Sign in

Steve Springett

@stevespringett.bsky.social
684 followers 130 following 15 posts

Father, husband, cybersecurity professional, lover of all things that go “vrooom”, and avid watch collector. Creator of OWASP Dependency-Track. Chair of CycloneDX. Founder of Ecma TC54. OWASP Global Board of Directors. about.me/stevespringett

PostsRepliesMedia
Reposted by Steve Springett
OWASP® Foundation @owasp.org · 09/06/2026
OWASP Dependency-Track 5.0 is GA, built for enterprise scale: early adopters ingested 20K+ SBOMs/hour with single instances holding 250K+ projects and 2M+ components. Now with horizontal scaling, fault tolerance, and supply chain integrity checks. dependencytrack.org/ #OWASP #SBOM #AppSec
295
Reposted by Steve Springett
CycloneDX Bill of Materials Specification (ECMA-424) @cyclonedx.bsky.social · 03/03/2026
The Authoritative Guide to AI/ML-BOM from CycloneDX just dropped. Full transparency into your AI supply chain: security, compliance, data lineage, reproducibility. AI regulations are here. Be ready. #AI #AIBOM #SBOM #OWASP #CycloneDX cyclonedx.org/guides/
cyclonedx.org
Guides and Resources | CycloneDX
Unlock valuable insights and practical guidance to help your organization maximize CycloneDX and reduce supply chain risk.
021
Steve Springett @stevespringett.bsky.social · 03/02/2026
Always been a fan of BSD and really excited to see the new direction, starting with 15. canartuc.medium.com/freebsd-laptop-…
010
Reposted by Steve Springett
Jordan Harband @jordan.har.band · 09/01/2026
I made a new thing! like the semver package, but for PURLs: www.npmjs.com/package/purl `npx purl $specifier` or `npx purl $purl` will validate, normalize, and provide parse info. add `--check` & it'll contact the relevant registry & verify the package and version exist (you can import it too)
npmjs.com
161
Reposted by Steve Springett
Anchore @anchore.com · 12/12/2025
Compliance doesn't have to mean endless spreadsheets. 📉 @stevespringett.bsky.social on machine-readable attestations: "A single attestation can attest to multiple standards simultaneously. This saves a l... anchore.com/blog/4-lessons-on-futur…
021
Reposted by Steve Springett
Anchore @anchore.com · 06/12/2025
What you intended to build vs. what you actually built. @stevespringett.bsky.social explains the power of the Manufacturing BOM to catch drift and compromise in the build pipeline. Don't trust the source;... anchore.com/blog/4-lessons-on-futur…
011
Reposted by Steve Springett
Anchore @anchore.com · 03/12/2025
"The format doesn't really matter... It's really about the content." We hosted @stevespringett.bsky.social, Chair of the CycloneDX WG, to discuss why the industry needs to stop fighting format wars and st... anchore.com/blog/4-lessons-on-futur…
022
Reposted by Steve Springett
CycloneDX Bill of Materials Specification (ECMA-424) @cyclonedx.bsky.social · 21/10/2025
CycloneDX v1.7 is here! The latest release strengthens software & system transparency with: - Cryptography BOM (CBOM) - Data provenance & citations - Intellectual property visibility Learn more: cyclonedx.org/news/cyclone... #OWASP #SBOM #CBOM #CyberSecurity
x.com
CycloneDX SBOM Spec (OWASP) on X: "CycloneDX v1.7 is here! The latest release strengthens software & system transparency with: - Cryptography BOM (CBOM) - Data provenance & citations - Intellectual property visibility Learn more: https://t.co/VjHCDgC5tL #OWASP #CycloneDX #SBOM #CBOM #CyberSecurity" / X
CycloneDX v1.7 is here! The latest release strengthens software & system transparency with: - Cryptography BOM (CBOM) - Data provenance & citations - Intellectual property visibility Learn more: https://t.co/VjHCDgC5tL #OWASP #CycloneDX #SBOM #CBOM #CyberSecurity
196
Reposted by Steve Springett
OWASP Nest @nest.owasp.org · 11/10/2025
🎉 Big news from the OWASP Nest Team! 🎉 We're thrilled to share that OWASP Nest has officially been promoted from the Incubator level to the Lab level! www.linkedin.com/feed/update/...
3124
Steve Springett @stevespringett.bsky.social · 06/10/2025
For those of you that despise Liquid Glass, there's a way to disable it on macOS Tahoe. defaults write -g com.apple.SwiftUI.DisableSolarium -bool YES This reddit thread has more info.https://www.reddit.com/r/macapps/comments/1nz6tco/open_source_disable_liquid_glass_with_solidglass/
reddit.com
Reddit - The heart of the internet
020
Reposted by Steve Springett
CycloneDX Bill of Materials Specification (ECMA-424) @cyclonedx.bsky.social · 21/04/2025
Join us on Wed May 28, 2025 in Barcelona for a hands-on hackathon to test Beta 1 of the Transparency Exchange API (TEA) — a new way to securely exchange SBOMs, attestations & more. Free registration, thanks to @owasp.org and Ecma International. cyclonedx.org/events/hacka... #CycloneDX #SBOM
cyclonedx.org
Transparency Exchange API (TEA) Hackathon - Barcelona 2025 | CycloneDX
Join us in Barcelona to test and shape the Transparency Exchange API, the next evolution in secure supply chain communication.
085
Reposted by Steve Springett
Common Vulnerabilities and Exposures (CVE™) Program @cveprogram.bsky.social · 04/04/2025
“CVE Data Usage and Satisfaction Survey” Ends today, April 4, 2025, at 11:59 PM ET! CVE content consumers, & defenders, this is your opportunity to help enhance the CVE Program & its service offerings Access the survey here: forms.office.com/g/hx168RPctg
forms.office.com
Microsoft Forms
011
Reposted by Steve Springett
OWASP Dependency-Track @dependencytrack.bsky.social · 27/03/2025
Join our community meeting next Wednesday, 2nd April at 4-5PM UTC for a presentation from our friends at #Monzo Bank! Learn how Monzo replaced a proprietary vulnerability scanner with @cyclonedx.bsky.social #SBOMs & Dependency-Track. Calendar Invite: dub.sh/dtcalendar Zoom Link: dub.sh/dtzoom
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
164
Reposted by Steve Springett
Andrew Lilley Brinker @alilleybrinker.com · 10/03/2025
Identifying software is hard! I'll be on a panel with @stevespringett.bsky.social (OWASP), MegaZone (F5), and Christopher Turner (NIST) at VulnCon to talk about options for software identification in vulnerability management. 9:00 to 9:30 EDT, April 8th. www.first.org/conference/v...
first.org
Program Overview / CVE Program & FIRST VulnCon 2025
193
Steve Springett @stevespringett.bsky.social · 15/02/2025
Honored to be discussing @cyclonedx.bsky.social and machine-readable attestations with Anchore this month. Join me! This is going to be fun and educational for anyone not familiar with CycloneDX Attestations (CDXA). This is an ideal solution for EO 14144 which requires machine-readable attestations.
061
Steve Springett @stevespringett.bsky.social · 15/02/2025
@hacks4pancakes.com, you gave one of the best keynotes yesterday at ChiBrrCon that I’ve seen in a very long time. Bravo. Told my wife and a few co-workers about it and the utterly raw impact it had on many in the audience. Any chance of an encore or recording in the future? Best wishes.
120
Reposted by Steve Springett
Uncle Joe @sydseter.com · 14/02/2025
How to pass the OWASP MASVS verification by design? In Admincontrol, our Android app and IOS app passed the @owasp.org MASVS verification by deciding security requirements and -controls using a game. Here is how...https://dev.to/owasp/how-to-pass-the-owasp-masvs-verification-by-design-2cf9 #appsec
3297
Steve Springett @stevespringett.bsky.social · 10/02/2025
The continued innovation happening in @cyclonedx.bsky.social is truly inspiring. This week, its from the cdxgen team with "cdx1", a family of open-source, SOTA machine learning (ML) models purpose-built for xBOM analysis, validation, and reasoning. www.linkedin.com/pulse/cdx1-u... #OWASP #SBOM
linkedin.com
cdx1 - Unlocking the Next Frontier in xBOM Analysis
If asked to name an incubator that has produced hundreds of projects and tens of highly valuable unicorns, one need only mention the OWASP Foundation. While many in the Western world erroneously assum...
142
Reposted by Steve Springett
Reliza @reliza.bsky.social · 22/01/2025
Why We Chose CycloneDX Over SPDX #sbom #cybersecurity worklifenotes.com/2025/01/21/w...
worklifenotes.com
Why We Chose CycloneDX Over SPDX - Work & Life Notes
This is my second post in SBOM series where I would explain why we chose CycloneDX over SPDX for our projects. The first post was focusing on the need to have
064
Steve Springett @stevespringett.bsky.social · 22/01/2025
I have been on Twitter since Feb 2009 and today, I have deactivated the account. While I am unable to make public political statements, it's not that hard to figure out. The projects that I lead or co-lead will continue to have a presence on the site, but I will not.
0271
Reposted by Steve Springett
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 15/12/2024
📌 Excited to share my upcoming book, "Alice and Bob Learn Secure Coding," with you all! Learn from real-world examples, practical advice, and insightful anecdotes. Stay tuned for the release on Feb 5th! shehackspurple.ca/bo...
1185
Reposted by Steve Springett
Uncle Joe @sydseter.com · 10/12/2024
At the first ever KoalaCon @owasp.org shared insights into how TEA (Transparency Exchange API) can help automate your product lifecycle. This will be essential to dependency management and vulnerability management in the future. And you can be part of it! #cybersec #appsec #dependency-management
0155
Steve Springett @stevespringett.bsky.social · 02/12/2024
KoalaCon 2024 was a huge success. Thank you to all the speakers, including Olle E Johansson, Anthony Harrison, Niklas Düster, Viktor Petersson, and Piotr P. Karwasz. Couldn't attend. No worries, the recording is available on YouTube. youtu.be/NStzYW4WnEE?... #OWASP #SBOM #SoftwareTransparency
youtu.be
OWASP KoalaCon 2024
YouTube video by OWASP CycloneDX
0107
Reposted by Steve Springett
Eivind Skjelmo @skjelmo.no · 29/11/2024
Black Friday, a day to be exposed to surprising reset password flows. Password in email, repeatedly the same verification token, etc. Owasp has a great Forgot Password Cheat Sheet if you ever find yourself implementering a forgot password service: cheatsheetseries.owasp.org/cheatsheets/...
cheatsheetseries.owasp.org
Forgot Password - OWASP Cheat Sheet Series
Website with the collection of all the cheat sheets of the project.
152
Reposted by Steve Springett
OWASP® Foundation @owasp.org · 26/11/2024
🎉 Don't miss out on this thrilling opportunity! Get your SUPER Early Bird Tickets for 2025 #OWASP Global #AppSec EU in Barcelona now! Book your spot at a special discounted rate for the May conference. Hurry, these prices are only for a limited time!!! REGISTER TODAY: owasp.glueup.com/eve... #AI
0136
Steve Springett @stevespringett.bsky.social · 20/11/2024
Some of the projects I'm involved with have establish bsky account recently. Check out: OWASP CycloneDX (ECMA-424) @cyclonedx.bsky.social OWASP Dependency-Track @dependencytrack.bsky.social Ecma Technical Committee 54 @tc54.bsky.social
031
Reposted by Steve Springett
securefirmware @securefirmware.bsky.social · 06/11/2024
Can't wait to merge the new #SBOM stuff into the EMBA master ... now with dependencies and much more included
031
Reposted by Steve Springett
OWASP® Foundation @owasp.org · 18/11/2024
If your company creates software that manage Software Bill of Material data - SBOMs - then you want to take part of the standardisation of an ECMA standard API for exchanging software transparency artefacts. Join us on November 25th! teaintro.even... #SPDX #SBOM #INTOTO #CYCLONEDX #OWASP
052
Steve Springett @stevespringett.bsky.social · 02/11/2024
Congrats to the winners of this years election.
000
Steve Springett @stevespringett.bsky.social · 22/02/2024
Ecma TC54 will be working towards standardizing Package URL, specifically purl, vers, and purl types. TC54 will be working out the details over the next few weeks. We invite everyone to learn more about TC54 and contribute to the advancement of Package URL. tc54.org #PackageURL #SBOM #OWASP
030