Skip to content

Commit b90ed38

Browse files
committed
Fix formatting
1 parent 09dd7e5 commit b90ed38

1 file changed

Lines changed: 14 additions & 9 deletions

File tree

โ€Žmarketing/content/blog/sbom_creators_and_consumers.mdโ€Ž

Lines changed: 14 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -11,27 +11,32 @@ SBOMs are a critical tool for understanding your software supply chain. But not
1111
There are ๐—ฐ๐—ฟ๐—ฒ๐—ฎ๐˜๐—ผ๐—ฟ๐˜€ and there are ๐—ฐ๐—ผ๐—ป๐˜€๐˜‚๐—บ๐—ฒ๐—ฟ๐˜€. Sometimes they're the same person, but often they're not.
1212

1313
๐Ÿ‘ฉ๐Ÿปโ€๐Ÿ’ป ๐—–๐—ฟ๐—ฒ๐—ฎ๐˜๐—ผ๐—ฟ๐˜€
14+
1415
These folks generate SBOMs as part of the software build or packaging process:
15-
๐Ÿ’ป Development teams
16-
โš™๏ธ CI/CD pipelines
17-
๐Ÿ“ฆ Software vendors
18-
๐Ÿ› ๏ธ Tooling platforms
16+
17+
* ๐Ÿ’ป Development teams
18+
* โš™๏ธ CI/CD pipelines
19+
* ๐Ÿ“ฆ Software vendors
20+
* ๐Ÿ› ๏ธ Tooling platforms
1921

2022
๐ŸŽฏ Their job: Ensure SBOMs are accurate, complete and reflect the actual software build artifacts.
2123

2224
๐Ÿ™‹๐Ÿปโ€โ™‚๏ธ ๐—–๐—ผ๐—ป๐˜€๐˜‚๐—บ๐—ฒ๐—ฟ๐˜€
25+
2326
These folks use SBOMs to evaluate, verify, or monitor software:
24-
๐Ÿ›ก๏ธ Security analysts
25-
๐Ÿ“ฆ Software integrators
26-
โš–๏ธ Compliance teams
27-
๐Ÿ•ต๐Ÿปโ€โ™€๏ธ QA / SRE engineers
28-
๐Ÿ‘” Customers (especially enterprise/government)
27+
28+
* ๐Ÿ›ก๏ธ Security analysts
29+
* ๐Ÿ“ฆ Software integrators
30+
* โš–๏ธ Compliance teams
31+
* ๐Ÿ•ต๐Ÿปโ€โ™€๏ธ QA / SRE engineers
32+
* ๐Ÿ‘” Customers (especially enterprise/government)
2933

3034
๐ŸŽฏ Their job: Use SBOMs to assess risk, validate trust, and meet policy and/or regulatory requirements.
3135

3236
๐Ÿค“ ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜„๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—ถ๐˜ ๐—ด๐—ฒ๐˜๐˜€ ๐—ถ๐—ป๐˜๐—ฒ๐—ฟ๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด...
3337

3438
If you're a ๐—ฐ๐—ฟ๐—ฒ๐—ฎ๐˜๐—ผ๐—ฟ, you're responsible for ๐˜๐—ฟ๐˜‚๐˜๐—ต.
39+
3540
If you're a ๐—ฐ๐—ผ๐—ป๐˜€๐˜‚๐—บ๐—ฒ๐—ฟ, you're responsible for ๐˜๐—ฟ๐˜‚๐˜€๐˜.
3641

3742
This is why signing SBOMs and supporting cryptographic digital verification is critical. Without that, you might be consuming... misinformation? ๐Ÿคทโ€โ™‚๏ธ

0 commit comments

Comments
ย (0)