Advancing CBOM: hands-on with CycloneDX v1.7 and PKI extensions
The opening half of the two-hour CBOM workshop: the Linux Foundation's Post-Quantum Cryptography Alliance and its projects, then the case for a standard way of reporting cryptography. The argument that carries into this working group's methodology is on the reporting-versus-scanning slides — no organization has access to all the source code in use, so cryptography in vendor software and hardware has to be reported rather than discovered, and what has to be reported depends on the use case. The later sessions on use cases and open-source tooling are not in this deck.