TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

An Intro to SBOMs

24 点作者 vmbrasseur大约 2 年前

3 条评论

ipsocannibal大约 2 年前
You are starting more companies that are US Gov contractors invest in SBOM generation and software provenance solutions due to <a href="https:&#x2F;&#x2F;www.nist.gov&#x2F;itl&#x2F;executive-order-14028-improving-nations-cybersecurity" rel="nofollow">https:&#x2F;&#x2F;www.nist.gov&#x2F;itl&#x2F;executive-order-14028-improving-nat...</a>
wallrat大约 2 年前
Are SBOMs a &quot;thing&quot; yet? Is anybody using SBOMs in their day to day workflows?<p>The current tooling for <i>generating</i> them seems to have matured, but tools for storing and managing an SBOM inventory seem non-existent with exception for OWASP Dependency-Track.
评论 #35698481 未加载
评论 #35702335 未加载
richbell大约 2 年前
I <i>despise</i> the SPDX format, it feels like it was designed by the same people who created the current disaster that is NVD.
评论 #35697001 未加载