SBOM
6 postsDiscover how Docker Scout integrates with secure container repositories to ensure vulnerability-free and compliant images in highly secure environments.
The Docker team introduces Docker Scout health scores to help quickly evaluate image health and simplify software security for developers.
We share highlights from a recent webinar: “Docker Scout: Live Demo, Insights, and Q&A," which is also now available on-demand.
A secure software supply chain represents another facet of Microsoft’s built-in security to enhance and maintain trust in our products. It’s a continuation of the journey we embarked upon since the launch of Security Development Lifecycle (SDL) in 2004 and represents our commitment to continually enhance Microsoft’s foundational security. The post The Journey to Secure the Software Supply Chain at Microsoft appeared first on Engineering@Microsoft.
We are excited and proud to open source our software bill of materials (SBOM) generation tool. A key requirement of the Executive Order on Improving the Nation’s Cybersecurity, SBOMs are lists of ingredients that make up software components, providing software transparency so organizations have insight into their supply chain dependencies. The post Microsoft open sources its software bill of materials (SBOM) generation tool appeared first on Engineering@Microsoft.
In this post, Adrian Diglio walks us through how Microsoft is planning to generate SBOMs not just to meet the U.S. Presidential Executive Order on Improving the Nation's Cybersecurity, but for all software that Microsoft produces. The post Generating Software Bills of Materials (SBOMs) with SPDX at Microsoft appeared first on Engineering@Microsoft.