#cbom

0xKaishakunin0xKaishakunin
2026-02-13

Just stumbled upon the Group

This list provides a shared, unambiguous vocabulary for
identifying and in Software Bill of
Materials (SBOMs), SPDX documents, and related tooling.

lists.spdx.org/g/spdx-security

2025-07-23

Key BIS advice for banks: start your quantum-safe transition NOW. That means inventorying all your crypto (#CBOM), assigning a lead exec for quantum readiness, and realizing this isn’t a “just swap algorithms” upgrade. Migrating to #PQC will be a painstaking overhaul, more complex than any past crypto upgrade. #QuantumReadiness postquantum.com/industry-news/

:bongoCat:pft
2025-04-15

I have a small hunch why IBM has a tool that generates a and tells you if they are safe or not...

Suffice to say that it's a reminiscent of the time that Altman traveled around the world and warned everyone that his machine is an existential threat to humanity.

2024-06-10

Huge congrats (and thank you) to IBM for releasing an open source plugin for SonarQube which generates Cryptography Bill of Materials (#CBOM). github.com/IBM/sonar-cryptogra

And check out the Authoritative Guide to CBOM available at cyclonedx.org/guides/OWASP_Cyc

#OWASP #SBOM #cryptography

Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2024-04-09

#SBOM: #OWASP CycloneDX v1.6 Standard Released, Advances Software Supply Chain Security with Cryptographic Bill of Materials(#CBOM) and CDXA Attestations ("proof-of-compliance"):
👇

cyclonedx.org/news/cyclonedx-v
cyclonedx.org/news/cyclonedx-v

OWASP Dependency-TrackDependencyTrack@infosec.exchange
2024-03-07

Couldn’t attend this week’s Dependency-Track community meeting? No worries, we’ve got the recording.

@nscur0 leads us through the project roadmap. We also have special guests from the @CycloneDX #cryptography working group presenting #CBOM. Don’t miss it.

youtube.com/watch?v=0WPvVCRyLj

Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2024-03-07

If you missed the OWASP #CycloneDX community virtual meeting on March 6th the recording is available on YouTube. Learn about the latest DependencyTrack updates and #CBOM or Cryptography Bill of Materials in CycloneDX:

youtube.com/watch?v=0WPvVCRyLj

Steve "Looking for Work" Pordon (he/him/his)legion303@infosec.exchange
2023-12-21

@jerry well let's see...I have a first-gen Trezor and some dogecoin. #CBOM

2023-12-21

Preparing for post-quantum cryptography? First identify what #AppliedCryptography you have already have in place, says security researcher Daniel Cuthbert. Here's how new tools for generating a Cryptographic Bill of Materials (#CBOM) can help.
databreachtoday.com/preparing-

Gottfried Szingkjoo@hachyderm.io
2023-12-19

In a #postquantum cryptographic world you will need #Cryptography Bill of Materials or #CBOM... this information doesn't and it shouldn't be collected manually, since there are ways to generate a list out of repository GitHub. Not for all languages, but at least for #python #c and #c++.

github.blog/2023-12-05-address

Steve Springett :verified:stevespringett@infosec.exchange
2023-10-04

Great article from Basil Hess and Nicklas Körtge on Cryptography Bill of Materials (CBOM), the many use cases, and how we're building this capability into #OWASP @CycloneDX v1.6.

owasp.org/blog/2023/10/03/Cycl

#SBOM #CBOM #CSRM #SoftwareTransparency #Cryptography #nsm10 #eo14028

Satori ❄️ :skyeface3:Satori@mastodon.thirring.org
2023-10-03

@ExtraPenguin Thank you 😘. Oops I realize that was a confusing post! 😂 I should have tagged our dear @ADailyViolet! She is our favourite boss bunny and a Celebrity Bun of Mastodon #CBOM ☺️. It was her birthday yesterday and we love her so! 🥳💜

(PS Skye’s Gotcha Day is Nov 2- because she’s a rescue we found outside, we don’t know her actual birthday!)

Steve Springett :verified:stevespringett@infosec.exchange
2023-03-29

Here's the deck I presented to the DoD CIO panel last week. The overwhelming majority of the deck are capabilities that only OWASP @CycloneDX BOM Standard supports. Going beyond simple #SBOM use cases and supporting #SaaSBOM, #HBOM, #OBOM, #VDR, and #VEX today, and in two months time will also be supporting #MLBOM, #MBOM, and bill of attestations. And let's not forget about #CBOM for inventory of cryptographic assets for analysis in a post-quantum world. Thanks to the many organizations and individuals contributing to the standard, the future is incredibly bright.

docs.google.com/presentation/d

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst