From 7fe17a3c201b00d9cb5f30d457ca864d12a71050 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 22 Jul 2025 05:19:38 +0000 Subject: [PATCH 1/2] Bump form-data from 4.0.2 to 4.0.4 in /SBOM-Catalog Bumps [form-data](https://github.com/form-data/form-data) from 4.0.2 to 4.0.4. - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](https://github.com/form-data/form-data/compare/v4.0.2...v4.0.4) --- updated-dependencies: - dependency-name: form-data dependency-version: 4.0.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] Signed-off-by: Vinny Barton --- SBOM-Catalog/package-lock.json | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/SBOM-Catalog/package-lock.json b/SBOM-Catalog/package-lock.json index ede2562..a0ce2ec 100644 --- a/SBOM-Catalog/package-lock.json +++ b/SBOM-Catalog/package-lock.json @@ -3296,14 +3296,15 @@ } }, "node_modules/form-data": { - "version": "4.0.2", - "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.2.tgz", - "integrity": "sha512-hGfm/slu0ZabnNt4oaRZ6uREyfCj6P4fT/n6A1rGV+Z0VdGXjfOhVUpkn6qVQONHGIFwmveGXyDs75+nr6FM8w==", + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.4.tgz", + "integrity": "sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==", "license": "MIT", "dependencies": { "asynckit": "^0.4.0", "combined-stream": "^1.0.8", "es-set-tostringtag": "^2.1.0", + "hasown": "^2.0.2", "mime-types": "^2.1.12" }, "engines": { From 8db2187b661caf438ac3acccca163f60fb93089c Mon Sep 17 00:00:00 2001 From: Vinny Barton Date: Tue, 9 Sep 2025 06:48:41 -0400 Subject: [PATCH 2/2] adding tool SecureSBOM and logo Signed-off-by: Vinny Barton --- SBOM-Catalog/public/data.yaml | 64 +++++++++++++++++++++++ SBOM-Catalog/public/logos/SecureSBOM.png | Bin 0 -> 1177 bytes 2 files changed, 64 insertions(+) create mode 100644 SBOM-Catalog/public/logos/SecureSBOM.png diff --git a/SBOM-Catalog/public/data.yaml b/SBOM-Catalog/public/data.yaml index 04b4aeb..39a6ad8 100644 --- a/SBOM-Catalog/public/data.yaml +++ b/SBOM-Catalog/public/data.yaml @@ -7179,3 +7179,67 @@ - Analyze - Deployment - Container +- Abilities: + - Validate + - Sign + Languages: + - C + - "C++" + - Dotnet + - Erlang + - Elixir + - Fortran + - Go + - Haskell + - Java + - Javascript + - Nim + - "Objective-C" + - Perl + - PHP + - Python + - R + - Ruby + - Rust + - Scala + - Swift + - Typescript + License: Proprietary + Link: https://shiftleftcyber.io/securesbom + Name: SecureSBOM + Publisher: ShiftLeftCyber + Source: Human written + Standards: + - SPDX + - CycloneDX + Summary: 'SecureSBOM is ShiftLeftCybers enterprise-grade cryptographic API for software supply chain security. It + provides scalable signing and verification capabilities for Software Bills of Materials (SBOMs), enabling + organizations to establish trust and integrity in their software supply chains through cryptographic authentication. + + SecureSBOM is available as a cloud-based API service and accessible at https://shiftleftcyber.io/securesbom/. + + Capabilities: + + - Cryptographic signing of SBOMs using industry-standard algorithms (RSA, ECDSA) with secure cloud-based key management + + - Signature verification to validate SBOM authenticity and detect tampering during transit or storage + + - Support for CycloneDX 1.6 standard signature format with SPDX detached signature support (coming soon) + + - RESTful API architecture enabling seamless integration with CI/CD pipelines, DevSecOps workflows, and existing toolchains + + - Enterprise-scale performance with configurable retry logic, timeout handling, and batch processing capabilities + + - Secure key lifecycle management including generation, rotation, and access control through API-based administration + + - Integration support for popular CI systems including GitHub Actions, Jenkins, GitLab CI, and Azure DevOps for automated SBOM signing workflows + + - Audit trail and compliance reporting for regulatory requirements and supply chain governance + Types: + - Design + - Source + - Build + - Analyze + - Deployment + - Runtime + - Container diff --git a/SBOM-Catalog/public/logos/SecureSBOM.png b/SBOM-Catalog/public/logos/SecureSBOM.png new file mode 100644 index 0000000000000000000000000000000000000000..ec90071eae055d0675c915ad306ba37d9dc4a480 GIT binary patch literal 1177 zcmeAS@N?(olHy`uVBq!ia0vp^$AEYZ3p0?sbn6^QfF<40*O7r?V?XzwL{=bQA=x9y zmw};5je((|g@NH0P^jSr14F3+1H-EX1_rAc3=HB0b9M#V040P1d_r7-w1H;1zE+u@ zRvD1||NsBvB|Cts7+6Yz{DK+GiuU-dmd*z98I!!-U08qQzdR1)aOS(Y6$8c0f$Rqi z)-jdMAi)BUNT8seG6*wPEVVBK3bL1Y`ns~eEaktaqI2u+F6Sgc#f^DVn{#5I7g4Y;MqflzaRdk-@3WcV}XiW=iS)bO5=wcg_owj*neztqm27{?pt@) ze5$eQDd2fE@!eN1|5>HnxAM3n7i@akpf0H+!zPyU=H;e&vp#GIjJCU-w)J@r-^b|g z%mYGJkLFqM{!Fh@OH2D^_oegn9(#UYaYkY9r{620-*yJybIJYr zywU8_oXv8=m6J;JmL;Cv>|f`0F?1?hr)^JEjYOcD^^*UJ6?rS#XKj=^o^E6NDpR9B z|IeBNS#Mk3nHd(UGX8ebyc^Z_Ms0JKJQdJpG-V-As>WkeiD&kSH`ER8^e?|Z)$rZ< z9rpjrtBsavp5L!DEy;)D$@h6YkLRu8z8ZDn!+!R5S;?{`)26aKK6_X2M!d$y-EBs( z^A5cDo}RFBQc4Vv^)3CudyXR#FSw;0j|IFvx8U9~4#N}nOH(DTWUC7v>;3mVHqSmB zYPB=m6&}W?vUxc~uRH5_ulm+JY4&gNs~Z9)tvZ^>w|L324r?Br6E}?4q}^EY|C^M) zQ_$9|o)FRNcLI$*o3CC|HenL4smy!3eH#h%_djZs~2W`LjXD<$Uz+sY;i zUgap3u>Jg~K{4R&!X3Amy3D>2osz z9?hAWxqR)*#Z~1m{?4CtWu|=4N4s5r-v})=d$s>BkC=U=?cvL7(_9><&FOs1x5V9M z&gR-BOU`Lb+SH>{V6#NxxnrbUP*8e&sMgijFU=<}Vq9|c-%bHwu2L;=jVMV;EJ?LW zE=mPb3`Pb