Software Bill-of-Materials with OWASP CycloneDX
Details
Recent vulnerabilities, like those for Log4J, have revealed the importance of knowing all the components of a software product. Software bill of materials is the general term to define that listing and has support from industry as well as CISA and NIST. OWASP CycloneDX is a lightweight Bill of Materials (BOM) standard designed for use in application security contexts and supply chain component analysis.
Steve Springett, Chair of CycloneDX SBOM Standard Core Working Group, will present CycloneDX and how it can help.
