Explore the world
of cyber security

Driven by volunteers, OWASP resources are accessible for everyone.





Advisory on Software Bill of Materials and Real-time Vulnerability Monitoring for Open-Source Software and Third-Party Dependencies

image

Steve Springett, February 24, 2025

The OWASP Foundation, in collaboration with the Cyber Security Agency (CSA) of Singapore, presents this advisory on using Software Bill of Materials (SBOM) for enhanced vulnerability management, highlighting OWASP CycloneDX—a format standardized by Ecma International as ECMA-424 —and underscoring OWASP’s joint efforts with both Ecma International and CSA. The advisory also features OWASP Dependency-Track the reference platform for how to consume and analyze SBOMs. For details, including GitHub and GitLab examples and additional references, please see the original advisory published by CSA.

...read more

Upcoming at OWASP

Quick access to our highlighted
flagship resources
See all flagship resources(15)
Documentation
Top Ten
The reference standard for the most critical web application security risks
Documentation
ASVS
Application security verification standard
Documentation
Cheat Sheets
List of crucial app security information
Have an idea for a project?
Take advantage of our resources and
let it grow with OWASP.


Recent OWASP News & Opinions

Upcoming Conferences