SPDXTeam Profile Banner
SPDX Profile
SPDX

@SPDXTeam

Followers
417
Following
978
Media
0
Statuses
125

An open standard for communicating software bill of material (SBOM) information, including components, licenses, copyrights, and security references.

spdx.dev
Joined August 2017
Don't wanna be here? Send us removal request.
@ProjectElisa
ELISA Project
2 years
Join the #linux community on Oct. 11 for an #ELISASeminar that focuses on the Road to Safe Space Exploration presented by Ivan Perez Dominguez, Senior Research Scientist at @NASAAmes. Learn more & register: https://t.co/hEb23XGqOL @ProjectElisa @NASA #opensource #ELISAProject
1
4
11
@openssf
OpenSSF
2 years
#SBOM alone may not encode enough detail to separate non-exploitable vulnerabilities from exploitable ones writes Surendra Pathak in our latest guest blog on VDR, VEX, OpenVEX & CSAF
0
6
9
@allanfriedman
Allan is @allanfriedman on bsky & infosec.exchange
2 years
Cisco announces SBOMs for recent @cisco products. Great @jefschut blog highlighting 1) the importance of transparency, 2) acknowledging that #SBOM implementation will be a journey, but that 3) we all have to start now for better #supplychain security
Tweet card summary image
blogs.cisco.com
This announcement underscores our commitment to software transparency that improves supply chain security.
1
13
29
@getfossa
FOSSA
2 years
.@SPDX_SBOM v3.0 is in the works, and it's expected to include several major changes from the current v2.3. Get an early look at what to expect — such as support for emerging BOM use cases like AI and data — in our new blog. #SBOM @SPDXTeam https://t.co/t0M5m8w4Nu
Tweet card summary image
fossa.com
SPDX 3.0 introduces new profiles for better use case targeting and flexibility. Major upgrades include changes in document structure, profiles, relationships, and creator information.
0
6
8
@allanfriedman
Allan is @allanfriedman on bsky & infosec.exchange
2 years
Fun! A think tank analysis combines my passion for both Taylor Swift and #SBOM. Nice job by @DFRLab & @AtlanticCouncil @CyberStatecraft for unpacking some of the common (and dare we say imperfect) concerns about SBOM from beltway lobbyists. https://t.co/jCv8b8tKAI
Tweet card summary image
atlanticcouncil.org
SBOMs are an important step forward for software supply chain security, so despite pushback and opposition, industry and government should take a page out of Taylor Swift’s book and just keep...
0
6
13
@SPDX_SBOM
SPDX SBOM
2 years
Providing Transparency at Software Development’s core process: build time by @lumjjb and @_ctlfsh https://t.co/h4l7GERG7U
1
3
2
@SPDXTeam
SPDX
2 years
Excellent summary of what the team got up to during the SPDX Minisummit last month!
@SPDX_SBOM
SPDX SBOM
2 years
Unpacking the SPDX 3.0 Tooling Mini Summit: A New Era of Compliance and Security
0
1
3
@_omkhar
Omkhar Arasaratnam
2 years
I look forward to attending the SBOM-a-rama next week in Los Angeles, hosted by the @CISAgov. @theopenssf and @spdxteam believe SBOMs are a core part of securing our Open Source supply chain. Let me know if you'll be there! https://t.co/aX6v2VpHyx
cisa.gov
Agenda for the SBOM-a-Rama, which will take place on Wednesday, June 14th, 2023.
0
2
4
@mdolan
Mike D.
2 years
If you don't submit a comment, the USPTO will make it easier and more profitable for patent trolls to target #opensource users with bogus claims.
@linuxfoundation
The Linux Foundation
2 years
The USPTO has issued proposed rules that will make it harder for everyone in #opensource to challenge bad #patents. Let them know you want a fair and open system for all, where anyone can seek a review of an invalid patent. Provide your comment: https://t.co/QzmpMuQq86
0
4
9
@JordiMonPMM
Jordi Mon Companys
3 years
Packed venue for @jzemlin’s opening keynote at #OSSummit in Vancouver, BA 🇨🇦
0
4
13
@allanfriedman
Allan is @allanfriedman on bsky & infosec.exchange
3 years
Excited to get the perspectives of @_kate_stewart and @chrisblask on what the world will look like when #SBOM is ubiquitous.
2
2
23
@ZephyrIoT
Zephyr Project
3 years
Software #supplychain transparency is emerging w/ #SBOMs. In this @RSAConference talk on April 25 at 9:40 am, @linuxfoundation's @_kate_stewart & @cybeatstech's @chrisblask present best practices that improve IP control, lower operational costs & more: https://t.co/WZMPJNtGfR
0
2
5
@puerco
puerco
3 years
📢bom v0.5.1 the @kubernetesio SPDX SBOM tool is out! This release embeds the @SPDXTeam license list to generate SBOMs in airgapped envs, adds support for apk packages + lots of bug fixes Big thanks to @sbs0x @developerguyba @rosejudge5 and @comedordexis for contributing!
1
6
22
@SPDXTeam
SPDX
3 years
🎉Excited to see that an SPDX SBOM can now be generated by a push of an export button! Thanks for making things easier for all the open source developers on @github! Awesome work @jhutchings0
@jhutchings0
Justin Hutchings
3 years
Need an SBOM and not sure where to start? Now you can get an SBOM with the push of a button. https://t.co/qlswjHzpkN
2
5
17
@anchore
Anchore
3 years
Get the latest on the SBOM Everywhere working group from @joshbressers and @_kate_stewart in this new @theopenssf blog post. #sbom #security #opensource
@openssf
OpenSSF
3 years
SBOM Everywhere Update and Python SPDX-Tools https://t.co/d3zEfZKuRP #SBOM #SPDX #Python #OSS #OpenSource #OSSsecurity
0
1
4
@AllThingsOpen
All Things Open
3 years
Check out "Open Source Law Policy and Practice Book Panel" with Amanda Brock (@amandabrockUK), Jilayne Lovejoy (@jilaynelovejoy), Kate Stewart (@_kate_stewart ), Karen Sandler (@o0karen0o), Nithya Ruff (@nithyaruff) & Pamela Chestek (@pchestek) on YouTube!
0
5
8
@puerco
puerco
3 years
Shaheem Azmal and Gaurav Mizra from Siemens presenting how Fossology reads licensing information from source code at the @fosdem #SBOM devroom
0
1
8
@puerco
puerco
3 years
Hearing from @nicpappler about plans to leverage SPDX for functional safety 🦺 @fosdem #SBOM devroom #FuSa
1
3
12
@puerco
puerco
3 years
Joshua Watt from Garmin showcasing the upcoming @SPDXTeam build profile as part of his deep dive into build environment SBOMs in the @yoctoproject
0
4
16
@ZephyrIoT
Zephyr Project
3 years
If you're going to @OpenEmbeddedOrg's OE workshop on February 6 in Brussels, don't miss this talk by @Arm's Peter Hoyes about "Integrating #ZephyrRTOS using @yoctoproject." Learn more: https://t.co/y3RK95cFxO @ZephyrIoT #opensource #embedded #openembedded #RTOS
0
8
17