
Sign up to save your podcasts
Or
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes4.6
4141 ratings
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show Notes364 Listeners
639 Listeners
369 Listeners
263 Listeners
180 Listeners
1,012 Listeners
161 Listeners
316 Listeners
407 Listeners
190 Listeners
316 Listeners
77 Listeners
135 Listeners
91 Listeners
43 Listeners