by hubie on (#6H93R)
canopic jug writes:The US Department of Defense has published a report entitled, Securing the Software Supply Chain: Recommended Practices for Managing Open Source Software and Software Bill of Materials (warning for PDF) about aligning government activities with industry best practices. It covers principles that software developers and software suppliers can reference, including managing open source software andsoftware bills of materials to maintain and provide awareness about software security. The reports a follow up to the much hyped 2021 executive order on cybersecurity. Much focus is given to making and using Software Bill of Materials (SBOM) and incorporating them into the work flow: