<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>SBOMit = SBOM &#43; in-toto on SBOMit</title>
    <link>https://deploy-preview-18--sbomit.netlify.app/</link>
    <description>Recent content in SBOMit = SBOM &#43; in-toto on SBOMit</description>
    <generator>Hugo</generator>
    <language>en</language>
    <atom:link href="https://deploy-preview-18--sbomit.netlify.app/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title></title>
      <link>https://deploy-preview-18--sbomit.netlify.app/charter/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://deploy-preview-18--sbomit.netlify.app/charter/</guid>
      <description>&lt;h1 id=&#34;technical-charter-the-charter-for-sbomit-a-series-of-lf-projects-llc&#34;&gt;Technical Charter (the &amp;ldquo;Charter&amp;rdquo;) for SBOMit a Series of LF Projects, LLC&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;Adopted:&lt;/strong&gt; January 9th, 2024&lt;/p&gt;
&lt;p&gt;This Charter sets forth the responsibilities and procedures for technical
contribution to, and oversight of, the SBOMit open source project, which has
been established as SBOMit a Series of LF Projects, LLC (the “Project”). LF
Projects, LLC (“LF Projects”) is a Delaware series limited liability company.
All contributors (including committers, maintainers, and other technical
positions) and other participants in the Project (collectively, “Collaborators”)
must comply with the terms of this Charter.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Community</title>
      <link>https://deploy-preview-18--sbomit.netlify.app/community/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://deploy-preview-18--sbomit.netlify.app/community/</guid>
      <description>&lt;p&gt;&lt;strong&gt;SBOMit&lt;/strong&gt; is an open community project developed under the OpenSSF Security
Tooling Working Group. We welcome contributors, users, and anyone interested
in improving the trustworthiness of software supply chains.&lt;/p&gt;
&lt;h2 id=&#34;meetings&#34;&gt;Meetings&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Schedule: Every Wednesday at 11:00 AM US Eastern Time
&lt;a href=&#34;https://nyu.zoom.us/j/91097299041&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Zoom Meeting Link&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://docs.google.com/document/d/1-nHXMqvWNzgOxAq08O8Wu2BTHz0U60yBoAklrJAMaRc/edit?usp=sharing&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Meeting notes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;meet-the-maintainers&#34;&gt;Meet the Maintainers!&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/SBOMit/specification/blob/main/MAINTAINERS.md&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Maintainers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;join-our-slack&#34;&gt;Join our Slack!&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Click the Slack Icon at the bottom of the page&lt;/li&gt;
&lt;li&gt;Add these two channels: &lt;code&gt;#sbomit&lt;/code&gt; and &lt;code&gt;#sig-sbom-everywhere&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Documentation</title>
      <link>https://deploy-preview-18--sbomit.netlify.app/documentation/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://deploy-preview-18--sbomit.netlify.app/documentation/</guid>
      <description>&lt;p&gt;Documentation for the SBOMit specification, tooling, and reference
implementations will live here.&lt;/p&gt;
&lt;p&gt;In the meantime, the authoritative source is the
&lt;a href=&#34;https://github.com/SBOMit/specification&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;SBOMit specification repository&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;getting-started&#34;&gt;Getting started&lt;/h2&gt;
&lt;p&gt;Content coming soon.&lt;/p&gt;
&lt;h2 id=&#34;specification&#34;&gt;Specification&lt;/h2&gt;
&lt;p&gt;Content coming soon.&lt;/p&gt;
&lt;h2 id=&#34;tooling&#34;&gt;Tooling&lt;/h2&gt;
&lt;p&gt;Content coming soon.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FAQ</title>
      <link>https://deploy-preview-18--sbomit.netlify.app/faq/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://deploy-preview-18--sbomit.netlify.app/faq/</guid>
      <description>&lt;h2 id=&#34;why-do-we-need-accurate-sboms&#34;&gt;Why do we need Accurate SBOMs?&lt;/h2&gt;
&lt;p&gt;When &lt;a href=&#34;https://nvd.nist.gov/vuln/detail/CVE-2021-44228&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Log4Shell (CVE-2021-44228)&lt;/a&gt; hit in December
2021, the number of exposed systems exploded from 40,000 to 830,000 in under 72 hours. Log4j was
buried as a transitive dependency, and most teams had no way to know whether they were running it and where. Incident response turned into an organization-wide mining project.&lt;/p&gt;
&lt;figure&gt;
    &lt;img loading=&#34;lazy&#34; src=&#34;https://deploy-preview-18--sbomit.netlify.app/images/log4shell-growth.png&#34;
         alt=&#34;Log4Shell affected systems grew from 40,000 to 830,000 in 72 hours&#34;/&gt; &lt;figcaption&gt;
            &lt;p&gt;Affected systems in the 72 hours following the Log4Shell outbreak.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting Started</title>
      <link>https://deploy-preview-18--sbomit.netlify.app/getting-started/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://deploy-preview-18--sbomit.netlify.app/getting-started/</guid>
      <description>&lt;p&gt;This guide walks through setting up &lt;a href=&#34;https://github.com/in-toto/witness&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Witness&lt;/a&gt; to instrument
your build, then using SBOMit to generate an enriched SBOM from the resulting attestation.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;prerequisites&#34;&gt;Prerequisites&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://go.dev/doc/install&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Go&lt;/a&gt; 1.19 or later&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.openssl.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;openssl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://jqlang.github.io/jq/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;jq&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.gnu.org/software/coreutils/manual/html_node/base64-invocation.html&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;base64&lt;/a&gt; (part of GNU coreutils)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&#34;part-1-witness&#34;&gt;Part 1: Witness&lt;/h2&gt;
&lt;p&gt;Witness wraps your build process and records signed attestations, a cryptographic audit trail.&lt;/p&gt;
&lt;h3 id=&#34;1-install-witness&#34;&gt;1. Install Witness&lt;/h3&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;bash &amp;lt;&lt;span class=&#34;o&#34;&gt;(&lt;/span&gt;curl -s https://raw.githubusercontent.com/in-toto/witness/main/install-witness.sh&lt;span class=&#34;o&#34;&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Or download a binary from the &lt;a href=&#34;https://github.com/in-toto/witness/releases&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Witness releases page&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
