lsdm, to random French
@lsdm@mamot.fr avatar

Qu’attendre de la sortie de SPDX 3.0 ?
La communauté SPDX et la Linux Foundation annoncent la sortie de SPDX 3.0, une avancée significative du projet, avec l’ajout des profils SPDX pour gérer les cas d’utilisation des systèmes modernes.

La version 3.0 de SPDX sera soumise à l’ISO comme mise à jour. https://lsdm.live/modules/news/article.php?storyid=5040

sjvn, to security
@sjvn@mastodon.social avatar

Meet the System Package Data Exchange: SPDX 3.0, with Profiles: https://thenewstack.io/introducing-spdx-30-and-profiles/ by @sjvn

With 3.0, you can track not just software packages, but pretty much anything and everything. It's a game-changer.

ProvenPudding, to random
@ProvenPudding@fosstodon.org avatar

This will be interesting! I know what an is, but sounds like an American police drama series. @fossnorth

davelester, to random
@davelester@fosstodon.org avatar

Good morning from ! Opening keynote: “SBOMs Everywhere: Work in Progress & Challenges Ahead” with some great updates on incl the final release tag of 3.0! https://github.com/spdx/spdx-3-model/releases/tag/3.0

Slide: “Extending SPDX beyond 3.0”

arnie_dxer, to random Polish
@arnie_dxer@mastodon.radio avatar

Sierra Echo na pasku, zapowiadając live'a: Sikju Kontest! (bo zawody )

Sierra Echo po pół godziny pier*olenia o busach: robi łączność na 17m, nie w zawodach

Sierra Echo przez kolejne pół godziny: dalej pieroli o busach, ale przerywając go szybkimi łącznościami nie w zawodach*

Sierra Echo po kolejnych pół godziny: "może zaraz wróci Julia z Islandii, to zrobię łączność"... po czym DALEJ PIERDOLI O TYCH BUSACH XDDDDDD

luis_in_brief, to random
@luis_in_brief@social.coop avatar

Because I’m a nice guy and a glutton for punishment, I’m resubscribing to @osi ‘s License Review list.

pmonks,
@pmonks@sfba.social avatar

@luis_in_brief @osi Why not double down and join the legal subcommittee as well? (but srsly - they do great work)

mariuxdeangelo, to random

The last few days, I was checking out different tools to generate and took a closer look at the dependencies I get. While and specify how an SBOM should look, the resulting output can be very different. I've put together some notes here.https://mariuxdeangelo.gitlab.io/website/#/post/20230924-SBOM-dependency-semantics-SPDX-and-CycloneDx

kushal, to security
@kushal@toots.dgplug.org avatar

I wrote about and vulnerability scanning. https://kushaldas.in/posts/sbom-and-vulnerability-scanning.html


@joshbressers you will find some known project names in that post :)

kushal, to random
@kushal@toots.dgplug.org avatar

What is going on? https://spdx.dev

kushal, to security
@kushal@toots.dgplug.org avatar

Say I have files containers and projects inside of them. What are the good available options to keep scanning/checking those SBOM files for vulnerabilities right now?

@joshbressers any tips?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines