home.social

#sbom — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sbom, aggregated by home.social.

  1. 📰 CISA and G7 Partners Release New Guidance for AI SBOMs

    CISA and G7 partners have released new guidance on creating a Software Bill of Materials for AI (AI SBOM). The goal is to bring transparency to the AI supply chain by listing the 'ingredients' of AI models. 🤖📄 #AISecurity #SBOM #CISA #G7

    🔗 cyber.netsecops.io

  2. Global Agencies Unveil AI Supply Chain Risk Guidance with SBOMs

    Global agencies have joined forces to release groundbreaking guidance on AI supply chain risk, outlining minimum elements for Software Bill of Materials (SBOMs) to enhance security and transparency. This crucial step forward aims to tackle the complex challenges of measuring and defining AI risks across organizations.

    osintsights.com/global-agencie

    #AiSupplyChain #SoftwareBillOfMaterials #Sbom #ArtificialIntelligence #G7

  3. Erfolgreich scheitern mit #NPM- und #PyPI-Paketen. 🤗

    "zuletzt jeweils auf über 11 Millionen Downloads pro Woche. Und das sind nur zwei von insgesamt 416 Software-Paketversionen, die die Socket-Forscher in ihrem Bericht als betroffen auflisten."

    Die Ursache liegt eher bei den Entwicklern: 🙈

    "Softwareentwickler, die NPM- oder PyPI-Pakete im Einsatz haben, sollten dringend prüfen, ob sie möglicherweise eine oder mehrere betroffene Versionen der kompromittierten Pakete heruntergeladen haben. Ist dies der Fall, so sind die jeweiligen Systeme als kompromittiert zu betrachten."

    Die Sorglosigkeit scheint Programm zu sein. Erfahrene Entwickler werden leiden weil der gesamte Bereich nun im schlechten Licht gesehen wird. 🙄

    Ohne #SBOM und sorgfältiger Umgang mit Dritt-Software ist es sehr riskant. 🙁

    Fragen Sie erfahrene Entwickler wie man sicherer im #Internet die Entwicklung betreiben muss. Ob #NPM- und #PyPI-Pakete, es gibt Verfahren die deutlich weniger Fehler zulassen. 🙂

    golem.de/news/supply-chain-ang

    #NPM #PyPI #SBOM #Internet

  4. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  5. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0

  6. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  7. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  8. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  9. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  10. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0

  11. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  12. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  13. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=N-6Sc5CQwI0 #SBOM #Vulnerability

  14. If software supply chain is part of your day, Cybeats is worth knowing. Gold Sponsor at AppSec Village this year — thanks for the support!

    Learn more about them here: cybeats.com/

    #AppSecVillage #SBOM #SponsorShoutout #Goldsponsor

  15. If software supply chain is part of your day, Cybeats is worth knowing. Gold Sponsor at AppSec Village this year — thanks for the support!

    Learn more about them here: cybeats.com/

    #AppSecVillage #SBOM #SponsorShoutout #Goldsponsor

  16. If software supply chain is part of your day, Cybeats is worth knowing. Gold Sponsor at AppSec Village this year — thanks for the support!

    Learn more about them here: cybeats.com/

    #AppSecVillage #SBOM #SponsorShoutout #Goldsponsor

  17. If software supply chain is part of your day, Cybeats is worth knowing. Gold Sponsor at AppSec Village this year — thanks for the support!

    Learn more about them here: cybeats.com/

    #AppSecVillage #SBOM #SponsorShoutout #Goldsponsor

  18. Security Tip: Transparency is key to a secure software stack. 🛡️ Implementing a Software Bill of Materials (SBOM) allows your team to maintain a comprehensive inventory of all components. When a new vulnerability breaks, an SBOM helps you identify affected systems in minutes, not days. Stay informed on the latest vulnerabilities and remediation steps at cvedatabase.com #CyberSecurity #InfoSec #SBOM #SoftwareSupplyChain #CVE

  19. Security Tip: Transparency is key to a secure software stack. 🛡️ Implementing a Software Bill of Materials (SBOM) allows your team to maintain a comprehensive inventory of all components. When a new vulnerability breaks, an SBOM helps you identify affected systems in minutes, not days. Stay informed on the latest vulnerabilities and remediation steps at cvedatabase.com #CyberSecurity #InfoSec #SBOM #SoftwareSupplyChain #CVE

  20. Security Tip: Transparency is key to a secure software stack. 🛡️ Implementing a Software Bill of Materials (SBOM) allows your team to maintain a comprehensive inventory of all components. When a new vulnerability breaks, an SBOM helps you identify affected systems in minutes, not days. Stay informed on the latest vulnerabilities and remediation steps at cvedatabase.com

  21. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  22. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g

  23. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  24. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  25. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  26. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  27. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g

  28. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  29. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  30. Missed our Open Source stream? Catch the recording to hear about the latest Syft, Grype, and roadmap updates! youtube.com/watch?v=52p2WywWq7g #SBOM #VulnerabilityScanning

  31. Хватит копировать security YAML: AppSec-слой для Java-проектов через Gradle convention plugin

    Практический разбор того, как я вынес security-проверки Java-проектов из разрозненных CI/CD-скриптов в переиспользуемый Gradle plugin

    habr.com/ru/articles/1032532/

    #cicd #gitlabci #java #gradle #gradleplugin #security #sast #sbom

  32. Хватит копировать security YAML: AppSec-слой для Java-проектов через Gradle convention plugin

    Практический разбор того, как я вынес security-проверки Java-проектов из разрозненных CI/CD-скриптов в переиспользуемый Gradle plugin

    habr.com/ru/articles/1032532/

    #cicd #gitlabci #java #gradle #gradleplugin #security #sast #sbom

  33. Хватит копировать security YAML: AppSec-слой для Java-проектов через Gradle convention plugin

    Практический разбор того, как я вынес security-проверки Java-проектов из разрозненных CI/CD-скриптов в переиспользуемый Gradle plugin

    habr.com/ru/articles/1032532/

    #cicd #gitlabci #java #gradle #gradleplugin #security #sast #sbom

  34. Хватит копировать security YAML: AppSec-слой для Java-проектов через Gradle convention plugin

    Практический разбор того, как я вынес security-проверки Java-проектов из разрозненных CI/CD-скриптов в переиспользуемый Gradle plugin

    habr.com/ru/articles/1032532/

    #cicd #gitlabci #java #gradle #gradleplugin #security #sast #sbom

  35. The software supply chain is the new invisible perimeter. With threat actors targeting CI/CD pipelines, understanding CWE-1395 is critical for #DevSecOps professionals. Check out our deep dive into supply chain vulnerabilities and SBOMs. cvedatabase.com/blog/the-invis #AppSec #CyberSecurity #SBOM #CWE1395

  36. The software supply chain is the new invisible perimeter. With threat actors targeting CI/CD pipelines, understanding CWE-1395 is critical for professionals. Check out our deep dive into supply chain vulnerabilities and SBOMs. cvedatabase.com/blog/the-invis

  37. AI-BOMs Emerge to Secure Enterprise AI Supply Chains

    Imagine biting into a mysterious birthday cake without knowing its ingredients or who baked it - that's what it's like for enterprises trying to secure their AI supply chains without visibility into the components used to build their AI systems. Traditional software bills of materials just aren't cutting it in this new landscape.

    osintsights.com/ai-boms-emerge

    #AiSupplyChains #ArtificialIntelligence #ShadowAi #Sbom #EnterpriseSecurity

  38. El Reg has a story that exactly covers the problem I'm researching right now. It's not just the Devs, the whole company can be exposing secrets, corrupting data...

    theregister.com/2026/05/04/ai_

    #sbom #agenticai

  39. El Reg has a story that exactly covers the problem I'm researching right now. It's not just the Devs, the whole company can be exposing secrets, corrupting data...

    theregister.com/2026/05/04/ai_

    #sbom #agenticai

  40. El Reg has a story that exactly covers the problem I'm researching right now. It's not just the Devs, the whole company can be exposing secrets, corrupting data...

    theregister.com/2026/05/04/ai_

    #sbom #agenticai

  41. El Reg has a story that exactly covers the problem I'm researching right now. It's not just the Devs, the whole company can be exposing secrets, corrupting data...

    theregister.com/2026/05/04/ai_

    #sbom #agenticai

  42. El Reg has a story that exactly covers the problem I'm researching right now. It's not just the Devs, the whole company can be exposing secrets, corrupting data...

    theregister.com/2026/05/04/ai_

    #sbom #agenticai

  43. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=52p2WywWq7g #SBOM #Vulnerability

  44. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=52p2WywWq7g

  45. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=52p2WywWq7g #SBOM #Vulnerability

  46. Join the Anchore Open Source team this Thursday at 12 PM PT for our live stream! We'll cover issues, PRs, & roadmap. youtube.com/watch?v=52p2WywWq7g #SBOM #Vulnerability