The mission of this group is to bring together utility professionals in the power industry who are in the thick of the digital utility transformation. 

Post

Yes Virginia, SBOM is real.

image credit: OWASP CycloneDX project

Richard Brooks's picture
Co-Founder and Lead Software Engineer Reliable Energy Analytics LLC

Successful developer of Energy Industry B2B and Cyber security standards at North American Energy Standards Board (NAESB) (www.naesb.org) since 1995; ANSI Meritorious Service Award Recipient;...

  • Member since 2018
  • 1,064 items added with 430,279 views

The proficient and highly productive software engineers developing and supporting the NTIA supported CycloneDX SBOM standard within OWASP have announced the release of version 1.3 with some cool new features that will help improve software supply chain verification along with a plethora of tools to help implement SBOM now. Here are a few noteworthy features of this release:

Compositions:
The inventory of components, services, and their relationships to one another can be described using compositions.

Properties / name-value store:
The CycloneDX standard is fully extensible allowing for complex data to be represented in the SBOM that is not provided by the core specification.

Your access to Member Features is limited.

Copyright and license evidence:
In addition to the existing support for component-level copyrights, SPDX license IDs, SPDX license expressions, and unresolved license names, CycloneDX now supports evidence of copyrights and licenses

SBOM license
The CycloneDX spec has never defaulted to a specific license, but now includes the ability to specify a license for which the SBOM itself is licensed under.

More information is available here:

Finally, the CycloneDX tool center has been updated and should now include the tools that are referenced in the CycloneDX tools document from NTIA.

https://cyclonedx.org/schema/bom-1.3.xsd
https://cyclonedx.org/schema/bom-1.3.schema.json
https://cyclonedx.org/schema/bom-1.3-strict.schema.json
https://cyclonedx.org/schema/bom-1.3.proto

Discussions

Spell checking: Press the CTRL or COMMAND key then click on the underlined misspelled word.

No discussions yet. Start a discussion below.

Get Published - Build a Following

The Energy Central Power Industry Network is based on one core idea - power industry professionals helping each other and advancing the industry by sharing and learning from each other.

If you have an experience or insight to share or have learned something from a conference or seminar, your peers and colleagues on Energy Central want to hear about it. It's also easy to share a link to an article you've liked or an industry resource that you think would be helpful.

                 Learn more about posting on Energy Central »