4 ms·
I'm not suggesting scrounging. I'm suggesting that the guys who've repeatedly proven themselves technically competent around security at scale might have a cou
by yarg 3y ago
I'm not suggesting scrounging.
I'm suggesting that the guys who've repeatedly proven themselves technically competent around security at scale might have a couple of useful ideas regarding how the industry might go about crawling its way out of this little security clusterfuck.
And perhaps even stop treating something as simple as a BOM as an enterprise feature, given that the overhead on such things is damned near zilch and the security implications are staggering.
https://www.cisa.gov/sbom https://www.cisa.gov/sbom