SBOM & build provenance
Security & software supply chain
SBOM & build provenance
An SBOM lists software components in a format such as SPDX or CycloneDX. Build provenance records how an artifact was produced. Keep both tied to the released output.
Resources
Links marked “Amazon affiliate link” open an Amazon product page. As an Amazon Associate I earn from qualifying purchases. About affiliate links
SLSAReference · OpenSSF · opens in a new tabSoftware Supply Chain SecurityBook · Cassie Crossley · Amazon affiliate link, opens Amazon in a new tabCycloneDXReference · OWASP · opens in a new tabSPDXReference · The Linux Foundation · opens in a new tabDevOps guides (in French)Blog · Stéphane Robert · opens in a new tabOWASP Cheat Sheet SeriesReference · OWASP · opens in a new tabAlice and Bob Learn Application SecurityBook · Tanya Janca · Amazon affiliate link, opens Amazon in a new tabSecuring DevOpsBook · Julien Vehent · Amazon affiliate link, opens Amazon in a new tabDeveloping Secure Software (LFD121)Course · OpenSSF, The Linux Foundation · opens in a new tab