#sbom

56 posts · Last used 11d

#introduction I work on software supply-chain evidence, and I have one argument I would like to be wrong about. The CRA's two dates get planned in the wrong order. Reporting an exploited vulnerability within 24 hours starts 11 September 2026. The machine-readable SBOM is only required from 11 December 2027 — fifteen months after the clock starts. On a 24-hour clock the first question is not how to word the notification. It is which of your services ship the component. #CRA #SBOM
0
0
1
0
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA) Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference. Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry. If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss! 🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community. #FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3
0
0
0
0
OWASP Dependency-Track 5.0 is now generally available. Codenamed Hyades, v5 delivers the biggest redesign in project history: stateless, horizontally scalable APIs; durable execution that resumes BOM processing and vulnerability analysis after crashes; component integrity verification against upstream registry tampering; and a CEL-based policy engine. Early adopters processed 20,000+ SBOMs/hour. PostgreSQL is now the sole supported database. https://dependencytrack.org/ #OWASP #SBOM
6
0
2
0