our approved draft at
    ecma-tc54.github.io/ECMA-xxx-T
    #SBOM #TEA #CYCLONEDX #OWASP

  6. After many years of work with a great team, the OWASP Transparency Exchange API is now on the way to become an ECMA standard. Yesterday the ECMA TC54 approved TEA and it's now on its way to the ECMA general assembly for approval as an official ECMA standard.
    When I started working with SBOMs, the lack of automation was a big gap and the CycloneDX team agreed and we rebooted the BOM exchange API project Koala and created this new API.
    You can read our approved draft at
    ecma-tc54.github.io/ECMA-xxx-T
    #SBOM #TEA #CYCLONEDX #OWASP

  7. #TIL that #uv can export #CycloneDX compatible SBOM files. Really helpful for observing your supply chain.

    Exporting a lockfile | uv
    docs.astral.sh/uv/concepts/pro

    #Python

  8. #TIL that #uv can export #CycloneDX compatible SBOM files. Really helpful for observing your supply chain.

    Exporting a lockfile | uv
    docs.astral.sh/uv/concepts/pro

    #Python

  9. #TIL that #uv can export #CycloneDX compatible SBOM files. Really helpful for observing your supply chain.

    Exporting a lockfile | uv
    docs.astral.sh/uv/concepts/pro

    #Python

  10. #TIL that #uv can export #CycloneDX compatible SBOM files. Really helpful for observing your supply chain.

    Exporting a lockfile | uv
    docs.astral.sh/uv/concepts/pro

    #Python

  11. NEOMSA APIM 4.6.0, платформа управления API: как мы устранили уязвимости Critical и High из БДУ ФСТЭК

    Мы выпустили NEOMSA APIM 4.6.0 . Основной фокус этого релиза — повышение безопасности состава поставки платформы. В рамках процессов безопасной разработки (SSDLC) мы сформировали SBOM, проверили компоненты и их зависимости на известные уязвимости (SCA), сопоставили результаты с БДУ ФСТЭК России и обновили проблемные библиотеки. По итогам повторной проверки количество зарегистрированных находок сократилось с 57 до 7. Уязвимостей уровней Critical и High в финальной сборке не осталось. В статье рассказываем, как устроена проверка NEOMSA APIM перед выпуском и какой критерий безопасности мы используем для принятия решения о готовности релиза.

    habr.com/ru/companies/neoflex/

    #SBOM #SCA #DevSecOps #управление_уязвимостями #БДУ_ФСТЭК #CycloneDX #Grype #API_Management #безопасность_цепочки_поставок #neomsa_apim

  12. NEOMSA APIM 4.6.0, платформа управления API: как мы устранили уязвимости Critical и High из БДУ ФСТЭК

    Мы выпустили NEOMSA APIM 4.6.0 . Основной фокус этого релиза — повышение безопасности состава поставки платформы. В рамках процессов безопасной разработки (SSDLC) мы сформировали SBOM, проверили компоненты и их зависимости на известные уязвимости (SCA), сопоставили результаты с БДУ ФСТЭК России и обновили проблемные библиотеки. По итогам повторной проверки количество зарегистрированных находок сократилось с 57 до 7. Уязвимостей уровней Critical и High в финальной сборке не осталось. В статье рассказываем, как устроена проверка NEOMSA APIM перед выпуском и какой критерий безопасности мы используем для принятия решения о готовности релиза.

    habr.com/ru/companies/neoflex/

    #SBOM #SCA #DevSecOps #управление_уязвимостями #БДУ_ФСТЭК #CycloneDX #Grype #API_Management #безопасность_цепочки_поставок #neomsa_apim

  13. NEOMSA APIM 4.6.0, платформа управления API: как мы устранили уязвимости Critical и High из БДУ ФСТЭК

    Мы выпустили NEOMSA APIM 4.6.0 . Основной фокус этого релиза — повышение безопасности состава поставки платформы. В рамках процессов безопасной разработки (SSDLC) мы сформировали SBOM, проверили компоненты и их зависимости на известные уязвимости (SCA), сопоставили результаты с БДУ ФСТЭК России и обновили проблемные библиотеки. По итогам повторной проверки количество зарегистрированных находок сократилось с 57 до 7. Уязвимостей уровней Critical и High в финальной сборке не осталось. В статье рассказываем, как устроена проверка NEOMSA APIM перед выпуском и какой критерий безопасности мы используем для принятия решения о готовности релиза.

    habr.com/ru/companies/neoflex/

    #SBOM #SCA #DevSecOps #управление_уязвимостями #БДУ_ФСТЭК #CycloneDX #Grype #API_Management #безопасность_цепочки_поставок #neomsa_apim

  14. NEOMSA APIM 4.6.0, платформа управления API: как мы устранили уязвимости Critical и High из БДУ ФСТЭК

    Мы выпустили NEOMSA APIM 4.6.0 . Основной фокус этого релиза — повышение безопасности состава поставки платформы. В рамках процессов безопасной разработки (SSDLC) мы сформировали SBOM, проверили компоненты и их зависимости на известные уязвимости (SCA), сопоставили результаты с БДУ ФСТЭК России и обновили проблемные библиотеки. По итогам повторной проверки количество зарегистрированных находок сократилось с 57 до 7. Уязвимостей уровней Critical и High в финальной сборке не осталось. В статье рассказываем, как устроена проверка NEOMSA APIM перед выпуском и какой критерий безопасности мы используем для принятия решения о готовности релиза.

    habr.com/ru/companies/neoflex/

    #SBOM #SCA #DevSecOps #управление_уязвимостями #БДУ_ФСТЭК #CycloneDX #Grype #API_Management #безопасность_цепочки_поставок #neomsa_apim

  15. 👉 Apache CycloneDX Antlib 0.1 is now available for download: ant.apache.org/antlibs/bindown

    CycloneDX Antlib is a library of Apache Ant types and a task that support the creation of CycloneDX SBOMs

    @CycloneDX

  16. 👉 Apache CycloneDX Antlib 0.1 is now available for download: ant.apache.org/antlibs/bindown

    CycloneDX Antlib is a library of Apache Ant types and a task that support the creation of CycloneDX SBOMs

    #CycloneDX #SBOM @CycloneDX

  17. 👉 Apache CycloneDX Antlib 0.1 is now available for download: ant.apache.org/antlibs/bindown

    CycloneDX Antlib is a library of Apache Ant types and a task that support the creation of CycloneDX SBOMs

    #CycloneDX #SBOM @CycloneDX

  18. 👉 Apache CycloneDX Antlib 0.1 is now available for download: ant.apache.org/antlibs/bindown

    CycloneDX Antlib is a library of Apache Ant types and a task that support the creation of CycloneDX SBOMs

    #CycloneDX #SBOM @CycloneDX

  19. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  20. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  21. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  22. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  23. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  24. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  25. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  26. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  27. Quarkus can now give you a useful SBOM from the build itself, not just a Maven dependency tree with nicer stationery.

    I wrote up the practical path: add `quarkus-cyclonedx`, build a tiny service, inspect the distribution SBOM, generate the dependency SBOM, validate both with the CycloneDX CLI, and archive them in CI.

    Boring evidence is still evidence. I like that part.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SBOM #CycloneDX

  28. Quarkus can now give you a useful SBOM from the build itself, not just a Maven dependency tree with nicer stationery.

    I wrote up the practical path: add `quarkus-cyclonedx`, build a tiny service, inspect the distribution SBOM, generate the dependency SBOM, validate both with the CycloneDX CLI, and archive them in CI.

    Boring evidence is still evidence. I like that part.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SBOM #CycloneDX

  29. Quarkus can now give you a useful SBOM from the build itself, not just a Maven dependency tree with nicer stationery.

    I wrote up the practical path: add `quarkus-cyclonedx`, build a tiny service, inspect the distribution SBOM, generate the dependency SBOM, validate both with the CycloneDX CLI, and archive them in CI.

    Boring evidence is still evidence. I like that part.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SBOM #CycloneDX

  30. Quarkus can now give you a useful SBOM from the build itself, not just a Maven dependency tree with nicer stationery.

    I wrote up the practical path: add `quarkus-cyclonedx`, build a tiny service, inspect the distribution SBOM, generate the dependency SBOM, validate both with the CycloneDX CLI, and archive them in CI.

    Boring evidence is still evidence. I like that part.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SBOM #CycloneDX

  31. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  32. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  33. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  34. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  35. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  36. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  37. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  38. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  39. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  40. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  41. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  42. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  43. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  44. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  45. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  46. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  47. Going to #FOSDEM? Please join us to celebrate our recent success stories in ECMA TC54! #CycloneDX 1.7, Package URL (#PURL) 1.0 and the Common Lifecycle Enumeration 1.0 (#CLE). We are working to improve all of these and complete the Transparency Exchange API (#TEA) soon!

    Join us in the Bedford hotel, Brussels, Friday January 30 at 17-19 for Drinks and light bites. Register att workshop.aboutcode.org with the code TC54FTW to reserve a ticket while they're available!

    Looking forward to meeting you there!

    #SBOM #CYCLONEDX #PURL #TEA #CLE

    @CycloneDX
    @owasp @fosdem