Event JSON
{
"id": "1bd2da326adbc68153f1aeef5b26ad06b5839cd24dd0f6e475f5e8555f36ded0",
"pubkey": "35dd7abff87d2b2961da2b62bffbdd8a90b928b6eadc4fd0cc056c6930e459ba",
"created_at": 1731614544,
"kind": 1,
"tags": [
[
"proxy",
"https://fosstodon.org/@sethmlarson/113483090781799755",
"web"
],
[
"t",
"python"
],
[
"proxy",
"https://fosstodon.org/users/sethmlarson/statuses/113483090781799755",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://fosstodon.org/users/sethmlarson/statuses/113483090781799755",
"pink.momostr"
],
[
"-"
]
],
"content": "Published some early validation results from my \"SBOM for #Python packages\" project. TLDR: I forked auditwheel and added some rudimentary SBOM record-keeping for bundled libraries and showed that today's SCA tools are able to use that information out-of-the-box. Full instructions and work in the post:\n\nhttps://sethmlarson.dev/early-promising-results-with-sboms-and-python-packages",
"sig": "6baf6ddcec2b6515432ba132e83908d3900cba1777f0a8414cb89398df19b0a4558f977df237ed75f3a84849eb565d12331ed20ef84455aa57365e45febac3af"
}