
Sign up to save your podcasts
Or


Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes
By Josh Bressers4.7
4040 ratings
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes
189 Listeners

289 Listeners

2,005 Listeners

369 Listeners

272 Listeners

374 Listeners

648 Listeners

1,034 Listeners

168 Listeners

322 Listeners

8,111 Listeners

316 Listeners

74 Listeners

97 Listeners

44 Listeners