Skip to content

refresh the CBOM blog post to match shipped capability #99

Description

@aurangzaib048

content/posts/2024-04-10-future-proofing-cybersecurity-with-the-cryptography-bill-of-materials-cbom.md undersells the product (implies crypto data only rides inside existing SBOM documents; standalone CBOM artifacts are supported) and presents unshipped features in present tense (certificate expiry visibility, migration planning). The post was content-refreshed while keeping date: 2024-04-10, so the front-matter date misleads.

Changes:

  • Update the product paragraph to name shipped capabilities and link the feature page
  • Add a CycloneDX 1.6/1.7 + ECMA-424 note, and EO 14412's CBOM minimum-elements directive (guidance due ~March 2027)
  • Align promise tense with shipped reality; keep NIST IR 8547 cited as draft; do not claim the CRA requires a CBOM
  • Adopt a lastmod front-matter convention for refreshed posts

Related: the TEA FAQ lists CBOM among TEA-shareable artifact types, which the product does not do yet (tracked in sbomify/sbomify#1167) — caveat or hold that line until it ships.

Acceptance:

  • No claim on the page is ahead of the product
  • Regulatory dates match the verified set

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions