feat: CBOM feature page, FAQs, blog refresh, and the EO 14412 post - #110
Open
aurangzaib048 wants to merge 2 commits into
Open
feat: CBOM feature page, FAQs, blog refresh, and the EO 14412 post#110aurangzaib048 wants to merge 2 commits into
aurangzaib048 wants to merge 2 commits into
Conversation
Feature page walks upload, inventory, quantum grading, certificates, protocols with the PCI DSS 12.3.3 CSV export, the workspace dashboard, Trust Center posture, release-level CBOM, and generation recipes, with real product screenshots. Linked from the features index and llms.txt. Three FAQs: uploading a CBOM, how quantum readiness grading works, and which tools generate CBOMs. The 2024 CBOM post gets a lastmod, a product paragraph naming shipped capabilities with a feature-page link, a CycloneDX 1.6/1.7 ECMA-424 note, EO 14412 leading the regulatory section, the PCI claim tightened to requirement 12.3.3 with its date, and a current generation-tools list (sbomify-action cdxgen, PQCA cbomkit). New post: EO 14412 and the coming CBOM minimum elements, with verified dates and primary-source links throughout.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #98. Closes #99. Closes #100.
What
lastmod: 2026-07-22front matter, product paragraph names shipped capabilities and links the feature page, CycloneDX 1.6/1.7 + ECMA-424 note, EO 14412 leads the regulatory list, PCI claim tightened to requirement 12.3.3 with its mandatory date, generation tools list updated to sbomify-action/cdxgen and PQCA cbomkit. NIST IR 8547 stays cited as draft; the CRA line stays supportive-not-required.Sequencing
The feature page and FAQs describe the crypto surfaces shipping in sbomify/sbomify#1205 (drill-down, certificate and protocol views, CSV export, workspace dashboard, TEA). Merge this after that PR deploys so no page is ahead of the product. Screenshots are from a live environment running that branch.
Checks
Hugo production build passes; every internal link and image reference on the new and edited pages verified against the built output (zero broken).