
Patrick Dwyer -- CycloneDX and SBOMs
The Application Security Podcast
00:00
Is Cyclone D X a Replacement for SCA?
Cyclone d x is a standard form at you can generate them for different eco systems, quite different package eco systems share that information between different tools and ordimation. So i wouldn't use cyclone diex in a build piplane then. Or would i use ar? You would. But it gives you biga picture of your supply chan. It tells me, and sometimes breaks the build if there's some type of high risk vulnerability that exists inside of my application.
Transcript
Play full episode