Skip to main content

Search

Items tagged with: sbom


With regard to xz backdoor, did anyone actually have any idea this was going on? With all these vendors doing source code scanning, was there any indication of maliciousness?

#OSS #Security #SBOM #xz


Episode 364 of the #osspodcast in which Kurt had bad shwarma, @joshbressers agrees that good shwarma is great, and we learn that it's also hard to know what's in your software even if you do #SBOM https://opensourcesecurity.io/2023/02/26/episode-364-using-sboms-is-hard/ TL;DR: We got different kinds of SBOM, SBOM drift, services and APIs, and then there some complicated problems on top of all that. Also legal obligations.


The new Omnibus Bill in the US Senate includes a requirement to "provide to the Secretary a software bill of materials, including commercial, open-source, and off-the-shelf software components" for medical devices.

https://www.appropriations.senate.gov/imo/media/doc/JRQ121922.PDF

If you're not already looking into ways to generate an #SBOM for your product or #OpenSource project, you need to start now, no matter the industry.

/ht Dick Brooks for the pointer