Standards & Community
We help write the standards we build on.
Supply chain transparency only works when everyone speaks the same language. We contribute to the specifications, guides and working groups that define that language, and we ship open-source implementations of them.
01
ECMA TC54-TG1
Transparency Exchange API
TEA standardizes how xBOMs and other transparency artifacts are published and discovered. Oolong is our open-source implementation, and ReARM supports it natively.
↳ TEA on GitHubOUR ROLEKey contributorPavel Shukhman is an Invited Expert.
02
ECMA-424
CycloneDX
CycloneDX is the Transparency Exchange Language. We support and contribute to it, and it underpins how our products store, diff and enrich BOMs.
↳ cyclonedx.orgOUR ROLESupporter & contributorCore format across ReARM and BEAR.
03
OWASP · CYCLONEDX
Authoritative Guide to AI/ML-BOM
The OWASP guide explains how to describe AI/ML models, datasets and their dependencies in a Bill of Materials.
↳ Read the guide (PDF)OUR ROLEGuide contributorPavel Shukhman took part in its preparation.
04
OPEN SOURCE SECURITY FOUNDATION
OpenSSF SBOM group
We contribute to the OpenSSF SBOM group and to the materials it has developed for the wider community.
↳ openssf.orgOUR ROLEContributorWorking group and published materials.
Implemented in our products
| STANDARD | ReARM | OOLONG | BEAR |
|---|---|---|---|
| CycloneDX (ECMA-424) | ✓ | ✓ | ✓ |
| SPDX (ISO/IEC 5962:2021) | ✓ | – | – |
| Transparency Exchange API | ✓ | ✓ | – |
| OpenVEX | ✓ | – | – |
| Package-URL (ECMA-427) | ✓ | ✓ | ✓ |
| CLE (ECMA-428) | ✓ | – | – |
Join the community