#OASIS has launched an open software supply chain info modeling (#OSIM) TC , which aims to standardize and promote open #informationmodels for software provenance and #supplychain #security. How do #SBOM, VEX, CSAF, #CycloneDX, and all that fit together? Come see. Checkmarx, Cisco, Cyware, Google, IBM, LegitSecurity, Microsoft, Root, SAP, CISA, and US NSA are already in.
https://www.oasis-open.org/2024/06/20/oasis-launches-osim/