#SBoM

JAVAPROjavapro
2025-07-03

Ever wondered if your containers hide a ticking time bomb? @MohammadAliEN combines & attestations to lock down the supply chain. Ready to secure your build?

Read: javapro.io/2025/07/03/how-to-c

2025-07-01

Burning #SBOM or #Vulnerability scanning questions for the Anchore OSS team? Join our live stream every Thursday!
Or just come along and hang out while we noodle on our projects.
anchorecommunity.discourse.gro

2025-06-30

"It's more than just software now, it really is a system"β€”the insight driving the biggest evolution in supply chain security since SBOMs were invented.

Why SPDX 3.0 redesigned everything around system-level thinking:

πŸ”— anchore.com/blog/spdx-3-0-from

#SPDX #SBOM #SoftwareSupplyChain

Ottoottok
2025-06-30

Is your company planning to start contributing to open source? πŸš€ My new post shares best practices for corporate upstream contributions, spanning things from legal compliance (CRA is coming!) to building reputation & quality: optimizedbyotto.com/post/best-

2025-06-29

Syft users! πŸ“£ We want to hear from YOU! Take our quick 5-question survey to help shape the future of Syft. Your feedback is invaluable! πŸ‘‰ forms.gle/VJZ7idKZgchminYD7
#Syft #SBOM #OpenSource

2025-06-27

While everyone's debating SBOM formats, the real revolution is happening:

❌ Software inventory
βœ… System risk orchestrator

Legacuy SBOMs weren't built for distributed architectures where risk flows through connections, not just components.

πŸ”— anchore.com/blog/spdx-3-0-from

#SBOM

Anant Shrivastava aka anantshrianant@anantshri.info
2025-06-27

Presented at @OWASPLondon Chapter "You secured your code dependencies, is that enough?"

Focus is on things other then SBOM / code imports that will and have in past result in compromises and you should have awareness about.

https://slides.anantshri.info/dzKZn9/you-secured-your-code-dependencies-is-that-enough

#SBOM #SupplyChain #infosec

Nordic Software Security Summinsssummit
2025-06-26

The Nordic Software Security Summit is the premier conference on the topic of the EU Cyber Resilience Act (CRA) in the Nordics. Check out our agenda today and enjoy early bird pricing on your registration! nsss.se

Nordic Software Security Summinsssummit
2025-06-25

We have opened for early bird registration to the conference! The program is getting updated every day as we're getting the photos and details from speakers.

Looking forward to meeting you in Stockholm!

2025-06-25

You can't secure what you can't seeβ€”and traditional SBOMs can't see the connections where tomorrow's vulnerabilities hide.

How SPDX 3.0 transforms software inventory into system risk orchestration πŸ‘‡

πŸ”— anchore.com/blog/spdx-3-0-from

#SPDX #SBOM #SoftwareSupplyChain

2025-06-24

πŸ’‘ "SBOM capabilities opened doors we didn't know existed."

One client's results:

βœ… CISO-approved POCs that wouldn't happen before
βœ… Faster sales cycles
βœ… Positioned as trusted security partner vs vendor

Implementation strategy πŸ‘‰ anchore.com/blog/how-to-respon

#SBOM

Finite StateFiniteState
2025-06-23

Still relying on outdated security tools?

πŸ‘Ž No binary scanning
πŸ•³οΈ Incomplete
πŸ“‰ Missed vulnerabilities

Here are 6 signs it's time to upgrade & what to look for πŸ‘‰ finitestate.io/blog/when-to-up

2025-06-23

Burning #SBOM or #Vulnerability scanning questions for the Anchore OSS team? Join our live stream every Thursday!
Or just come along and hang out while we noodle on our projects.
anchorecommunity.discourse.gro

2025-06-23

I chatted with Philippe Ombredanne about Package URLs, or PURLs. He created them, so he knows a thing or two.

We do complain about CPE quite a bit :)

But it's a really hard problem. It feels like a package identifier should be easy, but it's way harder than you think it is. There's nobody better than Philippe to drop some knowledge.

opensourcesecurity.io/2025/202

#PURL
#CVE
#SBOM

2025-06-21

In case you missed it, here's yesterday's live stream. Best enjoyed at 2x speed :) #security #sbom youtube.com/watch?v=HZhyaffuiE

2025-06-21

🌊 Executive Order 14028. EU Cyber Resilience Act. FedRAMP updates.

The regulatory tsunami driving SBOM requirements isn't slowing downβ€”it's accelerating.

Most vendors are scrambling.

Smart orgs are riding the wave πŸ‘‰ anchore.com/blog/how-to-respon

#SBOM #SupplyChainSecurity

2025-06-19

Grab a beverage and join the Syft & Grype team livestream in 5 minutes! #security #sbom youtube.com/watch?v=HZhyaffuiE

2025-06-19

We're live in an hour! Join us on YouTube for #opensource fun with the Syft & Grype team! #security #sbom
youtube.com/watch?v=HZhyaffuiE

2025-06-18

🚨 Security teams: Stop manually grepping through your codebase during #zeroday incidents. Learn how to implement production #SBOM inventory that turns "Are we affected by this CVE?" into a simple query. get.anchore.com/rapid-incident #ZeroDay #DevSecOps

2025-06-18

The team was busy shipping last week! 🚒 While Grype got some new scanners, Syft got quality-of-life improvements for enterprise users and better SPDX handling. A rising tide lifts all boats!
See what we were up to: anchorecommunity.discourse.gro
#SBOM #OpenSource #SoftwareSupplyChain

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst