|
SBOM is included in the latest Omnibus bill
‘‘SEC. 524B. ENSURING CYBERSECURITY OF DEVICES.
‘‘(3) provide to the Secretary a software bill of
20 materials, including commercial, open-source, and
21 off-the-shelf software
‘‘SEC. 524B. ENSURING CYBERSECURITY OF DEVICES.
‘‘(3) provide to the Secretary a software bill of
20 materials, including commercial, open-source, and
21 off-the-shelf software
|
By
Dick Brooks
·
#1617
·
|
|
SBOM stripped from NDAA may reappear in the Omnibus bill
Hello Everyone,
I’ve heard the SBOM provision that was in the NDAA is under consideration for the Omnibus Bill.
I sent written testimony to the Senate Appropriations Committee deliberating the
Hello Everyone,
I’ve heard the SBOM provision that was in the NDAA is under consideration for the Omnibus Bill.
I sent written testimony to the Senate Appropriations Committee deliberating the
|
By
Dick Brooks
·
#1616
·
|
|
Re: Congress is considering removing the SBOM provision from the NDAA Bill now before Congress
It’s all moot now. The bill passed the House and Senate today and is on it’s way to the President’s desk.
https://www.congress.gov/bill/117th-congress/house-bill/7776/text
All of the
It’s all moot now. The bill passed the House and Senate today and is on it’s way to the President’s desk.
https://www.congress.gov/bill/117th-congress/house-bill/7776/text
All of the
|
By
Dick Brooks
·
#1615
·
|
|
Re: Congress is considering removing the SBOM provision from the NDAA Bill now before Congress
You shared this previously https://insidecybersecurity.com/share/14118
I think that's a significant reason. And even as a proponent / agitator of SBOMs myself, I find the arguments they lay out
You shared this previously https://insidecybersecurity.com/share/14118
I think that's a significant reason. And even as a proponent / agitator of SBOMs myself, I find the arguments they lay out
|
By
Brian Fox
·
#1614
·
|
|
Re: Congress is considering removing the SBOM provision from the NDAA Bill now before Congress
Eliot,
I’m not familiar with the GSA work you mention. Can you provide a pointer to GSA documents indicating that SBOM’s are required.
I’ve seen where SBOM’s are required in the
Eliot,
I’m not familiar with the GSA work you mention. Can you provide a pointer to GSA documents indicating that SBOM’s are required.
I’ve seen where SBOM’s are required in the
|
By
Dick Brooks
·
#1613
·
|
|
Re: Congress is considering removing the SBOM provision from the NDAA Bill now before Congress
Why? GSA is already specifying SBOMs. And is the list to encourage congressional lobbying?
On 16.12.22 20:38, Dick Brooks wrote:
Why? GSA is already specifying SBOMs. And is the list to encourage congressional lobbying?
On 16.12.22 20:38, Dick Brooks wrote:
|
By
Eliot Lear
·
#1612
·
|
|
Congress is considering removing the SBOM provision from the NDAA Bill now before Congress
FYI:
Please get the word out to restore the SBOM provision in the NDAA.
“I don't see why any member of Congress would want to hamstring their own cybersecurity professionals from monitoring
FYI:
Please get the word out to restore the SBOM provision in the NDAA.
“I don't see why any member of Congress would want to hamstring their own cybersecurity professionals from monitoring
|
By
Dick Brooks
·
#1611
·
|
|
Possible Vendor Day
Sending this to the SPDX list per Gary’s suggestion at today’s SPDX tech team meeting. .
Last Week I attended a FERC-DOE supply chain technical conference and a suggestion was made to host a
Sending this to the SPDX list per Gary’s suggestion at today’s SPDX tech team meeting. .
Last Week I attended a FERC-DOE supply chain technical conference and a suggestion was made to host a
|
By
Dick Brooks
·
#1610
·
|
|
Your feedback as open source licenses expert/user about OSLiFe-DiSC tool
Dear all,
A step forward to automate license processing is to characterize legal terms dealt with by licenses and describe licenses accordingly in order to reach a standardized model.
To that end, we
Dear all,
A step forward to automate license processing is to characterize legal terms dealt with by licenses and describe licenses accordingly in order to reach a standardized model.
To that end, we
|
By
Sihem Ben Sassi
·
#1609
·
|
|
Re: Interpreting SPDX Validator Error: SpdxIdInUseException ... ExtractedLicensingInfo
Thank you, Gary! I wasn't sure where the right place was to ask this question. Issue submitted with example: https://github.com/spdx/spdx-online-tools/issues/414
Thank you, Gary! I wasn't sure where the right place was to ask this question. Issue submitted with example: https://github.com/spdx/spdx-online-tools/issues/414
|
By
Keith Zantow
·
#1608
·
|
|
Re: Interpreting SPDX Validator Error: SpdxIdInUseException ... ExtractedLicensingInfo
Hi Keith,
The “Unexpected Error” usually indicates an issue with the validation tool itself. Can you post an issue at https://github.com/spdx/spdx-online-tools/issues and attach a file that
Hi Keith,
The “Unexpected Error” usually indicates an issue with the validation tool itself. Can you post an issue at https://github.com/spdx/spdx-online-tools/issues and attach a file that
|
By
Gary O'Neall
·
#1607
·
|
|
Interpreting SPDX Validator Error: SpdxIdInUseException ... ExtractedLicensingInfo
Hi,
I'm using the SPDX online validator and I'm trying to understand what this error means. Could someone shed some light on it?
Analysis exception processing SPDX file: Unexpected Error:
Hi,
I'm using the SPDX online validator and I'm trying to understand what this error means. Could someone shed some light on it?
Analysis exception processing SPDX file: Unexpected Error:
|
By
Keith Zantow
·
#1606
·
|
|
Re: SPDX creation phase
Having also been in that call I would also like this clarification. The idea behind having this information available is for the recipient to make her or his own judgement on how accurate they expect
Having also been in that call I would also like this clarification. The idea behind having this information available is for the recipient to make her or his own judgement on how accurate they expect
|
By
Jimmy Ahlberg
·
#1605
·
|
|
FERC-DOE Supply Chain Technical Conference on December 7, 2022 at FERC HQ in Washington.
Hoping to meet some people at this supply chain technical conference in Washington on December 7.
Please come out and show your support for SBOM in software supply chains and meet many of the
Hoping to meet some people at this supply chain technical conference in Washington on December 7.
Please come out and show your support for SBOM in software supply chains and meet many of the
|
By
Dick Brooks
·
#1604
·
|
|
Re: SPDX creation phase
Hi Steve,
I’m going to include the SPDX tech group on the email thread – sorry to many of you for the duplication.
Steve – If you’re a member of that email we can continue the thread
Hi Steve,
I’m going to include the SPDX tech group on the email thread – sorry to many of you for the duplication.
Steve – If you’re a member of that email we can continue the thread
|
By
Gary O'Neall
·
#1603
·
|
|
Re: SPDX creation phase
Steve,
SBOM’s are created to serve a purpose, for example some SBOM’s are used for license management, some are used for dependency tracking and the one I’m most familiar with is an SBOM
Steve,
SBOM’s are created to serve a purpose, for example some SBOM’s are used for license management, some are used for dependency tracking and the one I’m most familiar with is an SBOM
|
By
Dick Brooks
·
#1602
·
|
|
SPDX creation phase
Hi all,
One of the suggestions in today’s call for the OpenChain Telco SIG, where we’re discussing proposals for an SBOM standard for the Telecommunications industry, was:
> SBOMs
Hi all,
One of the suggestions in today’s call for the OpenChain Telco SIG, where we’re discussing proposals for an SBOM standard for the Telecommunications industry, was:
> SBOMs
|
By
Steve Kilbane
·
#1601
·
|
|
Re: Thurs SPDX General Meeting Reminder
Small correction: Thurs is Dec 1.
From:spdx@... <spdx@...> on behalf of Phil Odence via lists.spdx.org <phil.odence=synopsys.com@...>
Date: Wednesday, November 30, 2022 at 10:16 AM
To: SPDX-general
Small correction: Thurs is Dec 1.
From:spdx@... <spdx@...> on behalf of Phil Odence via lists.spdx.org <phil.odence=synopsys.com@...>
Date: Wednesday, November 30, 2022 at 10:16 AM
To: SPDX-general
|
By
Phil Odence
·
#1600
·
|
|
Thurs SPDX General Meeting Reminder
This month we’ll have a couple special presentations. Gary will give a debrief on Wednesday’s docfest. Alexios will walk is through the GitHub 3.0 directories so everyone knows how to
This month we’ll have a couple special presentations. Gary will give a debrief on Wednesday’s docfest. Alexios will walk is through the GitHub 3.0 directories so everyone knows how to
|
By
Phil Odence
·
#1599
·
|
|
Re: SBOM Survey
This survey was a great start to gather feedback about SBOM, but it would be good to get some questions about AI sBOM, they need additional information collected
This survey was a great start to gather feedback about SBOM, but it would be good to get some questions about AI sBOM, they need additional information collected
|
By
karen.bennet
·
#1598
·
|