content/posts/2024-04-10-future-proofing-cybersecurity-with-the-cryptography-bill-of-materials-cbom.md undersells the product (implies crypto data only rides inside existing SBOM documents; standalone CBOM artifacts are supported) and presents unshipped features in present tense (certificate expiry visibility, migration planning). The post was content-refreshed while keeping date: 2024-04-10, so the front-matter date misleads.
Changes:
- Update the product paragraph to name shipped capabilities and link the feature page
- Add a CycloneDX 1.6/1.7 + ECMA-424 note, and EO 14412's CBOM minimum-elements directive (guidance due ~March 2027)
- Align promise tense with shipped reality; keep NIST IR 8547 cited as draft; do not claim the CRA requires a CBOM
- Adopt a
lastmod front-matter convention for refreshed posts
Related: the TEA FAQ lists CBOM among TEA-shareable artifact types, which the product does not do yet (tracked in sbomify/sbomify#1167) — caveat or hold that line until it ships.
Acceptance:
content/posts/2024-04-10-future-proofing-cybersecurity-with-the-cryptography-bill-of-materials-cbom.mdundersells the product (implies crypto data only rides inside existing SBOM documents; standalone CBOM artifacts are supported) and presents unshipped features in present tense (certificate expiry visibility, migration planning). The post was content-refreshed while keepingdate: 2024-04-10, so the front-matter date misleads.Changes:
lastmodfront-matter convention for refreshed postsRelated: the TEA FAQ lists CBOM among TEA-shareable artifact types, which the product does not do yet (tracked in sbomify/sbomify#1167) — caveat or hold that line until it ships.
Acceptance: