SPDX SBOM’s Post

View organization page for SPDX SBOM, graphic

688 followers

In the ever-evolving landscape of software development, SPDX 3.0 emerges as a transformative solution, ushering in a new era of enhanced security and streamlined vulnerability tracking.  #SPDX3 #SoftwareSupplyChain #SBOM #SecurityUpdates #VulnerabilityData #CVSS #EPSS #KEV #SSVC #VEX #SecurityStandards #SPDXProfile #DynamicVulnerabilityData #MetadataGroupings #SoftwareSecurity #SBOMUtility #CVEtracking #OpenSourceSecurity

Capturing Software Vulnerability Data in SPDX 3.0

https://spdx.dev

SPDX Version 2.3 appendix K.1.9 shows how to link an online "living" SBOM Vulnerability Disclosure Report (VDR) to a static SBOM document following NIST guidelines. https://spdx.github.io/spdx-spec/v2.3/how-to-use/#k19-linking-to-an-sbom-vulnerability-report-for-a-software-product-per-nist-executive-order-14028

Like
Reply

To view or add a comment, sign in

Explore topics