Piotr P. Karwasz

@piotr.karwasz.org

Java & Open Source expert | Apache Software Foundation member | VP Logging Services & Ecma Relations | Father of three wonderful daughters

I just released version `0.2.0` of SBOM Enforcer Maven Plugin. This plugin does for (CycloneDX) SBOMs what the Maven Enforcer Plugin does for POM files. Although the current number of built-in rules is small, the plugin is extensible and other built-in rules are on their way!

Release 0.2.0 · sbom-enforcer/sbom-enforcer

What's Changed fix: possible NPEs in handling Maven and CycloneDX models by @ppkarwasz in #42 fix: handle modules with packaging pom by @ppkarwasz in #43 fix: set global workflow permissions to em...

github.com

Unfortunately AI is not limited to e-mails. We are receiving an increasing number of AI-generated issue reports and we would need an AI to close those reports automatically… 😀

Post nicht verfügbar.

After another round of (automatically tested and merged) Dependabot upgrades, my thoughts return to the eternal question: How to inform `libfoo` users that `libfoo` only requires `libbar` 1.0.0 (or later), but I have successfully tested it with `libbar` version 1.23.45?

Had a really good meeting with the #SCITT community today. I keep using their open meetings to get input for the #OWASP Transparency Exchange API - how to add transparency logs and monitor for abuse, changes and manipulation. Software transparency is a lot about trust. #SBOM #TEA