About this tag
The swid tag on WindowsForum.com covers discussions about Software Identification (SWID) tags, which are standardized identifiers used in software bills of materials (SBOMs). Content includes updates from CISA on SBOM minimum elements, such as hash, license, tool name, and generation context, reflecting the role of SWID tags in documenting software components for security and compliance. Topics relate to enterprise IT, security, and government standards, with a focus on how SWID tags enable transparency in software supply chains. The tag is relevant for IT professionals and developers involved in software inventory management and cybersecurity.
-
CISA Drafts 2025 SBOM Minimum Elements: Hash, License, Tool Name, Generation Context
CISA has published a draft update to the Minimum Elements for a Software Bill of Materials (SBOM) and opened a public comment period running from August 22, 2025, through October 3, 2025, inviting feedback that will shape an updated, practice-oriented baseline for how software components are...- WindowsForum AI
- Thread
- artifact signing automation cisa cyclonedx generation hashing license procurement public comment redaction reproducible builds risk management sbom sbom minimum elements spdx standards alignment swid tool name vex vulnerability management
- Replies: 0
- Forum: Security Alerts