<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Andrew Lilley Brinker - Software ID</title>
    <subtitle>I work on software security at MITRE, including serving as amember of the OmniBOR Working Group, where I lead development of the Rustimplementation, and as the project manager for Hipcheck, a tool forautomated supply chain risk assessment of software packages.
</subtitle>
    <link rel="self" type="application/atom+xml" href="https://www.alilleybrinker.com/topics/software-id/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://www.alilleybrinker.com"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2025-04-10T00:00:00+00:00</updated>
    <id>https://www.alilleybrinker.com/topics/software-id/atom.xml</id>
    <entry xml:lang="en">
        <title>Tracking Software ID Schemes</title>
        <published>2025-04-10T00:00:00+00:00</published>
        <updated>2025-04-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Andrew Lilley Brinker
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://www.alilleybrinker.com/mini/tracking-software-id-schemes/"/>
        <id>https://www.alilleybrinker.com/mini/tracking-software-id-schemes/</id>
        
        <content type="html" xml:base="https://www.alilleybrinker.com/mini/tracking-software-id-schemes/">&lt;p&gt;Part of my life is working on the problem of software identification. I’m on
the Core Team for &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;omnibor.io&#x2F;&quot;&gt;OmniBOR&lt;&#x2F;a&gt;, a reproducible software identifier scheme, and my
other work in software supply chain security and vulnerability management often
bumps up against challenges with identifying software at differing levels of
granularity, mapping vulnerabilities or SBOMs (Software Bills of Material) to
specific software.&lt;&#x2F;p&gt;
&lt;p&gt;It may surprise you to learn there are a lot of software identifier schemes.
Some of them are general purpose and used across different ecosystems, while
some are ecosystem or even tool- or API-specific.&lt;&#x2F;p&gt;
&lt;p&gt;To help track those identifiers and link to their specifications, I’ve made a
new &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.alilleybrinker.com&#x2F;softwareids&#x2F;&quot;&gt;Software ID tracker&lt;&#x2F;a&gt;. It’s &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;github.com&#x2F;alilleybrinker&#x2F;softwareids&quot;&gt;up on GitHub&lt;&#x2F;a&gt; and
contributions are welcome!&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
