Author: OWASP Foundation - Bewertung: 0x - Views:0
The CycloneDX standard continues to evolve to meet the increasing demands of software transparency, AI accountability, and supply chain security. Version 1.7 introduces targeted improvements including improvements for cryptographic assets, and added support for patents and TLP. But 2.0 is a major architectural shift: a modular, model-driven approach designed to increase reuse, expressiveness, and long-term maintainability.
This session will walk through the new capabilities introduced in CycloneDX 1.7 and preview the roadmap to 2.0. We'll discuss practical benefits for tool developers and adopters, explain how the new model structure works, and offer guidance for preparing for the transition. Whether you're building SBOM tooling, managing compliance, or contributing to the standard, this talk will equip you with the latest and next directions for CycloneDX.
Steve Springett
ServiceNow
Creator of OWASP Dependency-Track and Chair of CycloneDX SBOM Core Working Group and Ecma TC54
Chicago
about.me/stevespringett
https://www.linkedin.com/in/stevespringett/
Managed by the OWASP® Foundation
https://owasp.org/
SOCIAL SHARE CARD GENERATOR