Dependency-Track

438 posts

Dependency-Track banner
Dependency-Track

Dependency-Track

@DependencyTrack

Open Source SBOM Analysis Platform. Reduce Supply Chain Risk. #OWASP #SBOM #SaaSBOM #HBOM #VEX #SoftwareSupplyChain… https://t.co/12EqTyufEE…

Katılım Aralık 2017
29 Takip Edilen1.4K Takipçiler
Dependency-Track retweetledi
Vivek Kumar Sahu
Vivek Kumar Sahu@viveksahu_26·
Today, I attended a session on hashtag @DependencyTrack , where an interesting case study on @monzo Bank was presented by Michael Macnair. It highlighted how they transitioned from a traditional security approach to a more SBOM-driven software supply chain security model. Monzo Bank's Journey to Software Supply Chain Security with SBOMs & Dependency-Track 🔍 Old Approach: • No SBOM (Software Bill of Materials) generation. • Security scans were done using proprietary scanners and in-house tools directly on the code. 🚀 New Approach: • Started generating SBOMs using tools like Syft. • Pushed these SBOMs to Dependency-Track, a popular SBOM management platform. • Leveraged SBOM-driven security analysis for better visibility and risk management. This shift not only improved their security posture but also helped them step into the world of modern software supply chain security, keeping eye on their third party components vulnerabilities, which was lacking in the old architecture. This case study is a great example of how organizations can move beyond traditional scanning and embrace SBOMs for a more structured and proactive approach to security. What are your thoughts on this transformation? Have you seen similar shifts in your organization or still waiting to shifts ? Let’s discuss! 🔍💡 Thanks to Michael Macnair for sharing... #OWASP #OpenSource #CyberSecurity #SBOM #CycloneDX #DependencyTrack #SoftwareSupplyChainSecurity
Vivek Kumar Sahu tweet mediaVivek Kumar Sahu tweet mediaVivek Kumar Sahu tweet media
English
0
1
2
283
Dependency-Track retweetledi
OWASP® Foundation
OWASP® Foundation@owasp·
OWASP Members change the world. Your membership helps shape the organization and drives our projects and community. If you are not a member or are due for renewal within 60 days, please join or renew today and get 10-25% off! owasp.org/membership > Memberships > Apply
OWASP® Foundation tweet media
English
2
12
15
2.9K
Dependency-Track
Dependency-Track@DependencyTrack·
As a reminder, you can watch the recordings, and access the slides, of all previous meetings here: #community-meetings" target="_blank" rel="nofollow noopener">github.com/DependencyTrac… The next community meeting will take place as per usual schedule on December 4th. See you there!
English
0
0
4
159
Dependency-Track
Dependency-Track@DependencyTrack·
The team decided to skip this month’s community meeting, which was originally scheduled for tomorrow (Nov. 6th). Since the last meeting, we released version 4.12.1 (#v4-12-1" target="_blank" rel="nofollow noopener">docs.dependencytrack.org/changelog/#v4-…). We’re aiming to release 4.12.2 in about a week’s time.
English
1
1
5
374
Dependency-Track
Dependency-Track@DependencyTrack·
Join us in tomorrow's community meeting at 4PM UTC to learn about the new version 4.12.0, which is scheduled for release later today! #community-meetings" target="_blank" rel="nofollow noopener">github.com/DependencyTrac…
English
0
8
9
2.5K
Dependency-Track retweetledi
CycloneDX SBOM Spec (OWASP)
CycloneDX SBOM Spec (OWASP)@CycloneDX_Spec·
Fantastic news for @QuarkusIO users! It's now easier than ever to generate accurate CycloneDX SBOMs for your applications. Massive kudos to the Quarkus team for the thoughtful and developer-friendly implementation!
Quarkus@QuarkusIO

We released Quarkus 3.14.3 with some additional bugfixes and a new feature SBOM generation. We don't usually add new features in micro but this is part of the preparation for our upcoming 3.15 LTS release. buff.ly/3B1Wr7G

English
0
7
18
3.2K
Dependency-Track
Dependency-Track@DependencyTrack·
We'd like to take this opportunity to thank the team at @IBM around Melba Lopez and Caroline Lee, who generously hosted all previous community meetings on their WebEx account. Thanks so much!
English
0
0
1
132
Dependency-Track
Dependency-Track@DependencyTrack·
As usual, you can find the invite in the OWASP Software Supply Chain Community Calendar: @group.calendar.google.com&ctz=UTC" target="_blank" rel="nofollow noopener">calendar.google.com/calendar/u/0/e…
English
1
0
0
141
Dependency-Track
Dependency-Track@DependencyTrack·
With the upcoming community meeting on Sept 4th, we're switching from WebEx to @owasp's Zoom. The calendar invite was updated accordingly. If you imported the invite to a calendar app, please verify whether the Zoom details are present, and re-import the invite if they're not.
English
1
2
3
480
Dependency-Track
Dependency-Track@DependencyTrack·
Couldn’t attend this week’s Dependency-Track community meeting? No0WPvVCRyLjwe’ve got the recording. @nscur0 leads us through the project roadmap. We also have special guests from the CycloneDX #cryptography working group presenting #CBOM. Don’t miss it. youtube.com/watch?v=0WPvVC…
YouTube video
YouTube
English
0
4
2
465
Dependency-Track
Dependency-Track@DependencyTrack·
Thank you SANS for this incredible honor. The Dependency-Track project would not be possible without our amazing community of maintainers, contributors, and the organizations that entrust #OWASP in helping reduce their supply chain risk. #SBOM #CycloneDX #EO14028
SANS Institute@SANSInstitute

Open-Source Tool of the Year 💻 goes to the person or organization that created an open-source tool that is of significant value to the community. This year, @DependencyTrack was the Community Winner! Congrats! #SANSDMA

English
1
9
19
5.4K