EPISODE · Jan 8, 2024 · 31 MIN
Episode 410 - Package identifiers are really hard
from Open Source Security
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not. Show Notes OpenSSF CISA response purl CPE OmniBOR SWID
Embed this episode
Ready to play
Episode 410 - Package identifiers are really hard
0:00
31:52
1×
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
Frequently Asked Questions
How long is this episode of Open Source Security?
This episode is 31 minutes long.
When was this Open Source Security episode published?
This episode was published on January 8, 2024.
Can I download this Open Source Security episode?
Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!