#CycloneDX
CycloneDX cancels their bug-bounty program blaming AI slop:

"This caused a lot of extra work which is why we decided to abandon the program. Thanks AI."

https://github.com/CycloneDX/cyclonedx-rust-cargo/pull/786
Remove Bug Bounty program by lfrancke · Pull Request #786 · CycloneDX/cyclonedx-rust-cargo
We received almost entirely AI slop reports that are irrelevant to our tool. It's a library and most reporters didn't even bother to read the rules or even look at what the intended purpose...
github.com
May 23, 2025 at 11:33 AM
If you care for the evolution of the Java ecosystem, consider expressing your opinion on github.com/CycloneDX/cy...
Proposal: cdx:java namespace for Java module names · Issue #198 · CycloneDX/cyclonedx-property-taxonomy
Hi, For over 10 years, since Java 9, a jar can declare a module name, either in its module-info.class or through the Automatic-Module-Name manifest attribute. That name is what the JVM runtime, the...
github.com
September 26, 2026 at 10:22 AM
The OWASP CycloneDX team will be well represented at @fosdem.bsky.social ! We'll talk in the Security dev room and the SBOM dev room. Find us if you want to chat about CycloneDX, PURL, TEA or other CycloneDX projects.

#SBOM #CYCLONEDX #TEA #PURL

@cyclonedx.bsky.social @owasp.org
January 16, 2025 at 3:36 PM
From @cyclonedx.bsky.social Level up your Ruby SBOMs with cdxgen v11.1.0 - now featuring #evinse for enhanced security and insights. Chat with #cdxgenGPT to learn more. chatgpt.com/g/g-673bfeb4...
ChatGPT - CycloneDX Generator (cdxgen)
I'm a CycloneDX and xBOM expert.
chatgpt.com
January 19, 2025 at 6:43 PM
🛡️ Sentinel Forge is live — now indexed on Zenodo with a DOI!

A local SOC-style desktop tool built with Electron, React & TypeScript:
• Supply chain audits (npm/Yarn/pnpm/Bun)
• Local SAST & Secret scanning
• Git-OPS & CycloneDX SBOM

🔗 github.com/chavatte/sentinel-forge

#DevSecOps #AppSec #InfoSec
September 23, 2026 at 11:12 AM
Binarly's Alex Matrosov has launched SBOM Tools, a platform to compare and analyze SBOM files to understand software supply chain risks

sbom.tools
sbom-tools — From SBOM to Insight
Semantic SBOM diff and analysis tool. Compare, validate, and assess the quality of SBOMs across CycloneDX and SPDX formats.
sbom.tools
March 1, 2026 at 1:07 AM
From Jeff Williams at @cyclonedx.bsky.social
"The new Cybersecurity EO requires machine readable secure software development attestations. Good thing the OWASP CycloneDX project already created the CDXA standard to capture attestations."

Check it out: cyclonedx.org/capabilities...
January 17, 2025 at 9:37 AM
Jan Kowalleck is a #SovereignTechFellow and works on software supply chain standards, including as maintainer of OWASP CycloneDX: www.sovereign.tech/news/meet-th... 6/
March 13, 2025 at 2:07 PM
🐧 **CycloneDX CLI – command-line toolkit for BOM documents**

CycloneDX CLI analyzes, converts, merges, signs, verifies and validates BOM documents, with support for CycloneDX and SPDX formats. The post CycloneDX CLI – command-line toolkit for BOM documents a...

📰 Source: LinuxLinks
🔗 Link […]
Original post on igeek.gamer-geek-news.com
igeek.gamer-geek-news.com
September 22, 2026 at 9:20 PM
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. A complete and accurate inventory of all first-party and third-party components is essential for risk and vulnerability identification. Check it out!
KoalaCon 2024 was a huge success. Thank you to all the speakers, including Olle E Johansson, Anthony Harrison, Niklas Düster, Viktor Petersson, and Piotr P. Karwasz. Couldn't attend. No worries, the recording is available on YouTube.

youtu.be/NStzYW4WnEE?...

#OWASP #SBOM #SoftwareTransparency
OWASP KoalaCon 2024
YouTube video by OWASP CycloneDX
youtu.be
December 3, 2024 at 5:40 AM
📦 mteu/sbom-parser 0.5.0

Type-safe parser for CycloneDX Software Bill of Materials (SBOM) JSON files

🔗 https://github.com/mteu/sbom-parser
September 25, 2026 at 9:59 PM
Do you, like me, scratch your head and think "SBOMs, what are they good for?" ? If you do, why not join one of the working groups on CycloneDX - now even easier to do by checking out the new site at https://cyclonedx.org !
1/2
CycloneDX Bill of Materials Standard | CycloneDX
OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. The specification supports Software Bill of Materials (SBOM), Software-as-a-Service Bill of Materials (SaaSBOM), Hardware Bill of Materials (HBOM), Operations Bill of Materials (OBOM), Vulnerability Disclosure Reports (VDR), and Vulnerability Exploitability eXchange (VEX).
cyclonedx.org
January 8, 2025 at 4:21 PM
Join us on Wed May 28, 2025 in Barcelona for a hands-on hackathon to test Beta 1 of the Transparency Exchange API (TEA) — a new way to securely exchange SBOMs, attestations & more.

Free registration, thanks to @owasp.org and Ecma International.

cyclonedx.org/events/hacka...

#CycloneDX #SBOM
Transparency Exchange API (TEA) Hackathon - Barcelona 2025 | CycloneDX
Join us in Barcelona to test and shape the Transparency Exchange API, the next evolution in secure supply chain communication.
cyclonedx.org
April 21, 2025 at 8:39 PM
Elixir now meets OpenChain (ISO/IEC 5230) standards! This milestone strengthens our commitment to open source license compliance and secure development. Get the full story and see what it means for contributors and users alike:
elixir-lang.org/blog/2025/02...
Announcing Elixir OpenChain Certification
The Elixir project now meets OpenChain (ISO/IEC 5230). Each release ships with Source SBoMs in CycloneDX 1.6 and SPDX 2.3, plus attestation.
elixir-lang.org
February 26, 2025 at 1:06 PM
🚀 Exciting news: Socket is now part of TC54! We're joining forces to help shape the future of SBOMs, CycloneDX, and PURL, making software supply chains more secure & transparent.

socket.dev/blog/socket-...

#SBOM #CycloneDX #PURL #cybersecurity
Socket Joins TC54 to Help Shape the Future of SBOMs, Cyclone...
Socket is joining TC54 to help develop standards for software supply chain security, contributing to the evolution of SBOMs, CycloneDX, and Package UR...
socket.dev
January 31, 2025 at 2:53 PM
Having to shut down your bug bounty program due to the sheer volume of AI flooding it with responses trying to cash out is just a really sad state of affairs github.com/CycloneDX/cy...
Remove Bug Bounty program by lfrancke · Pull Request #786 · CycloneDX/cyclonedx-rust-cargo
We received almost entirely AI slop reports that are irrelevant to our tool. It's a library and most reporters didn't even bother to read the rules or even look at what the intended purpose...
github.com
May 23, 2025 at 1:31 PM
Today, we're launching CycloneDX Assessors Studio (currently in alpha). Built for maturity tracking, compliance audits, and supply chain vendor trust. Turn compliance checklists into verifiable attestations.

#CycloneDX #OWASP #Compliance #GRC #OpenSource

assessors.studio
CycloneDX Assessors Studio
Operationalize CycloneDX Attestations. Perform structured assessments, gather verifiable evidence, and issue machine-readable attestations.
assessors.studio
April 14, 2026 at 12:42 PM
The Authoritative Guide to AI/ML-BOM from CycloneDX just dropped. Full transparency into your AI supply chain: security, compliance, data lineage, reproducibility. AI regulations are here. Be ready.

#AI #AIBOM #SBOM #OWASP #CycloneDX

cyclonedx.org/guides/
Guides and Resources | CycloneDX
Unlock valuable insights and practical guidance to help your organization maximize CycloneDX and reduce supply chain risk.
cyclonedx.org
March 3, 2026 at 8:16 PM
KoalaCon 2024 was a huge success. Thank you to all the speakers, including Olle E Johansson, Anthony Harrison, Niklas Düster, Viktor Petersson, and Piotr P. Karwasz. Couldn't attend. No worries, the recording is available on YouTube.

youtu.be/NStzYW4WnEE?...

#OWASP #SBOM #SoftwareTransparency
OWASP KoalaCon 2024
YouTube video by OWASP CycloneDX
youtu.be
December 2, 2024 at 11:29 PM
🍻 cargo-cyclonedx 🍻

Creates CycloneDX Software Bill of Materials (SBOM) from Rust (Cargo) projects

🔗 https://cyclonedx.org/

#homebrew #newpkg #macos #linux #formula
February 8, 2025 at 12:44 PM
No prob! I also tentatively start following "sbom-cyclonedx" classifier. Easy enough to change until 2.20 release but better set up something.
April 28, 2025 at 11:19 PM
Just finished writing a blog post about Creating SBOM with sbom-tool and CycloneDX on Azure DevOps.
#Azure #AzurePipelines #SBOM #sbomtool #CycloneDX dev.to/atahanceylan...
Creating SBOM with sbom-tool and CycloneDX on Azure DevOps
What is SBOM? [A software bill of materials (SBOM) declares the inventory of components used to...
dev.to
January 20, 2025 at 10:53 PM