
Sign up to save your podcasts
Or


Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes
By Josh Bressers4.7
4040 ratings
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes
190 Listeners

289 Listeners

2,011 Listeners

373 Listeners

268 Listeners

374 Listeners

655 Listeners

1,023 Listeners

164 Listeners

318 Listeners

8,041 Listeners

315 Listeners

74 Listeners

98 Listeners

44 Listeners