home.social

#sboms — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sboms, aggregated by home.social.

fetched live
  1. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit @svenruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  2. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit @svenruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  3. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit Sven Ruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  4. Wer heute Abhängigkeiten verwaltet, verwaltet auch Risiken. Genau deshalb reichen Versionsnummern in der Parent POM längst nicht mehr aus. Mit Sven Ruppert erfährst du, wie #SBOMs, CRA & NIS2 das Dependency Management in #Java verändern: javapro.io/de/die-parent-pom-v

    #DevSecOps #Maven

  5. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  6. Third-Party Notices (TPNs) are often the only verifiable record when source code or #SBOMs are inaccessible, yet they’re usually trapped in unstructured PDFs.

    A new guest blog by Devashri Datta discusses transforming TPNs into "Security Intelligence."

    openssf.org/blog/2026/04/17/wh

  7. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  8. Again for the evening (CET) crowd:

    The recording from NYC*BUG (Properly pronounced "Nice Bug") Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

    Youtube: youtu.be/HOCsvcCm1Ec
    Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

    #bookofpf #OpenBSD #freebsd #packetfilter #EUCRA #CRA #SBOMS #dependency #supplychain #security @nostarch

  9. Andrew Nesbitt takes us on a thrilling journey through the dazzling world of #lockfiles, asking the earth-shattering question: could they be SBOMs? 🚀✨ Spoiler alert: the answer is yes, but in formats as unique as snowflakes. ❄️ Meanwhile, the rest of the world waits with bated breath for the EU to dictate our digital lives! 🇪🇺🔒
    nesbitt.io/2025/12/23/could-lo #SBOMs #digitaltransformation #EUregulations #cybersecurity #HackerNews #ngated

  10. Andrew Nesbitt takes us on a thrilling journey through the dazzling world of #lockfiles, asking the earth-shattering question: could they be SBOMs? 🚀✨ Spoiler alert: the answer is yes, but in formats as unique as snowflakes. ❄️ Meanwhile, the rest of the world waits with bated breath for the EU to dictate our digital lives! 🇪🇺🔒
    nesbitt.io/2025/12/23/could-lo #SBOMs #digitaltransformation #EUregulations #cybersecurity #HackerNews #ngated

  11. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  12. 🧑‍🌾 bomctl makes SBOMs easier to work with by handling format and version differences for you. Convert between SPDX and CycloneDX, upgrade spec versions, and link #SBOMs across suppliers and systems.

    Watch the OpenSSF Project Spotlight about #bomctl: youtu.be/Tax1pNaySYQ?si=98Cg8V

  13. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  14. When a new vulnerability drops, the first question is always: Is this in my supply chain? 🔍

    By ingesting and enriching #SBOMs with vulnerability and dependency data, #GUAC lets you query your entire application portfolio and pinpoint where action is needed immediately.

    🎥 youtu.be/uDT0xes5ico?si=3qMKMs

  15. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  16. I chat with @mbarbero about security happenings at the @EclipseFdn

    My favorite project they have is helping projects generate #SBOMs, but there's a lot happening. If you want to see some public examples of how to do security right, give it a listen!

    opensourcesecurity.io/2025/202

  17. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  18. Our next #JCON2025 session is live: 'SBOMs Are Not Enough' with Brian Demers

    Software Bill of Materials #SBOMs have emerged as a #critical component of #software supply chain #security, promising transparency about the #dependencies in our…

    Grab your coffee and hit play: youtu.be/4jtf9ATNyx8

  19. Next week I will attend to #osseu 2025 from @linuxfoundation to talk about osskb.org , the service that allow OSS devs and projects to detect open source software, so they can curate it, then create accurate and complete #sboms with their tooling of choice, in a reasonable amount of time osseu2025.sched.com/event/25Vu

  20. Next week I will attend to #osseu 2025 from @linuxfoundation to talk about osskb.org , the service that allow OSS devs and projects to detect open source software, so they can curate it, then create accurate and complete #sboms with their tooling of choice, in a reasonable amount of time osseu2025.sched.com/event/25Vu

  21. Great podcast to learn how open source assessment is leveraged in mergers and aquisitions, and the value of SBOM for license compliance: My Open Source Experience Podcast: From Law to OSPOs shows.acast.com/my-open-source #OpenSource #SBOMs #podcast

  22. Great podcast to learn how open source assessment is leveraged in mergers and aquisitions, and the value of SBOM for license compliance: My Open Source Experience Podcast: From Law to OSPOs shows.acast.com/my-open-source #OpenSource #SBOMs #podcast

  23. Love #SBOMs ☕ Hate Mondays 😒
    Join us TODAY at 11 AM ET — we’ve got the meeting for you! openssf.org/getinvolved/

  24. Love #SBOMs ☕ Hate Mondays 😒
    Join us TODAY at 11 AM ET — we’ve got the meeting for you! openssf.org/getinvolved/

  25. Stop with gut feelings. Part 3 of Steve Poole’s series brings the facts your #AI & software pipelines need. From #SBOMs to audit trails, AI risk levels & vendor checks—get compliant, stay ready.

    👉 Read now: javapro.io/2025/04/08/move-fast-break-laws-ai-open-source-and-devs-part-3/

    #DevSecOps #AICompliance #SupplyChainSecurity

  26. Stop with gut feelings. Part 3 of Steve Poole’s series brings the facts your #AI & software pipelines need. From #SBOMs to audit trails, AI risk levels & vendor checks—get compliant, stay ready.

    👉 Read now: javapro.io/2025/04/08/move-fast-break-laws-ai-open-source-and-devs-part-3/

    #DevSecOps #AICompliance #SupplyChainSecurity

  27. Ever tried to patch a vulnerable #Java image hours before release? @MohammadAliEN shares how #SBOMs, multi-stage builds, and attestations keep your pipeline clean—so you never scramble last minute again.

    Check it out: javapro.io/2025/07/03/how-to-c

    #SpringBoot #DockerScout #DevSecOps

  28. Ever tried to patch a vulnerable #Java image hours before release? @MohammadAliEN shares how #SBOMs, multi-stage builds, and attestations keep your pipeline clean—so you never scramble last minute again.

    Check it out: javapro.io/2025/07/03/how-to-c

    #SpringBoot #DockerScout #DevSecOps

  29. Discover how eBPF, Cilium, and Tetragon enhance container security with real-time kernel-level insights. Learn to combine these tools with SBOMs for robust security monitoring. Boost your skills with OS-SCi education programs! #ContainerSecurity #eBPF #Cilium #Tetragon #SBOMs dub.sh/cZVQvk6

  30. Discover how eBPF, Cilium, and Tetragon enhance container security with real-time kernel-level insights. Learn to combine these tools with SBOMs for robust security monitoring. Boost your skills with OS-SCi education programs! #ContainerSecurity #eBPF #Cilium #Tetragon #SBOMs dub.sh/cZVQvk6

  31. 🔍 Secure your #software supply chain!

    See how #ScanCode, #VulnerableCode & #SBOMs help find licenses & vulnerabilities for safe #FOSS reuse. Watch Benjamin Aronov share practical tips for safer development.

    Click here: youtu.be/-uKyckLPSQc

  32. 🔍 Secure your #software supply chain!

    See how #ScanCode, #VulnerableCode & #SBOMs help find licenses & vulnerabilities for safe #FOSS reuse. Watch Benjamin Aronov share practical tips for safer development.

    Click here: youtu.be/-uKyckLPSQc

  33. 🔍 Secure your #software supply chain!

    See how #ScanCode, #VulnerableCode & #SBOMs help find licenses & vulnerabilities for safe #FOSS reuse. Watch Benjamin Aronov share practical tips for safer development.

    Click here: youtu.be/-uKyckLPSQc

  34. 🧰 #SBOMs are the foundation of understanding your software supply chain, but picking the right tool can be tricky. In a new blog post, Nathan walks through key SBOM generation tools—from single-language options to multi-language solutions like cdxgen, syft, and tern.

    Read the guest blog: openssf.org/blog/2025/06/05/ch

    #OpenSSF #OSSSecurity

  35. Join the @swheritage team at Mining Software Repositories 2025 to learn about their latest work on: understanding the historical trajectory of Programming Language Evolution over 50 years, advancements in achieving Reproducible Builds at Scale & Wild #SBOMs. Full program: 2025.msrconf.org #MSR2025

  36. Excited for #JCON EUROPE 2025? See Brian Demers at #JCON2025 in Cologne talking about '#SBOMs Are Not Enough'

    Software Bill of Materials (SBOMs) have emerged as a #critical component …

    Get your free #JUG Ticket: jcon.one

  37. Last month, the SBOMit community explored how attestations can enhance #SBOMs to secure the software supply chain. Learn why SBOMs alone aren’t enough and how attestations help ensure integrity! 🔐 Read the recap:
    🔗 openssf.org/blog/2025/03/25/be
    #SoftwareSecurity

  38. #SBOMs are buzzy for sure but why? Join us tomorrow on our series "Understanding SBOMs" - we are demo'ing:
    1. How to automate SBOM generation
    2. How to integrate SBOMs into #CICD
    3. How to control costs
    Register today get.anchore.com/automate-gener

  39. #Sigstore creator, #Chainguard CEO, #OpenSSF TAC member and Season 1 guest Dan Lorenc returns to the #ITOps Query podcast to discuss the year in #opensource and #cybersecurity. Topics range from #softwaresupplychain management, hardening #containerimages and #SBOMs in limbo to #openproduct companies and business models, including his own company's shift in focus this year. Plus: a look ahead to #SecOps and #AI in 2025. #yearinreview #2024yearinreview

    podbean.com/ew/pb-ivy26-1778bf