Patrick Dwyer

2.2K posts

Patrick Dwyer

Patrick Dwyer

@coderpatros

Principal Consultant @CyberCX and @OWASP @CycloneDX_Spec #SBOM Project Co-Lead. All views are my own.

Sunshine Coast, Queensland Sumali Mayıs 2014
428 Sinusundan472 Mga Tagasunod
Patrick Dwyer nag-retweet
DDD Brisbane
DDD Brisbane@DDDBrisbane·
We're now accepting sponsorship for our 2024 conference, held at Brisbane State High School on December 7th. Get your brand in front of 450+ developers, testers, managers, and more! DM or email sponsorship@dddbrisbane.com for a copy of our 2024 prospectus.
DDD Brisbane tweet media
English
0
8
9
1.3K
Patrick Dwyer nag-retweet
CycloneDX SBOM Spec (OWASP)
CycloneDX SBOM Spec (OWASP)@CycloneDX_Spec·
#OWASP CycloneDX v1.6 now available with support for Cryptography Bill of Materials (CBOM), Attestations, and more. Explore whats new in the: - Authoritative Guide to CBOM - Authoritative Guide to Attesations - Authoritative Guide to SBOM, Second Edition cyclonedx.org/guides/
English
0
4
5
346
Patrick Dwyer nag-retweet
CycloneDX SBOM Spec (OWASP)
CycloneDX SBOM Spec (OWASP)@CycloneDX_Spec·
CycloneDX v1.6 has landed with support for tracking cryptographic assets and their dependencies for Post-Quantum Cryptography (PQC) readiness. #CBOM CycloneDX Attestations provides “compliance as code” Enhancements to existing AI/ML support… #SBOM cyclonedx.org/news/cyclonedx…
English
0
3
6
2.5K
Patrick Dwyer nag-retweet
BSides Brisbane
BSides Brisbane@Bsides_BNE·
Happy New Year to all! Start the year with a bang by securing your seat at the #BSidesBrisbane2024 event. Tickets are on sale now, don't miss out! The first 50 ticket sales using discount code BSIDES-EARLYBIRD will receive 10% off Grab your tickets here: buff.ly/3GYQnN7
English
0
8
11
1.8K
Patrick Dwyer nag-retweet
TC54
TC54@EcmaTC54·
The Ecma TC54 website is now live! Visit tc54.org to learn more about the ongoing work the technical committee is pursuing and how to contribute. #ecma #tc54 #owasp #cyclonedx #sbom
English
0
5
10
245
Patrick Dwyer nag-retweet
TC54
TC54@EcmaTC54·
Ecma TC54 is holding its first call on Thursday, 13 December at 10:30 U.S. Eastern. Meetings are open to Ecma member organizations. Reach out to @stevespringett and @littledan for Zoom link.
English
1
2
4
455
Patrick Dwyer nag-retweet
Dependency-Track
Dependency-Track@DependencyTrack·
Thank you SANS for this incredible honor. The Dependency-Track project would not be possible without our amazing community of maintainers, contributors, and the organizations that entrust #OWASP in helping reduce their supply chain risk. #SBOM #CycloneDX #EO14028
SANS Institute@SANSInstitute

Open-Source Tool of the Year 💻 goes to the person or organization that created an open-source tool that is of significant value to the community. This year, @DependencyTrack was the Community Winner! Congrats! #SANSDMA

English
1
10
20
5.4K
Patrick Dwyer nag-retweet
swisscyberstorm
swisscyberstorm@swisscyberstorm·
The @CycloneDX_Spec (Software Bill of Materials Standard) project took a step further with the convening of a new technical committee at @EcmaIntl. @coderpatros, co-lead of the project, spoke about this at @swisscyberstorm 2021. See his talk here: youtu.be/zQmtdV-4ZiQ?si…
YouTube video
YouTube
TC54@EcmaTC54

Earlier today, Technical Committee 54 was officially convened within @EcmaIntl as a royalty-free task group. #TC54 is chartered with standardizing #OWASP @CycloneDX_Spec, standards and algorithms that advance transparency and sharing of this information across the supply chain.

English
0
1
2
304
Patrick Dwyer nag-retweet
TC54
TC54@EcmaTC54·
Earlier today, Technical Committee 54 was officially convened within @EcmaIntl as a royalty-free task group. #TC54 is chartered with standardizing #OWASP @CycloneDX_Spec, standards and algorithms that advance transparency and sharing of this information across the supply chain.
TC54 tweet media
English
2
14
29
17.5K
Patrick Dwyer nag-retweet
OWASP SCVS Standard
OWASP SCVS Standard@OWASP_SCVS·
We’re proud to announce the immediate availability of the SCVS BOM Maturity Model. The model allows organizations to evaluate #SBOM quality and mature and optimize their investment in software and system transparency. einpresswire.com/article/665343… #OWASP
English
0
4
7
491
Patrick Dwyer nag-retweet
Tech At Bloomberg
Tech At Bloomberg@TechAtBloomberg·
Bloomberg is proud to be a founding member of @EcmaIntl's TC54, which will work with @owasp on standardizing #CycloneDX & related technologies to improve software and system transparency, which are critical to securing the #softwaresupplychain for modern applications #SBOM
CycloneDX SBOM Spec (OWASP)@CycloneDX_Spec

@owasp Foundation Joins Ecma International to Drive Software Transparency and Standardization of OWASP #CycloneDX. Press release: einpresswire.com/article/661184… Blog post: owasp.org/blog/2023/10/1… #SBOM #SoftwareTransparency #SaaSBOM #HBOM #CBOM #EO14028

English
0
9
12
8.3K
Patrick Dwyer
Patrick Dwyer@coderpatros·
@tuckner @allanfriedman I wouldn't typically store it in the repo unless you are manually managing dependencies, and the SBOM. The first place I would store it is as an additional build artifact. And then publish it to something like Dependency-Track as part of the release process.
English
0
0
0
32
tuckner
tuckner@tuckner·
@coderpatros @allanfriedman Nothing specific which I'm realizing is a problem. For sake of an example, lets just assume an internal project with a org requirement to have an SBOM generated for it.
English
1
0
0
37
tuckner
tuckner@tuckner·
Where are folks storing their SBOMs? Top level of the repo? What is a standard file name for it? Just sbom.format? @allanfriedman if you're around
English
4
0
2
3.2K