Open Source Security Podcast
Episode 410 - Package identifiers are really hard
- Autor: Vários
- Narrador: Vários
- Editor: Podcast
- Duración: 0:31:52
- Mas informaciones
Informações:
Sinopsis
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not. Show Notes OpenSSF CISA response purl CPE OmniBOR SWID