home.social

#spdx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spdx, aggregated by home.social.

fetched live
  1. SPDX gets more interesting when the SBOM is not only for scanners.

    I wrote a hands-on Quarkus walkthrough around `quarkus-spdx`: generate an SPDX 3.0.1 SBOM, inspect the JSON-LD graph, follow declared license relationships, and check why NTIA/CISA minimums still fail out of the box.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SPDX #SBOM #DevSecOps

  2. SPDX gets more interesting when the SBOM is not only for scanners.

    I wrote a hands-on Quarkus walkthrough around `quarkus-spdx`: generate an SPDX 3.0.1 SBOM, inspect the JSON-LD graph, follow declared license relationships, and check why NTIA/CISA minimums still fail out of the box.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SPDX #SBOM #DevSecOps

  3. SPDX gets more interesting when the SBOM is not only for scanners.

    I wrote a hands-on Quarkus walkthrough around `quarkus-spdx`: generate an SPDX 3.0.1 SBOM, inspect the JSON-LD graph, follow declared license relationships, and check why NTIA/CISA minimums still fail out of the box.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SPDX #SBOM #DevSecOps

  4. SPDX gets more interesting when the SBOM is not only for scanners.

    I wrote a hands-on Quarkus walkthrough around `quarkus-spdx`: generate an SPDX 3.0.1 SBOM, inspect the JSON-LD graph, follow declared license relationships, and check why NTIA/CISA minimums still fail out of the box.

    the-main-thread.com/p/quarkus-

    #Quarkus #Java #SPDX #SBOM #DevSecOps

  5. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  6. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  7. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  8. Yesterday at the European SBOM user group we discussed the ENISA report on SBOM adoption. It was a very open discussion, inspired by this report and we found issues that we want to come back to, issues we did not really agree with the report on. This is the type of discussions we want to enable by inviting to the user group meetings.

    Join us by registering at sbomeurope.eu/community/

    #SBOM #SBOMEUROPE #SPDX #CYCLONEDX

  9. [Перевод] Автоматизация SBOM в большом legacy-проекте: опыт LibreOffice и Collabora Online

    Вот уже более 20 лет проходит масштабная конференция разработчиков свободного и открытого ПО – FOSDEM. Для CodeScoring она примечательна тем, что с 2021 года на ней регулярно представлен тематический деврум "SBOMS and supply chains" посвященный составу программного обеспечения и цепочкам поставок. Эта статья – адаптация доклада "LibreOffice and Collabora Online – how we managed to automate SBOM generation for a large legacy project", с которым Торстен Беренц выступил на конференции в 2026 году. Специально для вас мы перевели выступление и превратили его в статью, оригинал доклада на английском языке – по ссылке .

    habr.com/ru/companies/codescor

    #sbom #fosdem #libreoffice #collabora_online #open_source #композиционный_анализ #spdx #c #c++ #sca

  10. [Перевод] Автоматизация SBOM в большом legacy-проекте: опыт LibreOffice и Collabora Online

    Вот уже более 20 лет проходит масштабная конференция разработчиков свободного и открытого ПО – FOSDEM. Для CodeScoring она примечательна тем, что с 2021 года на ней регулярно представлен тематический деврум "SBOMS and supply chains" посвященный составу программного обеспечения и цепочкам поставок. Эта статья – адаптация доклада "LibreOffice and Collabora Online – how we managed to automate SBOM generation for a large legacy project", с которым Торстен Беренц выступил на конференции в 2026 году. Специально для вас мы перевели выступление и превратили его в статью, оригинал доклада на английском языке – по ссылке .

    habr.com/ru/companies/codescor

    #sbom #fosdem #libreoffice #collabora_online #open_source #композиционный_анализ #spdx #c #c++ #sca

  11. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  12. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  13. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  14. Moet de overheid SBOM-standaarden (CycloneDX & SPDX) verplicht toepassen?

    Forum Standaardisatie onderzoekt dit en zoekt experts uit publieke en private sector om mee te denken. Uw kennis over softwarebeveiliging helpt ons bij de toetsing voor de ‘Pas toe of leg uit’-lijst.

    📆 25 juni 2026, 10:00-14:00 (midden-Nederland)
    Lunch is inbegrepen.

    📧 Interesse? Mail ons: [email protected]

    Meer info: forumstandaardisatie.nl/nieuws

    #SBOM #CycloneDX #SPDX #OpenStandaarden #Overheid

  15. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  16. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  17. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  18. Goed nieuws voor de digitale weerbaarheid van de overheid: @forumstandaardisatie zal de intake van #SBOM-standaarden (#CycloneDX en #SPDX) hervatten.

    Een SBOM is als een ingrediëntenlijst voor software: essentieel voor inzicht in de keten en veiligheidsbeheer.

    Waarom nu?
    De onzekerheid over Europese regelgeving is weggenomen:
    👉 NEN-conceptnormen sluiten aan bij de praktijk.
    👉 CycloneDX en SPDX worden erkend.
    👉 Geen normconflicten met de EU.

    Lees meer: forumstandaardisatie.nl/nieuws

  19. New #SPDX License List has been published github.com/spdx/license-list-X
    It includes 33 new licenses and many markup changes to existing licenses. Many of them were added via #Fedora contributors and fedora-license-data.

  20. New #SPDX License List has been published github.com/spdx/license-list-X
    It includes 33 new licenses and many markup changes to existing licenses. Many of them were added via #Fedora contributors and fedora-license-data.

  21. New #SPDX License List has been published github.com/spdx/license-list-X
    It includes 33 new licenses and many markup changes to existing licenses. Many of them were added via #Fedora contributors and fedora-license-data.

  22. New #SPDX License List has been published github.com/spdx/license-list-X
    It includes 33 new licenses and many markup changes to existing licenses. Many of them were added via #Fedora contributors and fedora-license-data.

  23. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  24. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  25. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  26. Back from #FOSDEM and working on the new European SBOM conference in Stockholm April 10th. Send me your ideas for talks!

    #SBOM #CYCLONEDX #SPDX #CYBERSECURITY #CRA #EUCRA

  27. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  28. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  29. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  30. The slides for my presentation "Please sign your artefacts. WITH WHAT?" at #FOSDEM in the Security devroom are now available for viewing. A video will be coming soon.

    fosdem.org/2026/schedule/event

    #SBOM #SPDX #CYCLONEDX #OWASP #CYBERSECURITY #PKILOVE #pki

  31. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  32. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  33. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  34. At the #AboutCode SBOM tools workshop we talked about creating a way of continuing the discussions. I've just created a #SBOM-tools slack channel in the @orcwg space. Join us to discuss #SBOM tools and interoperability!

    orcwg.org/participate/

    #SBOM #CYCLONEDX #SPDX #PURL

  35. Finally, complete the v1 of spdxconv.

    spdxconv is a program to convert existing licenses and copyrights into #SPDX identifiers or insert new ones. This program works in tandem with #reuse software.

    Features:

    * REUSE Integration: Detects annotations from REUSE.toml.
    * Customizable Defaults: Set default license identifiers and copyright holders.
    * Smart Comments: Customizable patterns to set comment syntax ...

    See git.sr.ht/~shulhan/spdxconv/ for more information.

    #openSource #golang

  36. PEP 770 was accepted in April of this year, what has happened since then?

    * Published a white paper on PEP 770 and phantom dependencies
    * Auditwheel, manylinux, and cibuildwheel adoption
    * Over 300 projects already ship with PEP 770 SBOM data
    * Fedora and Red Hat adopted PEP 770 for Python packages

    Read more: sethmlarson.dev/pep-770-sbom-d

    #Python #SBOM #CycloneDX #SPDX #auditwheel #cibuildwheel

  37. PEP 770 was accepted in April of this year, what has happened since then?

    * Published a white paper on PEP 770 and phantom dependencies
    * Auditwheel, manylinux, and cibuildwheel adoption
    * Over 300 projects already ship with PEP 770 SBOM data
    * Fedora and Red Hat adopted PEP 770 for Python packages

    Read more: sethmlarson.dev/pep-770-sbom-d

    #Python #SBOM #CycloneDX #SPDX #auditwheel #cibuildwheel

  38. PEP 770 was accepted in April of this year, what has happened since then?

    * Published a white paper on PEP 770 and phantom dependencies
    * Auditwheel, manylinux, and cibuildwheel adoption
    * Over 300 projects already ship with PEP 770 SBOM data
    * Fedora and Red Hat adopted PEP 770 for Python packages

    Read more: sethmlarson.dev/pep-770-sbom-d

    #Python #SBOM #CycloneDX #SPDX #auditwheel #cibuildwheel

  39. PEP 770 was accepted in April of this year, what has happened since then?

    * Published a white paper on PEP 770 and phantom dependencies
    * Auditwheel, manylinux, and cibuildwheel adoption
    * Over 300 projects already ship with PEP 770 SBOM data
    * Fedora and Red Hat adopted PEP 770 for Python packages

    Read more: sethmlarson.dev/pep-770-sbom-d

    #Python #SBOM #CycloneDX #SPDX #auditwheel #cibuildwheel

  40. @herrfrankmann #SPDX #cybersecurity #csa #enisa #programming

    spdx.github.io/spdx-spec/v3.0.

    "The data may be serialized in a variety of formats for storage and transmission."

    "Canonical serialization is in JSON format"+ extra conditions.

    Is it just me or is that really, really stupid.

    How hard do you have to miss the point of defining a standard, when the output data needs further specification.

    Needlessly too.

    "No line breaks"

    Your (standard) parser can't handle line breaks or what?!?

  41. @herrfrankmann #SPDX #cybersecurity #csa #enisa #programming

    spdx.github.io/spdx-spec/v3.0.

    "The data may be serialized in a variety of formats for storage and transmission."

    "Canonical serialization is in JSON format"+ extra conditions.

    Is it just me or is that really, really stupid.

    How hard do you have to miss the point of defining a standard, when the output data needs further specification.

    Needlessly too.

    "No line breaks"

    Your (standard) parser can't handle line breaks or what?!?

  42. @herrfrankmann #SPDX #cybersecurity #csa #enisa #programming

    spdx.github.io/spdx-spec/v3.0.

    "The data may be serialized in a variety of formats for storage and transmission."

    "Canonical serialization is in JSON format"+ extra conditions.

    Is it just me or is that really, really stupid.

    How hard do you have to miss the point of defining a standard, when the output data needs further specification.

    Needlessly too.

    "No line breaks"

    Your (standard) parser can't handle line breaks or what?!?

  43. @herrfrankmann #SPDX #cybersecurity #csa #enisa #programming

    spdx.github.io/spdx-spec/v3.0.

    "The data may be serialized in a variety of formats for storage and transmission."

    "Canonical serialization is in JSON format"+ extra conditions.

    Is it just me or is that really, really stupid.

    How hard do you have to miss the point of defining a standard, when the output data needs further specification.

    Needlessly too.

    "No line breaks"

    Your (standard) parser can't handle line breaks or what?!?

  44. Naslednje #Kiberpipa srečanje bo

    v četrtek, 11.12. ob 17h
    v @muzej|u in sicer:

    • najprej bo @hook vodil delavnico o #REUSE dobrih praksah za označevanje svoje programske kode z #SPDX standardnimi oznakami za avtorstvo in licence. (bring your own code)

    • nato bosta @franga2000 in [email protected] predstavila kako deluje Zakon o dostopu do javnih informacij (#ZDIJZ) v praksi.

    dogodki.kompot.si/events/ee116
    več info in pofočkaj se ☝️

    #OprtaKoda #FOSS #JavniPodatki

  45. Naslednje #Kiberpipa srečanje bo

    v četrtek, 11.12. ob 17h
    v @muzej|u in sicer:

    • najprej bo @hook vodil delavnico o #REUSE dobrih praksah za označevanje svoje programske kode z #SPDX standardnimi oznakami za avtorstvo in licence. (bring your own code)

    • nato bosta @franga2000 in [email protected] predstavila kako deluje Zakon o dostopu do javnih informacij (#ZDIJZ) v praksi.

    dogodki.kompot.si/events/ee116
    več info in pofočkaj se ☝️

    #OprtaKoda #FOSS #JavniPodatki

  46. Naslednje #Kiberpipa srečanje bo

    v četrtek, 11.12. ob 17h
    v @muzej|u in sicer:

    • najprej bo @hook vodil delavnico o #REUSE dobrih praksah za označevanje svoje programske kode z #SPDX standardnimi oznakami za avtorstvo in licence. (bring your own code)

    • nato bosta @franga2000 in [email protected] predstavila kako deluje Zakon o dostopu do javnih informacij (#ZDIJZ) v praksi.

    dogodki.kompot.si/events/ee116
    več info in pofočkaj se ☝️

    #OprtaKoda #FOSS #JavniPodatki

  47. Naslednje #Kiberpipa srečanje bo

    v četrtek, 11.12. ob 17h
    v @muzej|u in sicer:

    • najprej bo @hook vodil delavnico o #REUSE dobrih praksah za označevanje svoje programske kode z #SPDX standardnimi oznakami za avtorstvo in licence. (bring your own code)

    • nato bosta @franga2000 in [email protected] predstavila kako deluje Zakon o dostopu do javnih informacij (#ZDIJZ) v praksi.

    dogodki.kompot.si/events/ee116
    več info in pofočkaj se ☝️

    #OprtaKoda #FOSS #JavniPodatki

  48. The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.

    toscalix.com/2025/10/14/introd

    #spdx #sbom #cyclonedx #cryptography #algorithm #linuxfoundation

  49. The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.

    toscalix.com/2025/10/14/introd

    #spdx #sbom #cyclonedx #cryptography #algorithm #linuxfoundation

  50. The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.

    toscalix.com/2025/10/14/introd

    #spdx #sbom #cyclonedx #cryptography #algorithm #linuxfoundation

  51. The SPDX community is now creating a new list — similar to the SPDX License List — but focused on cryptographic algorithms. This post shares how this effort started, its current status, the next steps, and a final call for participation.

    toscalix.com/2025/10/14/introd

    #spdx #sbom #cyclonedx #cryptography #algorithm #linuxfoundation