"[C]ompanies must now generate a Software Bill of Materials (SBOM), tracking vulnerabilities,.... and being transparent about security practices. For open source developers, this means, for the first time, companies must publicly acknowledge and document their open source dependencies."
add a skeleton here at some point
7 days ago