
Sign up to save your podcasts
Or


Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes
By Josh Bressers4.7
4040 ratings
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes
188 Listeners

288 Listeners

2,007 Listeners

368 Listeners

274 Listeners

376 Listeners

649 Listeners

1,026 Listeners

169 Listeners

316 Listeners

8,049 Listeners

314 Listeners

73 Listeners

98 Listeners

45 Listeners