SPDX @SPDXTeam
An open standard for communicating software bill of material (SBOM) information, including components, licenses, copyrights, and security references. spdx.github.io/spdx-spec/ spdx.dev Joined August 2017-
Tweets125
-
Followers415
-
Following124
-
Likes978
Join the #linux community on Oct. 11 for an #ELISASeminar that focuses on the Road to Safe Space Exploration presented by Ivan Perez Dominguez, Senior Research Scientist at @NASAAmes. Learn more & register: hubs.la/Q024fssH0 @ProjectElisa @NASA #opensource #ELISAProject
#SBOM alone may not encode enough detail to separate non-exploitable vulnerabilities from exploitable ones writes Surendra Pathak in our latest guest blog on VDR, VEX, OpenVEX & CSAF openssf.org/blog/2023/09/0…
Cisco announces SBOMs for recent @cisco products. Great @jefschut blog highlighting 1) the importance of transparency, 2) acknowledging that #SBOM implementation will be a journey, but that 3) we all have to start now for better #supplychain security blogs.cisco.com/security/demon…
.@SPDX_SBOM v3.0 is in the works, and it's expected to include several major changes from the current v2.3. Get an early look at what to expect — such as support for emerging BOM use cases like AI and data — in our new blog. #SBOM @SPDXTeam fossa.com/blog/spdx-3-0/
Fun! A think tank analysis combines my passion for both Taylor Swift and #SBOM. Nice job by @DFRLab & @AtlanticCouncil @CyberStatecraft for unpacking some of the common (and dare we say imperfect) concerns about SBOM from beltway lobbyists. dfrlab.org/2023/07/19/why…
Providing Transparency at Software Development’s core process: build time by @lumjjb and @_ctlfsh spdx.lfprojects.linuxfoundation.org/providing-tran…
Excellent summary of what the team got up to during the SPDX Minisummit last month!
Unpacking the SPDX 3.0 Tooling Mini Summit: A New Era of Compliance and Security spdx.dev/unpacking-the-…
I look forward to attending the SBOM-a-rama next week in Los Angeles, hosted by the @CISAgov. @theopenssf and @spdxteam believe SBOMs are a core part of securing our Open Source supply chain. Let me know if you'll be there! cisa.gov/sbom-2023-agen…
If you don't submit a comment, the USPTO will make it easier and more profitable for patent trolls to target #opensource users with bogus claims.
The USPTO has issued proposed rules that will make it harder for everyone in #opensource to challenge bad #patents. Let them know you want a fair and open system for all, where anyone can seek a review of an invalid patent. Provide your comment: hubs.ly/Q01SLr490
Excited to get the perspectives of @_kate_stewart and @chrisblask on what the world will look like when #SBOM is ubiquitous.
Software #supplychain transparency is emerging w/ #SBOMs. In this @RSAConference talk on April 25 at 9:40 am, @linuxfoundation's @_kate_stewart & @cybeatstech's @chrisblask present best practices that improve IP control, lower operational costs & more: hubs.la/Q01MgNN80
📢bom v0.5.1 the @kubernetesio SPDX SBOM tool is out! This release embeds the @SPDXTeam license list to generate SBOMs in airgapped envs, adds support for apk packages + lots of bug fixes Big thanks to @sbs0x @developerguyba @rosejudge5 and @comedordexis for contributing!
🎉Excited to see that an SPDX SBOM can now be generated by a push of an export button! Thanks for making things easier for all the open source developers on @github! Awesome work @jhutchings0
Need an SBOM and not sure where to start? Now you can get an SBOM with the push of a button. github.blog/2023-03-28-int…
Get the latest on the SBOM Everywhere working group from @joshbressers and @_kate_stewart in this new @theopenssf blog post. #sbom #security #opensource
SBOM Everywhere Update and Python SPDX-Tools hubs.la/Q01Jjd140 #SBOM #SPDX #Python #OSS #OpenSource #OSSsecurity
Check out "Open Source Law Policy and Practice Book Panel" with Amanda Brock (@amandabrockUK), Jilayne Lovejoy (@jilaynelovejoy), Kate Stewart (@_kate_stewart ), Karen Sandler (@o0karen0o), Nithya Ruff (@nithyaruff) & Pamela Chestek (@pchestek) on YouTube! youtu.be/KaOE1J8ycJs
Hearing from @nicpappler about plans to leverage SPDX for functional safety 🦺 @fosdem #SBOM devroom #FuSa
Joshua Watt from Garmin showcasing the upcoming @SPDXTeam build profile as part of his deep dive into build environment SBOMs in the @yoctoproject
If you're going to @OpenEmbeddedOrg's OE workshop on February 6 in Brussels, don't miss this talk by @Arm's Peter Hoyes about "Integrating #ZephyrRTOS using @yoctoproject." Learn more: hubs.la/Q01B51kg0 @ZephyrIoT #opensource #embedded #openembedded #RTOS
Dan Lorenc @lorenc_dan
11K Followers 2K Following OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at https://t.co/sGmuUU9JbG Sigstore: https://t.co/dWKlyYu6kv
developer-guy @developerguyba
5K Followers 2K Following 🚀CNCF Ambassador 23• 🐳 Docker Captain 23•🎖Best Sigstore Evangelist 22 • ㏅CDF Ambassador 23 • 🇹🇷@kcdturkey Organizer •🕴Organizer @cloudnativetr @devopstr
Luke Hinds @decodebytes
3K Followers 750 Following Creator of https://t.co/T8htHI7vHB , now building https://t.co/OBABqFvHE2 - the agent security platform.
Allan is @allanfriedm... @allanfriedman
7K Followers 2K Following #SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.
Continuous Delivery F... @CDeliveryFdn
8K Followers 548 Following CDF open source projects: @_cdevents, @jenkinsci, @orteliusos, @screwdrivercd, @spinnakerio
CNCF @CloudNativeFdn
112K Followers 756 Following CNCF is the home of @kubernetesio, @prometheusio, @envoyproxy, and many more. Join us at #kubecon.io 18-19 June in Mumbai
Cole Kennedy @colek42c
546 Followers 459 Following Founder - TestifySec - Secure Systems from Source to Production
puerco @puerco
3K Followers 2K Following Adolfo García Veytia / Technical Lead @Kubernetesio SIG Release / Staff Software Engineer @StackLokHQ / historian / WorldCyclist / fmr @chainguard_dev @uservers
ELISA Project @ProjectElisa
978 Followers 325 Following ELISA Project aims to make it easier to build & certify safety-critical apps. Follow on LinkedIn for updates: https://t.co/qKWv0tgl70
Zephyr Project @ZephyrIoT
11K Followers 1K Following An #opensource project that builds a safe, secure & flexible RTOS for resource-constrained devices. #ZephyrRTOS #ZephyrDevSummit
Shane Coughlan @opendawn
1K Followers 2K Following Ecosystem Strategist | Global Ambassador | Cross-Industry Facilitator | Building Frameworks for Complex IP Pipelines
Brandon Lum @lumjjb
971 Followers 626 Following 🔑CNCF Security TAG Co-Chair Emiritus 💻Google Engineer 🎸Musician/Guitarist All things Containers + Security... Opinions are my own...
OpenMainframeProject @OpenMFProject
5K Followers 2K Following A @LinuxFoundation Project for #OpenSource on the #Mainframe as the standard for enterprise class systems and applications. #OpenMainframe #OpenMainframeSummit
Ana JS @anajsana95
1K Followers 671 Following Project Manager @todogroup | @PyTorch | @linuxfoundation English • Español • 日本語 🇯🇵 M.S #DataScience 📊 #DevRel 🥑
OpenUK @openuk_uk
5K Followers 3K Following UK leadership and global collaboration in Open Tech Sign up to newsletter https://t.co/yA6lWM93qZ
Justin Hutchings @jhutchings0
2K Followers 2K Following Senior Director of PM @cloudflare | Formerly @github @microsoft. Mostly tech, security, Star Trek 🖖🏻, with a sprinkle of far left political outrage.
James Strong @strongjz
3K Followers 5K Following SA @isovalent, @Networkandk8s Author, ingress-nginx maintainer, weightlifter, ACG instructor,adjectives, yay, Opinions my own? he/him.
Feynman Zhou @FeynmanZhou
1K Followers 2K Following Product Manager @tencentcloud , Ex @Microsoft, @KubeSphere, @HPE CNCF Ambassador. InfoQ DevOps Editor
Sudoer777 @sudoer777
186 Followers 7K Following
TASSILO VOUTTA @tass_lab
0 Followers 156 Following
Aleš Svoboda @cdmaslo
14 Followers 451 Following
Nishidh @nishidh41
647 Followers 4K Following Advocate at Gujarat High Court and Founder at Oxylex | Amateur Graphic Designer | Alumni: @iitkgp (2011-2014) @NalsarUni @themsubaroda @gujuni1949
robbie robbins @robbie_robbins
215 Followers 690 Following Determined sales and business development pro with 20+ years experience in Cyber Security, Info Security, IT GRC, IDAM and Encryption markets.
Brett Lynden Everingh... @BrettEv10
93 Followers 2K Following Just another DEAD CONCERNED DAD WAITING TO HAPPEN AGAIN EXCEPT THIS TIME?? TRY ME..JUST TRY ME..
磐👻 @8282882eiijdjd
5 Followers 365 Following
Kevin Young @KevinYo99999
3 Followers 85 Following
®Dr.$¥sTm ʕ(⟁BÄ... @3b3rSonCMonToy4
319 Followers 7K Following |-l-|®AZ.3x-Agnt #NFS #NtworkFiLSysTm(@CIA) #Bio-M-3thic-Gπ-Inf-Tch-W3Ap0πS(@DARPA) ViSu-#AnALyTicS VI-#𝕏î0N-AR¥-#Dr-🝪🜁® #TGAOTU◬#BĀ-#ÂL-#ME👁777©|#תַּלְמוּד
Nir Zilberman @nirzilberman
42 Followers 7K Following
らん @ran350jp
686 Followers 1K Following 某F社 | 立命館 情報理工学研究科 | 登録セキスペ | Seccamp'24ネクスト | CODE BLUE'24学スタ | Sustainable Software Development | ずとまよ 将棋 麻雀 | ※発言は個人のもので、所属する団体や企業とは一切関係ありません
Zetta @ZettaOne
99 Followers 274 Following
Michael Scofield @gmscofield123
0 Followers 44 Following
®𝔻r$¥sŦm ʕ(⟁... @Eb3rSonCMonToY4
337 Followers 7K Following S.O.Ex-Agent SFN⟁ (⟁LoGisT⟁) (#N👁) #RealGeOp$¥sŦm🌎° #Bio-M-Ethic-Geπ-Info-Tech-IA-Weapons🌐* #DigVisuAnaly⟁ ®UL71M47UM #NeuPL⛮ 23/9/24 #OpInFac7oRy👁VÎXīŌŅÂŘ¥
Art อาท แบ�... @bact
133K Followers 6K Following Arthit Suriyawongkul. Pushing #digitalrights #ict4d w @thainetizen @mekongict. PhDing #AIethics & accountability at @DREAL_ie @ADAPTCentre @TCDdublin.
FossID @FOSSID_AB
136 Followers 83 Following Empowering people. One line of code at a time. We encourage people to use open-source confidently & safely.
John Dziurłaj @Dziurlaj
767 Followers 3K Following Where Politics, Policy, and Technology meet. Also @dziurlaj.bsky.social $RT -ne "Endorsment"
Vanessa Guo @Vanessa80169097
13 Followers 109 Following Open Source IP counsel; diplômée de l'Université Paris II Panthéon-Assas et CEIPI.
Compfix IT @Compfix_IT
927 Followers 5K Following Enterprise level Support for SMB. We deliver. We are mindful, goal orientated and pragmatic. All platforms. Medical & Security IT Specialists. 24/7 Monitoring.
Nnenna 👩🏽�... @nnennahacks
6K Followers 1K Following 👩🏽💻 DevRel Lead @QodoAI. Codex Ambassador. top 1% @OpenAI. Engineer obsessed with software quality in AI. DevEx. Systems thinker. Fit nerd.
Young Security Inc @Y0UNGSECURITY
42 Followers 345 Following Young Security, Inc. provides guidance and technical solutions on AI, IT, Cybersecurity, and Information Assurance for founders at or near inflection points.
バルスのニキ @kotakanbe
1K Followers 643 Following Creator of Vuls & uzomuzo-oss · R&D & Tech PM, FutureVuls · FIRST VulnCon 2026 speaker · IPSJ Software Japan Award 2019 · Google OSS Peer Bonus 2022
Frustrated in AppSec @FAppsec
75 Followers 182 Following
Radoslav Dimitrov @radoslav_dimitr
108 Followers 386 Following #opensource #supplychain #tuf #sigstore #golang #kubernetes @StackLokHQ ex-@VMware
Premanand Natarajan @TeknoStrat
220 Followers 7K Following Technical Strategist https://t.co/JLPIKd3lMR https://t.co/kaGDDJmlSP
Klar Name @patrick73965478
64 Followers 594 Following
Beth Pariseau @PariseauTT
4K Followers 3K Following Senior News Writer, @InformaTTGT $TTGT. Thoughts here are my own. beth.pariseau at informatechtarget dot com @[email protected]
Roberto Di Cosmo @rdicosmo
5K Followers 5K Following Scientist professor hacker writer citizen. Committed to building a better world through science technology and community. Director @swheritage. Follow ≠ endorse
Nicholas Leclerc @NicholasLecler6
66 Followers 1K Following Hi. Look at what I have to show you, y’all !
Derek Murawsky @OutOfOrder2day
107 Followers 280 Following Platform, cloud & DevSecOps guy at a stealth fintech startup. Husband, Father, Homesteader, Geek
Omkhar Arasaratnam @_omkhar
311 Followers 152 Following https://t.co/PsBN05Eqsb || https://t.co/aJ4RwewfJB || https://t.co/U2xuM1N95Z || https://t.co/npQi7LLTn1 || https://t.co/JUIQS205kQ
Maemalynn Meanor @Maemalynn
134 Followers 147 Following Director of PR & Communications at the @LinuxFoundation managing #opensource projects. @ProjectELISA @ZephyrIoT @Openmfproject & more! Views are my own...
Software Heritage @SWHeritage
4K Followers 2K Following We collect, preserve, and share #software #sourcecode for present and future generations. #swh #softwarecommons #freesoftware #opensource
zhangzhenyu0406 @zhangzheny22596
1 Followers 25 Following
Axel Baumann @AxelBaumann
337 Followers 5K Following
It's 5:05 @Its505pm
53 Followers 78 Following It's 5:05! We have reporters around the world, bringing you daily updates on open source and cybersecurity news. 10 minutes a day keeps the FOMO away.
Dan Lorenc @lorenc_dan
11K Followers 2K Following OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at https://t.co/sGmuUU9JbG Sigstore: https://t.co/dWKlyYu6kv
developer-guy @developerguyba
5K Followers 2K Following 🚀CNCF Ambassador 23• 🐳 Docker Captain 23•🎖Best Sigstore Evangelist 22 • ㏅CDF Ambassador 23 • 🇹🇷@kcdturkey Organizer •🕴Organizer @cloudnativetr @devopstr
Luke Hinds @decodebytes
3K Followers 750 Following Creator of https://t.co/T8htHI7vHB , now building https://t.co/OBABqFvHE2 - the agent security platform.
Allan is @allanfriedm... @allanfriedman
7K Followers 2K Following #SBOM Champion. Full service technocrat. Now at @CISAgov, formerly NTIA. Lapsed{engineer, academic, author}. Personal Account.
The Linux Foundation @linuxfoundation
587K Followers 9K Following A nonprofit organization enabling mass innovation through open source. #linux #kubernetes #riscv #hyperledger #anuket #openssf #openjs #o3de and more!
OpenSSF @openssf
6K Followers 29 Following Open Source Security Foundation (OpenSSF) Together, we're securing the #opensource ecosystem #OSSSecurity https://t.co/uUpbn44G4Q https://t.co/adjLU8dbk0
Chris Aniszczyk @cra
19K Followers 3K Following Building a Better World Through Open Collaboration / @CloudNativeFdn @linuxfoundation / Always Paying it Forward
CNCF @CloudNativeFdn
112K Followers 756 Following CNCF is the home of @kubernetesio, @prometheusio, @envoyproxy, and many more. Join us at #kubecon.io 18-19 June in Mumbai
puerco @puerco
3K Followers 2K Following Adolfo García Veytia / Technical Lead @Kubernetesio SIG Release / Staff Software Engineer @StackLokHQ / historian / WorldCyclist / fmr @chainguard_dev @uservers
Chainguard ⛓️ @chainguard_dev
6K Followers 116 Following The trusted source for open source (& memes).
ELISA Project @ProjectElisa
978 Followers 325 Following ELISA Project aims to make it easier to build & certify safety-critical apps. Follow on LinkedIn for updates: https://t.co/qKWv0tgl70
Zephyr Project @ZephyrIoT
11K Followers 1K Following An #opensource project that builds a safe, secure & flexible RTOS for resource-constrained devices. #ZephyrRTOS #ZephyrDevSummit
Shane Coughlan @opendawn
1K Followers 2K Following Ecosystem Strategist | Global Ambassador | Cross-Industry Facilitator | Building Frameworks for Complex IP Pipelines
Google Open Source @GoogleOSS
82K Followers 145 Following Announcing new open source releases, exploring projects, sharing how we approach FOSS, and supporting communities around the world.
Brandon Lum @lumjjb
971 Followers 626 Following 🔑CNCF Security TAG Co-Chair Emiritus 💻Google Engineer 🎸Musician/Guitarist All things Containers + Security... Opinions are my own...
Ana JS @anajsana95
1K Followers 671 Following Project Manager @todogroup | @PyTorch | @linuxfoundation English • Español • 日本語 🇯🇵 M.S #DataScience 📊 #DevRel 🥑
OpenUK @openuk_uk
5K Followers 3K Following UK leadership and global collaboration in Open Tech Sign up to newsletter https://t.co/yA6lWM93qZ
Justin Hutchings @jhutchings0
2K Followers 2K Following Senior Director of PM @cloudflare | Formerly @github @microsoft. Mostly tech, security, Star Trek 🖖🏻, with a sprinkle of far left political outrage.
sigstore @projectsigstore
4K Followers 1 Following sigstore is a non-profit , public good software signing service funded under the OpenSSF. https://t.co/HYGAJ06Z11 [email protected]
James Strong @strongjz
3K Followers 5K Following SA @isovalent, @Networkandk8s Author, ingress-nginx maintainer, weightlifter, ACG instructor,adjectives, yay, Opinions my own? he/him.
Surendra @interlynksp
3K Followers 5K Following Enabling security, transparency, and compliance in the software supply chain @ https://t.co/LYr5Ahwgem
Software Heritage @SWHeritage
4K Followers 2K Following We collect, preserve, and share #software #sourcecode for present and future generations. #swh #softwarecommons #freesoftware #opensource
Omkhar Arasaratnam @_omkhar
311 Followers 152 Following https://t.co/PsBN05Eqsb || https://t.co/aJ4RwewfJB || https://t.co/U2xuM1N95Z || https://t.co/npQi7LLTn1 || https://t.co/JUIQS205kQ
Axel Baumann @AxelBaumann
337 Followers 5K Following
FOSSA @getfossa
773 Followers 428 Following FOSSA is a leading application security and compliance platform that specializes in helping engineering teams deliver trusted software.
SPDX SBOM @SPDX_SBOM
163 Followers 29 Following Open standard for communicating Software Bill of Material information (SBOMs) | @linuxfoundation open source project | Freely available ISO/IEC 5962:2021
Tracy Miranda @tracymiranda
4K Followers 3K Following Making open source secure by default. Previously at @chainguard_dev, @cdeliveryfdn, @cloudbees. Open source powered. 🇨🇦 🇬🇧 🇰🇪
Gareth Rushgrove @garethr
13K Followers 4K Following VP Product @snyksec. @openpolicyagent Conftest maintainer. Developer, designer, product. Open source geek. Devops Weekly. @gdsteam alum. he/him.
Zoran Jovanović 🌻... @jovzoran
116 Followers 941 Following Architect @ Volvo Cars (ex Sony). Opinions my own. He/him (cis). @jyz.bsky.social
Takashi NINJOUJI @TakashiNinjouji
8 Followers 28 Following
Dan Luhring @danluhring
489 Followers 389 Following Heading up Vulnerability Management @chainguard_dev
Grype @GrypeProject
1K Followers 257 Following Grype is an open source vulnerability scanner for Software Bills of Material (SBOMs), containers, and filesystems. Created and maintained by @Anchore.
Syft @SyftProject
1K Followers 316 Following Syft is an open source tool to generate a Software Bill of Materials (SBOM) from a container image or filesystem. Created and maintained by @Anchore.
David Maynor @Dave_Maynor
14K Followers 6K Following No tree, it is said, can grow to heaven, unless it’s roots reach down to hell. Offensive Security, AI LLM Ops, hardware hacking
Omar Ωr Santos @santosomar
18K Followers 2K Following Cybersecurity, AI security research, bug hunting, IR, threat intel, @redteamvillage_ lead. @Cisco PSIRT. Prior @USMC. Author of over 25 books.
Reproducible Builds @ReproBuilds
2K Followers 60 Following A set of software development practices that create an independently-verifiable path from source code to the binary code used by computers.
sbomx @sbom_x
61 Followers 731 Following Software Bill of Materials · Software Supply Chain Security · License Check · Vulnerability Analysis
Terri O 🍁 @terriko
1K Followers 361 Following web security researcher, photographer, teacher, open source geek, naturalist, musician, maker, reader... with a phd in horribleness (err, computer security)
CYBEATS @cybeatstech
618 Followers 1K Following Cybeats, a cybersecurity leader, enhances software supply chain transparency with SBOM management. Specializing in risk management, we ensure software security.
Ariel Richtman (gone,... @ArielRichtman
52 Followers 905 Following DevOps, Cloud/Platform Engineering, and all things in facilitative infrastructure @[email protected]
Furkan Türkal @furkanturkaI
579 Followers 1K Following swe @Trendyol | foss | cncf | sscs | platform | k8s | containers | devx | arch | compilers | electronics | game dev | flyin' around clouds | opinions are GPLv3
Steve Lasker @SteveLasker
1K Followers 356 Following DataTrails, Docker, Former @Microsoft, @IETF, @OCI_ORG, @ORASPROJECT focusing on secure artifact workflows, Sailing/Racing, Biking, Climbing
Gabriele Columbro @mindthegabz
1K Followers 525 Following GM @lf_europe, ED of @finosfoundation, Open Sorcerer, @theASF committer, Speaker, SSC Napoli supporter, reggae lover, special needs dad
William Bartholomew @iamwillbar
653 Followers 2K Following He/him, Australian-born, USA-residing Director of Public Policy - Responsible AI @ Microsoft. Views are my own.
Jonas Rosland @jonasrosland
3K Followers 2K Following Director of Open Source Programs @sysdig. Executive Director @hitsaveorg. He/him. DMs are open. @jonasrosland @ bsky
brianbehlendorf @brianbehlendorf
12K Followers 2K Following Also @[email protected] BoD @Mozilla, @Filecoin, @EFF. Formerly AI and OWF @LinuxFoundation, GM @openssf, ED @Hyperledger, CTO @WEF, et al. He/him.
Anchore @anchore
3K Followers 1K Following Securing and managing the software supply chain. Proud parent of @SyftProject and @GrypeProject.
uosןıW qoɔɐJ @JacobDjWilson
5K Followers 3K Following MBA graduate @umich, Alumni @michigantech #CyberSecurity #ApplicationSecurity #Compliance #AI #Embedded #IoT #Opensource
GCC - GNU Toolchain @gnutools
12K Followers 188 Following GCC, Binutils, GDB, GLIBC. The system compiler for the FOSS and Linux software ecosystem. Continually Improving.
tektoncd @tektoncd
4K Followers 39 Following Twitter account for the Tekton project: https://t.co/wsd4qGce4p
Joshua Watt @JPEW_dev
22 Followers 20 Following
Stephen Augustus | �... @stephenaugustus
9K Followers 2K Following Over on #Bluesky now: https://t.co/pbedezubg7 // #BlackTechTwitter
Santiago @torresariass
831 Followers 899 Following Assistant Professor of ECE and Security Bricoleur @PurdueEngineers | @arch_security | views are my own




















