EPISODE · Jan 8, 2024 · 31 MIN
Episode 410 - Package identifiers are really hard
from Open Source Security
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not. Show Notes OpenSSF CISA response purl CPE OmniBOR SWID
NOW PLAYING
Episode 410 - Package identifiers are really hard
No transcript for this episode yet
Similar Episodes
Feb 18, 2026 ·26m
Jul 24, 2025 ·73m
Nov 3, 2024 ·52m
Sep 26, 2024 ·67m
Sep 16, 2024 ·139m
Aug 14, 2024 ·76m