Podchaser Logo
Home
Package identifiers are really hard

Package identifiers are really hard

Released Monday, 8th January 2024
Good episode? Give it some love!
Package identifiers are really hard

Package identifiers are really hard

Package identifiers are really hard

Package identifiers are really hard

Monday, 8th January 2024
Good episode? Give it some love!
Rate Episode

Josh and Kurt talk about package identifiers. We break this down in the context of an OpenSSF response to a CISA paper on software identifications. The identifiers that get all the air time are purl, CPE, SWID, and OmniBOR. This is a surprisingly complex problem space. It feels easy, but it's not.

Show Notes

Show More

Unlock more with Podchaser Pro

  • Audience Insights
  • Contact Information
  • Demographics
  • Charts
  • Sponsor History
  • and More!
Pro Features