toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

341
active users

#SBOM

4 posts4 participants1 post today
anchore<p>The next critical CVE is coming.</p><p>Will you be in a war room with bloodshot eyes by day 3? </p><p>Or will you run a query, alert affected teams automatically, and go home on time?</p><p>See how Anchore transforms incident response: <a href="https://anchore.com/blog/from-war-room-to-workflow-how-anchore-transforms-cve-incident-response/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchore.com/blog/from-war-room</span><span class="invisible">-to-workflow-how-anchore-transforms-cve-incident-response/</span></a></p><p><a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/VulnerabilityManagement" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VulnerabilityManagement</span></a></p>
anchore<p>🚨 Security teams: Stop manually grepping through your codebase during <a href="https://mstdn.business/tags/zeroday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zeroday</span></a> incidents. Learn how to implement production <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> inventory that turns "Are we affected by this CVE?" into a simple query. <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a> <a href="https://mstdn.business/tags/ZeroDay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZeroDay</span></a> <a href="https://mstdn.business/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p>
anchore<p>Imagine identifying every instance of CVE-2025-1974 across all your Kubernetes clusters in minutes, not days.</p><p>For Anchore Enterprise users during <a href="https://mstdn.business/tags/IngressNightmare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IngressNightmare</span></a>, this wasn't fantasy—it was reality.</p><p>See the step-by-step process: <a href="https://anchore.com/blog/from-war-room-to-workflow-how-anchore-transforms-cve-incident-response/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchore.com/blog/from-war-room</span><span class="invisible">-to-workflow-how-anchore-transforms-cve-incident-response/</span></a></p><p><a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a></p>
Grype<p>Grab a beverage and join the Syft &amp; Grype team livestream in 5 minutes! <a href="https://fosstodon.org/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://fosstodon.org/tags/sbom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbom</span></a> <a href="https://anchorecommunity.discourse.group/t/april-24th-open-source-gardening-live-stream/410" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchorecommunity.discourse.gro</span><span class="invisible">up/t/april-24th-open-source-gardening-live-stream/410</span></a></p>
LavX News<p>.NET Support Revolutionizes Supply Chain Security in C# Projects</p><p>Socket's latest update introduces .NET support, enhancing supply chain security and Software Bill of Materials (SBOM) accuracy for NuGet and MSBuild-powered C# projects. This pivotal integration aims ...</p><p><a href="https://news.lavx.hu/article/net-support-revolutionizes-supply-chain-security-in-c-projects" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/net-suppo</span><span class="invisible">rt-revolutionizes-supply-chain-security-in-c-projects</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mastodon.cloud/tags/NuGet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NuGet</span></a> <a href="https://mastodon.cloud/tags/Socket" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Socket</span></a></p>
anchore<p>Deep dive into supply chain security with the latest Open Source Security podcast! Josh Bressers and Alan Pope unpack the power of Syft and Grype, and other tools focusing on Software Bills of Materials (SBOMs) and vulnerability scanning. They explore not just the what, but also the why behind some key open source projects in this space. Learn how these tools are evolving to give you deeper insights into your s... <a href="https://mstdn.business/tags/OSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OSS</span></a> <a href="https://mstdn.business/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/VulnerabilityManagement" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VulnerabilityManagement</span></a> <a href="https://mstdn.business/tags/Syft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Syft</span></a> <a href="https://mstdn.business/tags/Grype" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Grype</span></a> <a href="https://opensourcesecurity.io/2025/2025-04-syft-grype-grant-alan-pope/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">opensourcesecurity.io/2025/202</span><span class="invisible">5-04-syft-grype-grant-alan-pope/</span></a></p>
anchore<p>📊 WEBINAR ALERT: Beyond the basics of <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> generation to solving the real challenge - SBOM sprawl. Join us live for implementation strategies, tool comparisons, and automation techniques for <a href="https://mstdn.business/tags/federal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>federal</span></a> environments. <a href="https://get.anchore.com/identify-and-tackle-sbom-sprawl/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/identify-and-t</span><span class="invisible">ackle-sbom-sprawl/</span></a></p>
Grype<p>Grab a beverage and join the Syft &amp; Grype team livestream in 5 minutes! <a href="https://fosstodon.org/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://fosstodon.org/tags/sbom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbom</span></a> <a href="https://www.youtube.com/live/jAYYZidqbKI" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/live/jAYYZidqbKI</span><span class="invisible"></span></a></p>
Matt "msw" Wilson<p>Reflecting tonight on the <a href="https://mstdn.social/tags/CVE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CVE</span></a> program, all it has given us, and how frustrated I’ve been because of what does, and what it fails to do.</p><p>Unfortunately there is no point in claiming that the purpose of a system is to do what it constantly fails to do…</p><p><a href="https://mstdn.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://mstdn.social/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a></p>
Grype<p>Zero-days: The uninvited guests crashing your production party. 🥳➡️🔥<br>Show them the door FASTER with SBOMs (Syft's got your inventory!) &amp; targeted scanning (Grype knows what's up!).<br>Webinar fun: April 16, 10 am PT.<br>RSVP: <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a><br><a href="https://fosstodon.org/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://fosstodon.org/tags/ZeroDay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZeroDay</span></a> <a href="https://fosstodon.org/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IncidentResponse</span></a></p>
anchore<p>📢 Webinar Tomorrow: Learn how to query your production environment for vulnerabilities like <a href="https://mstdn.business/tags/IngressNightmare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IngressNightmare</span></a> in seconds using an <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> instead of days with manual analysis. Register now: <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a> <a href="https://mstdn.business/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IncidentResponse</span></a></p>
Matthew Skelton<p>"Slopsquatting is a new supply chain threat where AI-assisted code generators recommend hallucinated packages that attackers register and weaponize."</p><p><a href="https://mastodon.social/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> <a href="https://mastodon.social/tags/sbom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbom</span></a> <a href="https://mastodon.social/tags/cicd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cicd</span></a> </p><p><a href="https://socket.dev/blog/slopsquatting-how-ai-hallucinations-are-fueling-a-new-class-of-supply-chain-attacks" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">socket.dev/blog/slopsquatting-</span><span class="invisible">how-ai-hallucinations-are-fueling-a-new-class-of-supply-chain-attacks</span></a></p>
anchore<p>🚨 Security teams: Stop manually grepping through your codebase during <a href="https://mstdn.business/tags/zeroday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zeroday</span></a> incidents. Learn how to implement production <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> inventory that turns "Are we affected by this CVE?" into a simple query. <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a> <a href="https://mstdn.business/tags/ZeroDay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZeroDay</span></a> <a href="https://mstdn.business/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p>
anchore<p>🚨 Is your organization drowning in SBOMs? Join our technical deep dive <a href="https://mstdn.business/tags/webinar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webinar</span></a> on managing SBOM sprawl with experts from Anchore and OSS Consultants. Get actionable strategies to scale compliance while maintaining <a href="https://mstdn.business/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> visibility. <a href="https://get.anchore.com/identify-and-tackle-sbom-sprawl/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/identify-and-t</span><span class="invisible">ackle-sbom-sprawl/</span></a> <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p>
Grype<p>Remember the chaos of Log4j or XZ Utils? Manually hunting for vulns is PAINFUL. 😩<br>Learn how SBOMs + vulnerability scanning cut through the noise for fast incident response. Webinar April 16th, 10 am PT. <a href="https://fosstodon.org/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://fosstodon.org/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://fosstodon.org/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <br>Sign up: <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a></p>
Grype<p>Grab a beverage and join the Syft &amp; Grype team livestream in 5 minutes! <a href="https://fosstodon.org/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://fosstodon.org/tags/sbom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbom</span></a> <a href="https://www.youtube.com/playlist?list=PL4LF17QFqXYZsXvQUL8PWwSN0ZnthPRMm&amp;playnext=1&amp;index=1" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/playlist?list=PL4L</span><span class="invisible">F17QFqXYZsXvQUL8PWwSN0ZnthPRMm&amp;playnext=1&amp;index=1</span></a></p>
anchore<p>👨‍💻 When the next <a href="https://mstdn.business/tags/IngressNightmare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IngressNightmare</span></a> happens, will you be ready? Join our <a href="https://mstdn.business/tags/webinar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webinar</span></a> to learn how to implement runtime <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> inventory for immediate zero-day vulnerability assessment. Technical demo included. <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a> <a href="https://mstdn.business/tags/ZeroDay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZeroDay</span></a> <a href="https://mstdn.business/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a></p>
anchore<p>As of last week, organizations handling payment data must comply with <a href="https://mstdn.business/tags/PCIDSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PCIDSS</span></a> 4.0.</p><p>Our guide explains how Software Bills of Materials (<a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a>) address Requirement 6.3.2's mandate for software component inventory.</p><p>Get prepared now: <a href="https://anchore.com/blog/pci-dss-4-compliance-with-sboms-and-software-supply-chain-security/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">anchore.com/blog/pci-dss-4-com</span><span class="invisible">pliance-with-sboms-and-software-supply-chain-security/</span></a></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/Python" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Python</span></a>'s <a href="https://mastodon.thenewoil.org/tags/PyPI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PyPI</span></a> Finally Gets Closer to Adding 'Organization Accounts' and SBOMs</p><p><a href="https://developers.slashdot.org/story/25/04/05/0515241/pythons-pypi-finally-gets-closer-to-adding-organization-accounts-and-sboms" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">developers.slashdot.org/story/</span><span class="invisible">25/04/05/0515241/pythons-pypi-finally-gets-closer-to-adding-organization-accounts-and-sboms</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/FOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FOSS</span></a> <a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.thenewoil.org/tags/SBoM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBoM</span></a></p>
anchore<p>📢 Technical webinar: Learn how to query your production environment for <a href="https://mstdn.business/tags/zeroday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zeroday</span></a> vulnerabilities in seconds using an <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> instead of days with manual analysis. Real-world implementation techniques demonstrated for <a href="https://mstdn.business/tags/devsecops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops</span></a> teams. Register now: <a href="https://get.anchore.com/rapid-incident-response-with-sboms/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">get.anchore.com/rapid-incident</span><span class="invisible">-response-with-sboms/</span></a> <a href="https://mstdn.business/tags/SBOM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SBOM</span></a> <a href="https://mstdn.business/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IncidentResponse</span></a></p>