Open Source Security

By Josh Bressers

Package identifiers are really hard

=> 🔊 Play episode (31 min) | Direct episode link | 💬 Share episode

Published January 07, 2024 6:00pm

Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not. Show Notes OpenSSF CISA response purl CPE OmniBOR SWID

=> Return to podcast

Proxy Information
Original URL
gemini://rocketcaster.xyz/episode/18020831171
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
3523.90312 milliseconds
Gemini-to-HTML Time
0.88773 milliseconds

This content has been proxied by September (3851b).