Skip to content
View coderpatros's full-sized avatar
🌀
🌀

Organizations

@government @CycloneDX @DependencyTrack @dotnet-outdated @sbom-tools @OpenVDR @Ecma-TC54

Block or report coderpatros

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
coderpatros/README.md

Technical leader with 25 years of experience across software engineering, application security, and international standards development. Co-lead of the OWASP CycloneDX SBOM standard (ECMA-424) and elected member of the Ecma International Executive Committee. By day, I manage product security at ServiceNow — by night (and weekends), I'm working to make software supply chains more transparent and secure for everyone.

I care about building things that matter, contributing to open standards, and making security an enabler rather than a roadblock. Most of my open source work lives in the CycloneDX ecosystem, spanning tooling in various ecosystems from C# to Fortran.

Pinned Loading

  1. CycloneDX/specification CycloneDX/specification Public

    OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. SBOM, SaaSBOM, HBOM, AI/ML-BOM, CBOM, OBOM, MBOM, VDR, an…

    XSLT 483 83

  2. cyclonedx-dotnet-msbuild cyclonedx-dotnet-msbuild Public

    An MSBuild task that automatically generates CycloneDX Software Bill of Materials (SBOM) during build

    C# 1

  3. CycloneDX/cyclonedx-cli CycloneDX/cyclonedx-cli Public

    CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.

    C# 458 76

  4. cyclonedx-verify cyclonedx-verify Public

    A tool to perform cryptographic verification of software integrity for a CycloneDX SBOM

    C#

  5. environment-indicator environment-indicator Public

    Javascript visual environment indicator for web apps (i.e. dev, uat, staging, etc)

    JavaScript 1

  6. talks talks Public

    Talks I've given

    1