
Sign up to save your podcasts
Or
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes4.7
4040 ratings
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes2,001 Listeners
369 Listeners
639 Listeners
288 Listeners
370 Listeners
266 Listeners
185 Listeners
1,017 Listeners
164 Listeners
321 Listeners
7,971 Listeners
315 Listeners
73 Listeners
98 Listeners
43 Listeners