As part of this training we will use OWASP Dependency Track.
As you can see in the picture this tools uses CycloneDX as exchange format.
It is possible to automatically generate this format from all commonly used software packaging systems or programming languages like:
For the training labs we will just use the most simplified way to install OWASP Dependency Track.
Just follow the instructions on Dependency Track Quickstart.
- Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (NIST SP 800-161r1)
- Software Supply Chain Security (Synopsys)
- Threat Landscape for Supply Chain Attacks (European Union Agency For Cybersecurity)
- What is software supply chain security and why does it matter? (GitHub)
- Supply Chain Security: Mitigating the Supply Chain Threat (Aqua Security)
- What is an SBOM? (Aqua Security)
- OWASP Software Component Verification Standard (SCVS)
