home.social

#sboms — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sboms, aggregated by home.social.

fetched live
  1. Wer vollständige #SBOMs veröffentlicht, schützt seine Lieferkette nicht automatisch. @svenruppert zeigt, warum kontrollierte Transparenz sicherer ist als maximale Offenlegung und wie sich SBOMs gezielt freigeben lassen.

    Lies: javapro.de/2026/06/24/sichere-

    #Cybersecurity #DevSecOps

  2. Wer vollständige #SBOMs veröffentlicht, schützt seine Lieferkette nicht automatisch. @svenruppert zeigt, warum kontrollierte Transparenz sicherer ist als maximale Offenlegung und wie sich SBOMs gezielt freigeben lassen.

    Lies: javapro.de/2026/06/24/sichere-

    #Cybersecurity #DevSecOps

  3. Wer vollständige #SBOMs veröffentlicht, schützt seine Lieferkette nicht automatisch. @svenruppert zeigt, warum kontrollierte Transparenz sicherer ist als maximale Offenlegung und wie sich SBOMs gezielt freigeben lassen.

    Lies: javapro.de/2026/06/24/sichere-

    #Cybersecurity #DevSecOps

  4. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit @svenruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  5. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit @svenruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  6. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit Sven Ruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  7. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit Sven Ruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  8. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  9. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  10. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  11. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  12. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  13. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  14. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  15. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  16. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  17. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  18. Andrew Nesbitt takes us on a thrilling journey through the dazzling world of #lockfiles, asking the earth-shattering question: could they be SBOMs? 🚀✨ Spoiler alert: the answer is yes, but in formats as unique as snowflakes. ❄️ Meanwhile, the rest of the world waits with bated breath for the EU to dictate our digital lives! 🇪🇺🔒
    nesbitt.io/2025/12/23/could-lo #SBOMs #digitaltransformation #EUregulations #cybersecurity #HackerNews #ngated

  19. Andrew Nesbitt takes us on a thrilling journey through the dazzling world of #lockfiles, asking the earth-shattering question: could they be SBOMs? 🚀✨ Spoiler alert: the answer is yes, but in formats as unique as snowflakes. ❄️ Meanwhile, the rest of the world waits with bated breath for the EU to dictate our digital lives! 🇪🇺🔒
    nesbitt.io/2025/12/23/could-lo #SBOMs #digitaltransformation #EUregulations #cybersecurity #HackerNews #ngated

  20. Andrew Nesbitt takes us on a thrilling journey through the dazzling world of #lockfiles, asking the earth-shattering question: could they be SBOMs? 🚀✨ Spoiler alert: the answer is yes, but in formats as unique as snowflakes. ❄️ Meanwhile, the rest of the world waits with bated breath for the EU to dictate our digital lives! 🇪🇺🔒
    nesbitt.io/2025/12/23/could-lo #SBOMs #digitaltransformation #EUregulations #cybersecurity #HackerNews #ngated

  21. Andrew Nesbitt takes us on a thrilling journey through the dazzling world of #lockfiles, asking the earth-shattering question: could they be SBOMs? 🚀✨ Spoiler alert: the answer is yes, but in formats as unique as snowflakes. ❄️ Meanwhile, the rest of the world waits with bated breath for the EU to dictate our digital lives! 🇪🇺🔒
    nesbitt.io/2025/12/23/could-lo #SBOMs #digitaltransformation #EUregulations #cybersecurity #HackerNews #ngated

  22. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  23. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  24. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  25. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  26. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  27. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  28. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  29. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  30. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  31. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  32. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  33. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  34. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  35. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  36. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  37. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  38. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  39. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  40. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  41. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  42. Next week I will attend to #osseu 2025 from @linuxfoundation to talk about osskb.org , the service that allow OSS devs and projects to detect open source software, so they can curate it, then create accurate and complete #sboms with their tooling of choice, in a reasonable amount of time osseu2025.sched.com/event/25Vu

  43. Next week I will attend to #osseu 2025 from @linuxfoundation to talk about osskb.org , the service that allow OSS devs and projects to detect open source software, so they can curate it, then create accurate and complete #sboms with their tooling of choice, in a reasonable amount of time osseu2025.sched.com/event/25Vu