Highlights
OWASP Common Lifecycle Enumeration (CLE)
Common-Lifecycle-Enumeration
Open standard supporting software component aliasing, component lifecycle changes such as end-of-life and end-of-support, and provenance chaining over time.
CycloneDX BOM Standard
CycloneDX
CycloneDX is a modern standard for the software supply chain. SBOM, SaaSBOM, CBOM, OBOM, VEX, and more. CycloneDX is a OWASP project ratified as ECMA-424
Dependency-Track
DependencyTrack
Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain
Steve Springett
stevespringett
I build stuff, I break stuff, I develop stuff to protect stuff.
Creator of @DependencyTrack. Chair of @CycloneDX and @Ecma-TC54. Core team of @package-url
@ServiceNow Chicago