Beefy Boxes and Bandwidth Generously Provided by pair Networks
XP is just a number
 
PerlMonks  

Re: Software Bill of Materials (SBOM) in Perl and CPAN

by LanX (Saint)
on Sep 03, 2024 at 11:19 UTC ( [id://11161541]=note: print w/replies, xml ) Need Help??


in reply to Software Bill of Materials (SBOM) in Perl and CPAN

General question, general answer:

  • Metacpan can show you the dependency tree for every module.
  • Parsing for XS modules should reveal associated C libraries too.
  • The METAs and READMEs of a distribution should list third party dependencies.
  • The cpantesters matrix should not only prove all of this, but also reveal OS version problems

I didn't dig deep into the WP article and didn't listen to Salve's talk (again²), but this should produce a good reliably founded document for your SBOM.

I'd be interested to know on which grounds this would not meet your army's requirements.¹

After all these documents are mostly written by bureaucrats and BA bachelors who measure software quality by the size and design of accompanying PDFs

Cheers Rolf
(addicted to the Perl Programming Language :)
see Wikisyntax for the Monastery

Update

¹) actually the article says

  • The directive gives the Army 90 days to develop implementation guidance for SBOMs, including sample language for requiring them in contracts

... so it's still vaporware 🤷🏻‍♂️

I wouldn't be surprised if someone charged with "implementing guidance" started googling now and stumbled over this post 🤔

²) I was in the audience, but don't remember much.

  • Comment on Re: Software Bill of Materials (SBOM) in Perl and CPAN

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://11161541]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others admiring the Monastery: (4)
As of 2026-03-05 23:28 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found

    Notices?
    hippoepoptai's answer Re: how do I set a cookie and redirect was blessed by hippo!
    erzuuliAnonymous Monks are no longer allowed to use Super Search, due to an excessive use of this resource by robots.