# spdx

Published articles for spdx.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Super SBOMs: See exactly what's inside

DevFeed: [Super SBOMs: See exactly what's inside](<https://devfeed.tech/articles/super-sboms-see-exactly-what-s-inside-13245.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/super-sboms-see-exactly-whats-inside>)

Published: 2026-01-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [spdx](<https://devfeed.tech/topics/spdx.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard Containers now provide richer SBOMs with binary-level details about embedded libraries and dependencies, along with CycloneDX support in addition to SPDX. The added visibility helps teams trace vulnerabilities and assess license compliance.

### Source excerpt

Chainguard Containers ship richer SBOMs with binary-level library details plus new CycloneDX support, making CVE impact and compliance tracing fast and clear.

## Software Bill of Materials

DevFeed: [Software Bill of Materials](<https://devfeed.tech/articles/software-bill-of-materials-13961.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/software-bill-of-materials/>)

Author: John Lee

Published: 2023-11-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces software bills of materials (SBOMs), explains their structure and formats such as SPDX and CycloneDX, and presents Espressif's ESP-IDF-SBOM tool. The tool generates SPDX SBOMs for ESP-IDF-based applications and checks them against the National Vulnerability Database for known vulnerabilities.

### Source excerpt

Overview# The "software bill of materials" (SBOM) has emerged as a key building block in software security and software supply chain risk management. An SBOM is a comprehensive list of all the software components, dependencies, and metadata associated with an application. Espressif believes that this information is a key step towards ensuring the security of the connected devices. And as such, we have now enabled easy to use tools and solutions to track and analyze this information.

## Working with government and industry to put open source security tooling into practice

DevFeed: [Working with government and industry to put open source security tooling into practice](<https://devfeed.tech/articles/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice-13342.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice>)

Published: 2023-09-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [bombshell](<https://devfeed.tech/tags/bombshell.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard describes two open-source SBOM tools developed with the U.S. Department of Homeland Security and other startups: protobom, which translates SBOM data between formats, and bomshell, which combines and composes SBOMs. The initiative aims to improve software supply chain security and visibility.

### Source excerpt

Pioneering SBOM tools with government and industry allies, Chainguard advances open source security measures.

## How Snyk can help secure supply chains per "A Guide to Implementing the Software Bill of Materials (SBOM) for Software Management"' by Japan's METI

DevFeed: [How Snyk can help secure supply chains per "A Guide to Implementing the Software Bill of Materials (SBOM) for Software Management"' by Japan's METI](<https://devfeed.tech/articles/how-snyk-can-help-secure-supply-chains-per-a-guide-to-implementing-the-software-bill-of-materials-sbom-for-software-management-by-japan-s-meti-7989.md>)

Original publisher: [Read original article](<https://snyk.io/blog/japan-meti-guide-to-sbom-for-software-management/>)

Author: Hiroko Nakano

Published: 2023-08-01T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [asia-pacific-japan](<https://devfeed.tech/tags/asia-pacific-japan.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [japan](<https://devfeed.tech/tags/japan.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains Japan's METI guidance for implementing Software Bill of Materials (SBOM) practices and describes how Snyk can help organizations create and scan SBOMs for vulnerabilities. It outlines the guide's implementation phases and discusses software supply-chain security, vulnerability management, and development productivity.

### Source excerpt

Snyk provides tools to create and scan SBOMs for vulnerabilities, helping organizations meet the requirements laid out by the METI Guide. This blog explores how Snyk can help to comply with the METI's guidance.

## Can Protobom end the SBOM format wars?

DevFeed: [Can Protobom end the SBOM format wars?](<https://devfeed.tech/articles/can-protobom-end-the-sbom-format-wars-12916.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-protobom-end-the-sbom-format-wars>)

Published: 2023-07-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Library](<https://devfeed.tech/topics/library.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [cisa](<https://devfeed.tech/tags/cisa.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [library](<https://devfeed.tech/tags/library.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>)

### AI overview

The article presents Protobom as an open source library designed to reduce the importance of choosing among SBOM formats. It provides a format-neutral representation of SBOM package and file data and translates that data between popular formats, allowing teams to focus more on software supply chain security.

### Source excerpt

Probe the SBOM format wars: Can ProtoBOM herald a new era of consensus? Chainguard weighs in.

## Chainguard to accelerate VEX adoption through OpenVEX specification

DevFeed: [Chainguard to accelerate VEX adoption through OpenVEX specification](<https://devfeed.tech/articles/chainguard-to-accelerate-vex-adoption-through-openvex-specification-12985.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-to-accelerate-vex-adoption-through-openvex-specification>)

Published: 2023-01-31T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [openvex](<https://devfeed.tech/topics/openvex.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [google](<https://devfeed.tech/tags/google.md>), [images](<https://devfeed.tech/tags/images.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom-vex](<https://devfeed.tech/tags/sbom-vex.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-tool](<https://devfeed.tech/tags/vulnerability-tool.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces the OpenVEX specification and reference toolchain, developed with industry and CISA VEX Working Group collaboration. OpenVEX helps software producers describe vulnerability exploitability and enables consumers to filter false positives, complementing SBOMs.

### Source excerpt

VEX needs the industry to come together to build formats that integrate into existing practices. OpenVEX enables organizations to put VEX into practice.

## Gradle dependency license validation

DevFeed: [Gradle dependency license validation](<https://devfeed.tech/articles/gradle-dependency-license-validation-20887.md>)

Original publisher: [Read original article](<https://code.cash.app/gradle-dependency-license-validation>)

Author: Jake Wharton

Published: 2021-06-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Jake Wharton](<https://devfeed.tech/sources/jake-wharton.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [spdx](<https://devfeed.tech/topics/spdx.md>), [Android](<https://devfeed.tech/topics/android.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [dependencies](<https://devfeed.tech/tags/dependencies.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [gradle-plugin](<https://devfeed.tech/tags/gradle-plugin.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software-license](<https://devfeed.tech/tags/software-license.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

This post explains how Cash App automated dependency license discovery and validation for its Android app using a new Gradle plugin called Licensee. The plugin normalizes license data to SPDX identifiers, supports allow-list validation that can fail builds for disallowed licenses, and serializes the results as JSON for use in the app's UI. It is intended to work with any Gradle-based project.

### Source excerpt

This post was published externally on Cash App Code Blog. Read it at https://code.cash.app/gradle-dependency-license-validation.

## Gradle Plugin Portal Approval Policy Update

DevFeed: [Gradle Plugin Portal Approval Policy Update](<https://devfeed.tech/articles/gradle-plugin-portal-approval-policy-update-24672.md>)

Original publisher: [Read original article](<https://blog.gradle.org/new-plugin-portal-acceptance-criteria>)

Author: Eric Wendelin

Published: 2018-10-18T04:00:00Z

Content type: release

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [github](<https://devfeed.tech/tags/github.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [issue](<https://devfeed.tech/tags/issue.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [plugins](<https://devfeed.tech/tags/plugins.md>), [policy](<https://devfeed.tech/tags/policy.md>), [repo](<https://devfeed.tech/tags/repo.md>), [security](<https://devfeed.tech/tags/security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Gradle is updating its approval policy for new plugins submitted to the Gradle Plugin Portal. The policy introduces validation of plugin descriptions, project URLs, group IDs, and artifact IDs, while prioritizing plugins with valid open-source repositories and properly applied SPDX-compatible licenses.

### Source excerpt

Gradle is updating the plugin approval policy for plugins submitted to the Gradle Plugin Portal, effective today, to begin adding stronger security safeguards for plugin consumers. First off, this does not affect plugins already on the plugin portal, just new plugins. Gradle builds that use plugins will not be affected in any way. Portal acceptance criteria in a nutshell Gradle will check the following for new plugins submitted to plugins.gradle.org: Description and project URL are valid and not misleading The group ID and artifact ID are valid and not misleading In addition to these changes, plugins with a valid open-source repo URL will be prioritized over other plugins for approval. Those that apply a SPDX-compatible license properly, even more so. If your plugin doesn't meet these requirements, we'll let you know as soon as possible and give you a chance to re-submit when it does. If your plugin cannot comply, please publish it to an alternative repository and use the pluginManagement {} DSL to configure where your plugins {} are resolved from. What happens to plugins that don't adhere to this criteria These checks do not yet apply for subsequent versions of a given plugin, and aren't yet going to be retroactively enforced. In the longer term, we will begin showing warnings on the plugin portal for plugins that don't adhere to this policy, and may introduce additional automated checks to give plugin consumers information about plugins they're viewing. If you have questions or concerns, we encourage you to discuss in the plugin-portal category on the Gradle forum. For any support requests, please open a GitHub issue.