@allanfriedman@infosec.exchange
Post #3653218
2026-07-07 16:42 UTC
An “omniBOM”? I had a blast recently chatting with my old friend @joshbressers@infosec.exchange about the proliferation of BOMs over the past few years, and how we need to think about them. I believe that they will eventually merge into one holistic “omniBOM.” However, we need to learn the lessons from the SBOM movement. Before we get to a completist solution, we’ll need to consider each independently to understand the technical- and business-specific use cases to build core data models that reflect utility, availability, and consistency. This, in turn, will catalyze ecosystems of tooling, automation, meaningful data use, and—yes—requirements and regs.
Available wherever you lovingly hand-pick your artisinal audio content.
https://opensourcesecurity.io/2026/2026-06-allan-omnibom/
Replies (1)
-
@christopherkunz@chaos.social 2026-07-07 20:33
@allanfriedman@infosec.exchange @joshbressers@infosec.exchange I have to do this, sorry. https://xkcd.com/927/