cyclonedx

1 article
sort: new top best
clear filter
0 4/10

Analysis of 15,000+ top PyPI packages reveals only 1.58% ship with SBOMs (238 packages), all CycloneDX format with zero SPDX adoption. The study, enabled by PyPI-TEA (a PEP 770 bridge to the Transparency Exchange API), identified 37 invalid SBOMs all tracing to a single cargo-cyclonedx bug and highlights the urgent need for improved SBOM adoption in the Python ecosystem.

PyPI PEP 770 CycloneDX SPDX TEA Transparency Exchange API PyPI-TEA sbomify-action sbomify cargo-cyclonedx Viktor Petersson Seth Larson
sbomify.com · mvip · 16 hours ago · details · hn