Open Source Security
Open Source Security
Josh Bressers
Episode 410 - Package identifiers are really hard
31 minutes Posted Jan 8, 2024 at 12:00 am.
0:00
31:52
Download MP3
Show notes

Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.

Show Notes