Conversation

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

RDF was invented by Big WWW to make harder to understand, more complex formats

1
2
4

anyways what is the point of including vulnerability information in the SBOM? Outside of “Hey automated vuln scanners. we are not affected by this vuln”. this is basically immediately out of date when there is an actual vulnerability, and if you continue shipping the software at this point you are shipping known insecure code

1
0
1

i guess this is comparable to errata lists in hardware but

spinning up a new revision for some hardware is quite expensive

releasing a new software version is free

1
0
1

in general the SBOM formats seem to be a lot more than just providing a dependency tree with like unique package IDs and the role and license each dependency has

1
0
0

“Hey automated vuln scanners. we are not affected by this vuln”

from what i heard about vuln scanners this info could be entirely ignored too

0
0
0