Episode 410 - Package identifiers are really hard
Jan 08, 2024•32 min•Ep. 410
Episode description
Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.
Show NotesFor the best experience, listen in Metacast app for iOS or Android
