Skip to content

Commit

Permalink
Merge pull request #224 from FishmanDigital/main
Browse files Browse the repository at this point in the history
Pull Request Links #2
  • Loading branch information
TracyRagan authored Dec 9, 2024
2 parents f15ad91 + a0c3b92 commit 214ef5c
Show file tree
Hide file tree
Showing 7 changed files with 9 additions and 10 deletions.
2 changes: 1 addition & 1 deletion content/en/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ With Ortelius, you can easily answer the question, “where is Log4J running?”

## Sign-up and Get Started Managing Vulnerabilities

From discovering where open-source packages are being used, to federating OpenSSF Scorecard and Application Security Posture Management data, Ortelius serves as a central hub for managing, evaluating, and responding to vulnerabilities, and understanding the risk associated to consuming open-source packages from code to cloud.
From discovering where open-source packages are being used, to federating OpenSSF Scorecard and [Application Security Posture Management](https://www.deployhub.com/application-security-posture-management/) data, Ortelius serves as a central hub for managing, evaluating, and responding to vulnerabilities, and understanding the risk associated to consuming open-source packages from code to cloud.

Get started with Ortelius using the free SaaS version. Take a quick tutorial and see it in action.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ Follow the [Ortelius Installation Guide](https://docs.ortelius.io/guides/usergui

## Conclusion

With the growing importance of adopting SBOMs for software transparency and security, Ortelius offers a method of consumption of the data for continuous vulnerability management. Ortelius streamlines the integration and management of SPDX and CycloneDX SBOMs, helping organizations in efficiently securing their software supply chain. For more information on optimizing SBOM management in complex, microservice-based environments, explore [Ortelius](https://docs.ortelius.io/guides/).
With the growing importance of adopting SBOMs for software transparency and security, Ortelius offers a method of consumption of the data for continuous vulnerability management. Ortelius streamlines the integration and management of SPDX and CycloneDX SBOMs, helping organizations in efficiently securing their software supply chain. For more information on optimizing [SBOM management](https://www.deployhub.com/sbom-management-and-sharing/) SBOM management in complex, microservice-based environments, explore [Ortelius](https://docs.ortelius.io/guides/).

## References
CycloneDX.org (2024) CycloneDX Use Cases. 2024. https://cyclonedx.org/use-cases/ [Accessed: 25 October 2024].
Expand Down
4 changes: 2 additions & 2 deletions content/en/blog/contributors/OrteliusVulnerabilityTracking.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ In conclusion, Ortelius's ability to consume an SBOM automatically and track vul

##### References

Deployhub Demo:- <https://www.deployhub.com/sbom-management/>
Deployhub Demo:- [SBOM Management](https://www.deployhub.com/sbom-management-and-sharing/)

Ortelius Docs:- [ttps://docs.ortelius.io/guides/userguide/integrations/osvdev/](https://docs.ortelius.io/guides/userguide/integrations/osvdev/)

Expand All @@ -43,4 +43,4 @@ Ortelius Docs:- [ttps://docs.ortelius.io/guides/userguide/integrations/osvdev/](

Neetu Jain was one of the first contributors to the Ortelius open-source projects serving in a project management capacity. Neetu is a Product Leader with a passion of turning great ideas into innovative customer centric products, with 2 decades of experience in the tech industry. Neetu builds outcomes, drives team engagement, and creates a culture of collaboration, accountability, and openness. Neetu thrives on the big picture by strategically connecting dots.

Learn more about Neetu Jain by visiting her [LinkedIn Profile](https://www.linkedin.com/in/neetujain/)
Learn more about Neetu Jain by visiting her [LinkedIn Profile](https://www.linkedin.com/in/neetujain/)
2 changes: 1 addition & 1 deletion content/en/blog/contributors/orteliusandsyft.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ author: Tracy Ragan
{{< figure src="/images/siftingdata.jpg" width="400px" height="400px" >}}


Core to the effort of hardening your software development process is SBOM generation and [SBOM Consumption](https://www.deployhub.com/sbom-consumption/). Software Bill of Materials (SBOM) reports are a critical tool in understanding all of the parts of your software supply chain. Without an SBOM you have little understanding of the dependencies your software is consuming. An SBOM gives you a list of your dependencies, what license they use, provenance (where it came from), and version information. With this information you can derive CVEs with a more comprehensive understanding of the artifact.
Core to the effort of hardening your software development process is SBOM generation and [SBOM Consumption](https://www.deployhub.com/understanding-software-bill-of-materials-sboms/). Software Bill of Materials (SBOM) reports are a critical tool in understanding all of the parts of your software supply chain. Without an SBOM you have little understanding of the dependencies your software is consuming. An SBOM gives you a list of your dependencies, what license they use, provenance (where it came from), and version information. With this information you can derive CVEs with a more comprehensive understanding of the artifact.

An SBOM should be created for every 'build' of your component, that being a monolithic application or decoupled microservice. With the direct link between your artifact and SBOM, you have a much clearer picture of your supply chain, and the CVEs associated to specific releases.

Expand Down
2 changes: 1 addition & 1 deletion content/en/blog/news/2023 Blog-A-Thon.md
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ Providing tips and tricks, how-to and getting started informational blogs is the

Education on what SBOMs are, how Ortelius consumes them and why they are important. Suggested topics:

- [What is an SBOM?](https://github.com/ortelius/outreach/issues/14)
- [What is an SBOM?](https://www.deployhub.com/understanding-software-bill-of-materials-sboms/)
- [What are SBOMs used for?](https://github.com/ortelius/outreach/issues/15)
- [How Ortelius Tracks SBOMs for microservices and applications](https://github.com/ortelius/outreach/issues/16)

Expand Down
5 changes: 2 additions & 3 deletions content/en/blog/news/xrplgrant.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,11 +15,10 @@ author: Tracy Ragan

The Ortelius open-source community will work with DeployHub to develop the open-source governance catalog to create an immutable SBOM audit trail that allows open-source developers to easily register their packages with SBOM information allowing organizations consuming open-source to easily access and act upon SBOM data, CVEs, and other usage information.

"SBOMs are key to understanding the software supply chain; however, they are not well managed, can be easily manipulated, and have no clear audit trail" explains Steve Taylor, CTO, DeployHub, Inc. “The transactions captured by the XRP Ledger will include the creation of the component version NFT, the creation of the application-level SBOM version, and the consumption of a logical application SBOM version.”
"[SBOMs](https://www.deployhub.com/understanding-software-bill-of-materials-sboms/) are key to understanding the software supply chain; however, they are not well managed, can be easily manipulated, and have no clear audit trail" explains Steve Taylor, CTO, DeployHub, Inc. “The transactions captured by the XRP Ledger will include the creation of the component version NFT, the creation of the application-level SBOM version, and the consumption of a logical application SBOM version.”

“We are honored to have been awarded the prestigious XRPL Grant which will allow the Ortelius community to address the gaps in SBOM management and audit. Providing a central store of this critical information will allow all open-source projects to be more secure” stated Tracy Ragan, CEO, DeployHub.
“We are honored to have been awarded the prestigious XRPL Grant which will allow the Ortelius community to address the gaps in [SBOM management](https://www.deployhub.com/sbom-management-and-sharing/) and audit. Providing a central store of this critical information will allow all open-source projects to be more secure” stated Tracy Ragan, CEO, DeployHub.

For more information, read the full [DeployHub blog](https://www.deployhub.com/sbom-audit-trail-for-hardening-cybersecurity/)

## About DeployHub

Expand Down
2 changes: 1 addition & 1 deletion content/en/microservicemapping/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ type: contributor

## Control Open-Source Vulnerabilities

Take control of your open-source software security with the Ortelius vulnerability evidence store. Ortelius ensures you maintain a secure and up-to-date inventory of all the open-source components within your software supply chain. It empowers you to make fast, informed decisions about open-source usage across your entire infrastructure, from code to cloud.
Take control of your [open-source software security](https://www.deployhub.com/open-source-software-security/) with the Ortelius vulnerability evidence store. Ortelius ensures you maintain a secure and up-to-date inventory of all the open-source components within your software supply chain. It empowers you to make fast, informed decisions about open-source usage across your entire infrastructure, from code to cloud.

Ortelius can quickly show you where an open-source package version is running across your infrastructure. A simple search on a package and version will provide you with a full inventory of where the package is running, and who is consuming it. This search provides teams a quick way to determine the impact of a CVE, and where it needs to be addressed.
</div>
Expand Down

0 comments on commit 214ef5c

Please sign in to comment.