SPDX (Software Package Data Exchange)
The official website for the SPDX standard. Visit website
This page contains a curated list of external resources to help you on your SBOM journey.
SPDX (Software Package Data Exchange)
The official website for the SPDX standard. Visit website
CycloneDX
The official website for the CycloneDX standard. Visit website
NTIA: Software Bill of Materials
The website of the US National Telecommunications and Information Administration (NTIA) on SBOMs. Visit website
CISA: Software Bill of Materials
The website of the US Cybersecurity and Infrastructure Security Agency (CISA) on SBOMs. Visit website
FIRST: SBOM and CSAF/VEX Operational Framework
A comprehensive guide by FIRST on implementing SBOM and CSAF/VEX practices, covering the relationship between static SBOMs and dynamic vulnerability data. Download PDF
CISA: SBOM Sharing Primer
CISA’s guide on SBOM sharing roles (Producer, Distributor, Consumer), sharing mechanisms, and best practices for SBOM distribution. Download PDF
CISA: Types of SBOMs
Defines the six types of SBOMs (Design, Source, Build, Analyzed, Deployed, Runtime) and their appropriate use across the software lifecycle. Download PDF
CSAF: Common Security Advisory Framework
The OASIS standard for machine-readable security advisories, including VEX profiles for communicating vulnerability exploitability status. View specification
OWASP SCVS
The OWASP Software Component Verification Standard (SCVS) is a community-driven effort to establish a framework for verifying the security of software components. Visit website
SLSA
Supply-chain Levels for Software Artifacts (SLSA) is a security framework, a check-list of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure. Visit website
OpenChain Project
The OpenChain Project identifies key requirements of a quality open source compliance program to build trust in the open source supply chain. Visit website