Robuta

https://anchore.com/ SBOM-Powered Software Composition Analysis • Anchore software composition analysissbompoweredanchore https://sbomarchi.us/ SBOM Risk Management Platform | SBOM Archi Continuous SBOM risk management for software supply chains. Detect vulnerabilities, manage license risk, and stay compliant with global regulations. risk managementsbomplatformarchi https://dependencytrack.org/ Dependency-Track | Software Bill of Materials (SBOM) Analysis | OWASP Dependency-Track is the open source platform that over 20,000 organizations use to inventory components, find vulnerabilities, and enforce policy across the... software bill of materialsdependencytracksbomanalysis https://www.eclipse.org/lists/open-regulatory-compliance/msg01050.html [open-regulatory-compliance] ENISA SBOM Survey regulatory complianceopenenisasbomsurvey https://edf.amd.com/sswreleases/rel-v2024.2/cve_sbom/zynqmp-generic_eg/?C=N;O=D Index of /sswreleases/rel-v2024.2/cve_sbom/zynqmp-generic_eg index ofrel https://www.sei.cmu.edu/library/keynote-software-barrel-of-monkeys-sbom/ Keynote: Software Barrel of Monkeys (SBOM) | CMU Software Engineering Institute This keynote session was presented by DJ Schleen at DevSecOps Days Washington, D.C., held virtually on October 12, 2022. cmu engineeringkeynotesoftwarebarrelmonkeys https://www.jotform.com/form-templates/sbom-monitoring-checklist-form SBOM Monitoring Checklist Form Template | Jotform SBOM Monitoring Checklist Form supports consistent SBOM review routines by helping teams document monitoring decisions, schedule follow-ups, and keep a... form templatesbommonitoringchecklistjotform https://docs.aws.amazon.com/es_es/AWSCloudFormation/latest/TemplateReference/aws-properties-iot-softwarepackageversion-sbom.html AWS::IoT::SoftwarePackageVersion Sbom - AWS CloudFormation Use the CloudFormation AWS::IoT::SoftwarePackageVersion.Sbom resource for IoT. aws iotsbomcloudformation https://live-cltc.pantheon.berkeley.edu/publication/towards-a-security-aware-sbom-framework/ Towards a Security-Aware SBOM Framework - CLTC Despite persistent and continuous efforts in the cyber-domain to produce software that is resilient to cybersecurity attacks, software security remains an... towardssecurityawaresbomframework https://data-seeder-6ea8f7.gitlab.io/factories/ci_reports_sbom_source/ Gitlab::Ci::Reports::Sbom::Source | Data Seeder Docs Gitlab::Ci::Reports::Sbom::Source gitlab cisource datareportssbomseeder https://source.android.google.cn/docs/setup/create/create-sbom Create a software bill of materials (SBOM) | Android Open Source Project software bill of materialsopen sourcecreate https://cheatsheetseries.owasp.org/cheatsheets/Dependency_Graph_SBOM_Cheat_Sheet.html Dependency Graph SBOM - OWASP Cheat Sheet Series Website with the collection of all the cheat sheets of the project. dependency graphcheat sheetsbomowaspseries https://thenewstack.io/enhance-your-sbom-success-with-slsa/ Enhance Your SBOM Success with SLSA - The New Stack Dec 14, 2022 - SBOMs alone are not enough for software supply chain security because they do not address the tampering of software artifacts. There’s a new framework for that. the newenhancesbomsuccessslsa https://doc.rust-lang.org/nightly/nightly-rustc/src/cargo/core/compiler/output_sbom.rs.html output_sbom.rs - source Source of the Rust file `src/tools/cargo/src/cargo/core/compiler/output_sbom.rs`. outputsbomrssource https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa78-common_meta-edf-app-sdk/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa78-common_meta-edf-app-sdk https://docs.aws.amazon.com/fr_fr/AWSCloudFormation/latest/TemplateReference/aws-properties-iot-softwarepackageversion-sbom.html AWS::IoT::SoftwarePackageVersion Sbom - AWS CloudFormation Use the CloudFormation AWS::IoT::SoftwarePackageVersion.Sbom resource for IoT. aws iotsbomcloudformation https://app.interlynk.io/ Interlynk | Free SBOM Tools, Automation and Management Interlynk | Free SBOM Manager | Analyze and edit CycloneDX, SDPX SBOMs, fix its errors, scan for vulnerabilities, apply VEX, share with ShareLynk to meet SBOM... sbom toolsfreeautomationmanagement https://docs.aws.amazon.com/de_de/AWSCloudFormation/latest/TemplateReference/aws-properties-iot-softwarepackageversion-sbom.html AWS::IoT::SoftwarePackageVersion Sbom - AWS CloudFormation Use the CloudFormation AWS::IoT::SoftwarePackageVersion.Sbom resource for IoT. aws iotsbomcloudformation https://blog.bdemers.io/categories/sbom/ Sbom Posts - Brian Demers Personal blog of Brian Demers sbompostsbriandemers https://sbom-insights.dev/ SBOM Insights Everything about Software Bill of Materials - Best practices, tools, and industry insights sbominsights https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa53-mali-common_edf-linux-disk-image/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa53-mali-common_edf-linux-disk-image https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa72-common_meta-edf-app-sdk/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa72-common_meta-edf-app-sdk https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-k24-sc-sdt-base_edf-qspi/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-k24-sc-sdt-base_edf-qspi https://docs.docker.com/reference/cli/docker/dhi/attestation/sbom/ docker dhi attestation sbom | Docker Docs dockerdhiattestationsbomdocs https://www.sonatype.com/compare/best-sbom-tools What Are The Best SBOM Tools? | Sonatype Discover the best software bill of materials (SBOM) tools. Understand key features for SBOM management, vulnerability assessment, and SBOM compliance. the bestsbom toolssonatype https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-zcu106-sdt-full_xilinx-bootbin/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-zcu106-sdt-full_xilinx-bootbin https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa78-mali-common_meta-edf-app-sdk/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/amd-cortexa78-mali-common_meta-edf-app-sdk https://www.sei.cmu.edu/news/sbom-harmonization-plugfest-opens-call-for-participants/ SBOM Harmonization Plugfest Opens Call for Participants | CMU Software Engineering Institute The SEI project seeks to uncover sources of divergence among software bills of materials (SBOMs) for the same individual software products. call for participantssoftware engineeringsbomharmonizationplugfest https://www.techtarget.com/searchitoperations/news/366536055/Amid-supply-chain-attacks-emerging-vendor-rethinks-SBOM Amid supply chain attacks, emerging vendor rethinks SBOM | TechTarget Codenotary uses a unique notarization approach to sign software components and an immutable database to store SBOM data for forensic analysis. supply chain attacksamidemergingvendorsbom https://sbom.observer/ SBOM Observer | Manage, Analyze & Enforce SBOMs at Scale Enforce compliance, validate SBOMs, and generate evidence to meet regulatory and customer requirements with SBOM Observer. sbomobservermanageanalyzeenforce https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-zcu111-sdt-full_xilinx-bootbin/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-zcu111-sdt-full_xilinx-bootbin https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/k24-smk-sdt_kria-qspi/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/k24-smk-sdt_kria-qspi https://www.manifestcyber.com/ Manifest Cyber | SBOM Generation & Software Supply Chain Security Automate SBOM generation, secure your software supply chain, and gain complete technology transparency across code, AI, vendors, and embedded systems. software supply chainmanifest cybersbom generationsecurity https://dejacode.readthedocs.io/en/stable/howto-3.html How To 3 - Downloading SBOM for Your Products - DejaCode documentation how tofor yourdownloadingsbomproducts https://opensourcesecuritypodcast.libsyn.com/website/episode-162-sbom-with-allan-friedman Open Source Security: Episode 162 - SBOM with Allan Friedman and Kurt speak with Allan Friedman of the US National Telecommunications and Information Administration about Software Bill of Materials. Where are we today,... open source securityepisodesbomallanfriedman https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/versal-vck190-sdt-seg_edf-qspi/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/versal-vck190-sdt-seg_edf-qspi https://www.linuxfoundation.org/research/sbom-guide-for-enterprise Strengthening License Compliance and Software Security with SBOM Adoption Strengthening License Compliance and Software Security with SBOM Adoption license compliancesoftware securitystrengtheningsbomadoption https://denederlandsekubernetespodcast.buzzsprout.com/2098061/episodes/18266252-121-sbom-or-be-doomed-surviving-the-next-supply-chain-meltdown #121 SBOM or Be Doomed: Surviving the Next Supply-Chain Meltdown In this episode of The Dutch Kubernetes Podcast, Ronald and Jan sit down with Soroosh Khodami to explore one of the most urgent questions in modern software... the nextsupply chainsbomdoomed https://data-seeder-6ea8f7.gitlab.io/factories/ci_reports_sbom_component/ Gitlab::Ci::Reports::Sbom::Component | Data Seeder Docs Gitlab::Ci::Reports::Sbom::Component gitlab cicomponent datareportssbomseeder https://docs.sbom.observer/ SBOM Observer Documentation Complete visibility into your software supply chain with automated SBOM generation, vulnerability tracking, and compliance reporting. sbomobserverdocumentation https://www.jotform.com/form-templates/sbom-review-checklist-form SBOM Review Checklist Form Template | Jotform SBOM Review Checklist Form helps teams standardize SBOM evaluations, record review outcomes, and support consistent data collection across security,... review checklistform templatesbomjotform https://data-seeder-6ea8f7.gitlab.io/factories/sbom_component/ Sbom::Component | Data Seeder Docs component datasbomseederdocs https://live-cltc.pantheon.berkeley.edu/publication/sbom-escrow/ SBOM Escrow - CLTC Feb 16, 2023 - In the current market many organizations want to have complete control over their security posture. This leads these organizations to request a Software Bill... sbomescrowcltc https://security.googleblog.com/2022/10/announcing-guac-great-pairing-with-slsa.html?hl=fr_CA Google Online Security Blog: Announcing GUAC, a great pairing with SLSA (and SBOM)! Posted by Brandon Lum, Mihai Maruseac, Isaac Hepworth, Google Open Source Security Team Supply chain security is at the fore of the indust... https://www.blackduck.com/solutions/software-supply-chain-security.html Software Supply Chain Security & SBOM Management | Black Duck Secure your software supply chain with Black Duck, and gain complete visibility into open source and third-party components. Identify risks, manage SBOMs,... software supply chainsbom managementsecurityblackduck https://advisories.gitlab.com/golang/chainguard.dev/melange/CVE-2025-54059/ melange's world-writable permissions expose SBOM files to potential image tampering | GitLab... CVE-2025-54059 melange's world-writable permissions expose SBOM files to potential image tampering: It was discovered that the SBOM files generated by melange... https://learn.microsoft.com/en-us/azure/security/container-secure-supply-chain/articles/attach-sbom?WT.mc_id=AZ-MVP-5004796 Attach a signed SBOM to a container image | Microsoft Learn Create and attach a signed SBOM to a container image container imageattachsignedsbommicrosoft https://edf.amd.com/sswreleases/rel-v2024.2/cve_sbom/zynqmp-generic_eg/?C=S;O=A Index of /sswreleases/rel-v2024.2/cve_sbom/zynqmp-generic_eg index ofrel https://eracent.com/ Eracent | SAM | ITAM | Software Compliance | SBOM Solutions software compliancesamitamsbomsolutions https://docs.aws.amazon.com/id_id/AWSCloudFormation/latest/TemplateReference/aws-properties-iot-softwarepackageversion-sbom.html AWS::IoT::SoftwarePackageVersion Sbom - AWS CloudFormation Use the CloudFormation AWS::IoT::SoftwarePackageVersion.Sbom resource for IoT. aws iotsbomcloudformation https://marketplace.visualstudio.com/items?itemName=medcrypt-helm.upload-sbom&ssr=false Medcrypt Helm - Upload SBOM - Visual Studio Marketplace Extension for Azure DevOps - Extension for uploading a product SBOM into Medcrypt's Helm system visual studiohelmuploadsbommarketplace https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-k26-sc-sdt-base_edf-qspi/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/zynqmp-k26-sc-sdt-base_edf-qspi https://edf.amd.com/sswreleases/rel-v2024.2/cve_sbom/zynqmp-generic_eg/spdx/ Index of /sswreleases/rel-v2024.2/cve_sbom/zynqmp-generic_eg/spdx index of https://docs.github.com/en/enterprise-cloud@latest/rest/dependency-graph/sboms REST API endpoints for software bill of materials (SBOM) - GitHub Enterprise Cloud Docs Use the REST API to export the software bill of materials (SBOM) for a repository. software bill of materialsrest api endpoints https://tomalrichblog.blogspot.com/2021/03/the-third-sbom-webinar-is-scheduled.html Tom Alrich's Blog: The third SBOM webinar is scheduled! Allan Friedman of the NTIA has scheduled the third in a series of informational webinars on use of software bills of materials (SBOMs) in ... s blogthe thirdtomsbomwebinar https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/versal-vek280-sdt-seg_edf-ospi/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/versal-vek280-sdt-seg_edf-ospi https://edf.amd.com/sswreleases/amd-edf/25.11/CVE_SBOM/versal-2ve-2vm-vek385-revb-sdt-seg_edf-ospi/ Index of /sswreleases/amd-edf/25.11/CVE_SBOM/versal-2ve-2vm-vek385-revb-sdt-seg_edf-ospi https://www.businesswire.com/news/home/20260318019254/en/Keysight-Launches-SBOM-Manager-to-Help-Organizations-Prepare-for-Emerging-Global-Cybersecurity-Regulations Keysight Launches SBOM Manager to Help Organizations Prepare for Emerging Global Cybersecurity... New solution streamlines SBOM generation, vulnerability intelligence, and secure sharing to support compliance with the EU Cyber Resilience Act. sbom managerto help https://sbom-hq.com/ SBOM-HQ | Analyze SBOMs for Security and Compliance SBOM-HQ helps organizations analyze and enrich Software Bills of Materials to uncover vulnerabilities, assess risk, and strengthen software supply chain... for securitysbomhqanalyzecompliance https://mas.owasp.org/MASTG/demos/ios/MASVS-CODE/MASTG-DEMO-0053/MASTG-DEMO-0053/ MASTG-DEMO-0053: Identifying Insecure Dependencies in SwiftPM through SBOM creation - OWASP Mobile... https://www.uschamber.com/security/cybersecurity/coalition-letter-on-a-software-bill-of-materials-sbom-provision-in-the-fy23-national-defense-authorization-act Coalition Letter on a Software Bill of Materials (SBOM) Provision in the FY23 National Defense... Mar 8, 2024 - This Coalition letter was sent to the House and Senate Armed Services Committees, the House Committee on Homeland Security, and the Senate Committee on... software bill of materials https://blogs.eclipse.org/post/marta-rybczynska/announcing-security-training-vulnerability-management-sbom-and-related Announcing Security Training on Vulnerability Management, SBOM and related subjects | Eclipse... security trainingvulnerability managementannouncing https://docs.docker.com/build/ci/github-actions/attestations/ Add SBOM and provenance attestations with GitHub Actions | Docker Docs Feb 21, 2026 - Add SBOM and provenance attestations to your images with GitHub Actions provenance attestationsgithub actionsaddsbomdocker https://doc.coreboot.org/sbom/sbom.html Software Bill of Materials (SBOM) — coreboot 26.06-524-g18352c02e5 documentation software bill of materials