Standards & Community

We help write the standards we build on.

Supply chain transparency only works when everyone speaks the same language. We contribute to the specifications, guides and working groups that define that language, and we ship open-source implementations of them.

01
ECMA TC54-TG1

Transparency Exchange API

TEA standardizes how xBOMs and other transparency artifacts are published and discovered. Oolong is our open-source implementation, and ReARM supports it natively.

↳ TEA on GitHub
OUR ROLEKey contributorPavel Shukhman is an Invited Expert.
02
ECMA-424

CycloneDX

CycloneDX is the Transparency Exchange Language. We support and contribute to it, and it underpins how our products store, diff and enrich BOMs.

↳ cyclonedx.org
OUR ROLESupporter & contributorCore format across ReARM and BEAR.
03
OWASP · CYCLONEDX

Authoritative Guide to AI/ML-BOM

The OWASP guide explains how to describe AI/ML models, datasets and their dependencies in a Bill of Materials.

↳ Read the guide (PDF)
OUR ROLEGuide contributorPavel Shukhman took part in its preparation.
04
OPEN SOURCE SECURITY FOUNDATION

OpenSSF SBOM group

We contribute to the OpenSSF SBOM group and to the materials it has developed for the wider community.

↳ openssf.org
OUR ROLEContributorWorking group and published materials.
Implemented in our products
STANDARDReARMOOLONGBEAR
CycloneDX (ECMA-424)✓✓✓
SPDX (ISO/IEC 5962:2021)✓––
Transparency Exchange API✓✓–
OpenVEX✓––
Package-URL (ECMA-427)✓✓✓
CLE (ECMA-428)✓––
Join the community