Skip to content

Support for SPDX BOMs #1222

Answered by stevespringett
jblu42 asked this question in Q&A
Oct 12, 2021 · 2 comments · 5 replies
Discussion options

You must be logged in to vote

It recently became ISO standard (ISO/IEC 5962:2021)

ISO now has two SBOM standards that cannot achieve the majority of cybersecurity use cases today. CycloneDX is an OWASP standard that achieves the majority of cybersecurity use cases and supports the most widely requested license use cases.

The SBOM Topic is mostly driven by Open Source Compliance

SBOM is driven primarily by cybersecurity use cases, not legal ones. If license use cases were not possible, SBOM would still be a requirement of Executive Order 14028. The NTIA minimum elements for SBOM do not contain any fields related to license, but do contain identity fields used for vulnerability analysis use cases including purl, CPE…

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
2 replies
@antovski
Comment options

@stevespringett
Comment options

Answer selected by jblu42
Comment options

You must be logged in to vote
3 replies
@stevespringett
Comment options

@SihuiHu6
Comment options

@sschuberth
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants