<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>SBOMit = SBOM &#43; in-toto on SBOMit</title>
    <link>https://deploy-preview-17--sbomit.netlify.app/</link>
    <description>Recent content in SBOMit = SBOM &#43; in-toto on SBOMit</description>
    <generator>Hugo -- gohugo.io</generator><atom:link href="https://deploy-preview-17--sbomit.netlify.app/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title></title>
      <link>https://deploy-preview-17--sbomit.netlify.app/charter/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://deploy-preview-17--sbomit.netlify.app/charter/</guid>
      <description>Technical Charter (the &amp;ldquo;Charter&amp;rdquo;) for SBOMit a Series of LF Projects, LLC Adopted: January 9th, 2024
This Charter sets forth the responsibilities and procedures for technical contribution to, and oversight of, the SBOMit open source project, which has been established as SBOMit a Series of LF Projects, LLC (the “Project”). LF Projects, LLC (“LF Projects”) is a Delaware series limited liability company. All contributors (including committers, maintainers, and other technical positions) and other participants in the Project (collectively, “Collaborators”) must comply with the terms of this Charter.</description>
    </item>
    
    <item>
      <title>Community</title>
      <link>https://deploy-preview-17--sbomit.netlify.app/community/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://deploy-preview-17--sbomit.netlify.app/community/</guid>
      <description>SBOMit is an open community project developed under the OpenSSF Security Tooling Working Group. We welcome contributors, users, and anyone interested in improving the trustworthiness of software supply chains.
Meetings Schedule: Every Wednesday at 11:00 AM US Eastern Time Zoom Meeting Link Meeting notes Meet the Maintainers! Maintainers Join our Slack! Click the Slack Icon at the bottom of the page Add these two channels: #sbomit and #sig-sbom-everywhere </description>
    </item>
    
    <item>
      <title>Documentation</title>
      <link>https://deploy-preview-17--sbomit.netlify.app/documentation/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://deploy-preview-17--sbomit.netlify.app/documentation/</guid>
      <description>Documentation for the SBOMit specification, tooling, and reference implementations will live here.
In the meantime, the authoritative source is the SBOMit specification repository.
Getting started Content coming soon.
Specification Content coming soon.
Tooling Content coming soon.</description>
    </item>
    
    <item>
      <title>FAQ</title>
      <link>https://deploy-preview-17--sbomit.netlify.app/faq/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://deploy-preview-17--sbomit.netlify.app/faq/</guid>
      <description>Why do we need Accurate SBOMs? When Log4Shell (CVE-2021-44228) hit in December 2021, the number of exposed systems exploded from 40,000 to 830,000 in under 72 hours. Log4j was buried as a transitive dependency, and most teams had no way to know whether they were running it and where. Incident response turned into an organization-wide mining project.
Affected systems in the 72 hours following the Log4Shell outbreak.
Log4Shell made the case for SBOMs clearly: if you had a complete, accurate inventory of every component in your software, you could answer &amp;ldquo;are we affected?</description>
    </item>
    
    <item>
      <title>Getting Started</title>
      <link>https://deploy-preview-17--sbomit.netlify.app/getting-started/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://deploy-preview-17--sbomit.netlify.app/getting-started/</guid>
      <description>This guide walks through setting up Witness to instrument your build, then using SBOMit to generate an enriched SBOM from the resulting attestation.
Prerequisites Go 1.19 or later openssl jq base64 (part of GNU coreutils) Part 1: Witness Witness wraps your build process and records signed attestations, a cryptographic audit trail.
1. Install Witness bash &amp;lt;(curl -s https://raw.githubusercontent.com/in-toto/witness/main/install-witness.sh) Or download a binary from the Witness releases page.
2. Create a signing keypair Witness signs each attestation with a private key.</description>
    </item>
    
  </channel>
</rss>
