Skip to content

feat: CBOM feature page, FAQs, blog refresh, and the EO 14412 post - #110

Open
aurangzaib048 wants to merge 2 commits into
sbomify:masterfrom
aurangzaib048:feat/cbom-docs
Open

feat: CBOM feature page, FAQs, blog refresh, and the EO 14412 post#110
aurangzaib048 wants to merge 2 commits into
sbomify:masterfrom
aurangzaib048:feat/cbom-docs

Conversation

@aurangzaib048

Copy link
Copy Markdown
Contributor

Closes #98. Closes #99. Closes #100.

What

  • /features/cbom/: full walkthrough (upload and auto-detect, quantum grading with FIPS 203/204/205 migration targets, certificate expiry, protocol and cipher-suite view with the PCI DSS 12.3.3 CSV export, workspace dashboard, Trust Center posture, release-level CBOM, generation recipes) with three real product screenshots. Linked from the features index and llms.txt.
  • Three FAQs (weights 87-89): how to upload a CBOM, how quantum readiness grading works, which tools generate CBOMs.
  • 2024 CBOM post refreshed per refresh the CBOM blog post to match shipped capability #99: lastmod: 2026-07-22 front matter, product paragraph names shipped capabilities and links the feature page, CycloneDX 1.6/1.7 + ECMA-424 note, EO 14412 leads the regulatory list, PCI claim tightened to requirement 12.3.3 with its mandatory date, generation tools list updated to sbomify-action/cdxgen and PQCA cbomkit. NIST IR 8547 stays cited as draft; the CRA line stays supportive-not-required.
  • New post: "EO 14412 and the Coming CBOM Minimum Elements" with verified dates (270-day guidance window landing ~March 2027, end-2030/2031 federal PQC deadlines, CNSA 2.0 Jan 2027 acquisition and 2033 transition, PCI 12.3.3 since 2025-03-31) and primary-source links.

Sequencing

The feature page and FAQs describe the crypto surfaces shipping in sbomify/sbomify#1205 (drill-down, certificate and protocol views, CSV export, workspace dashboard, TEA). Merge this after that PR deploys so no page is ahead of the product. Screenshots are from a live environment running that branch.

Checks

Hugo production build passes; every internal link and image reference on the new and edited pages verified against the built output (zero broken).

aurangzaib048 and others added 2 commits July 22, 2026 21:21
Feature page walks upload, inventory, quantum grading, certificates,
protocols with the PCI DSS 12.3.3 CSV export, the workspace dashboard,
Trust Center posture, release-level CBOM, and generation recipes, with
real product screenshots. Linked from the features index and llms.txt.

Three FAQs: uploading a CBOM, how quantum readiness grading works, and
which tools generate CBOMs.

The 2024 CBOM post gets a lastmod, a product paragraph naming shipped
capabilities with a feature-page link, a CycloneDX 1.6/1.7 ECMA-424
note, EO 14412 leading the regulatory section, the PCI claim tightened
to requirement 12.3.3 with its date, and a current generation-tools
list (sbomify-action cdxgen, PQCA cbomkit).

New post: EO 14412 and the coming CBOM minimum elements, with verified
dates and primary-source links throughout.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

post: EO 14412 and the coming CBOM minimum elements refresh the CBOM blog post to match shipped capability CBOM feature page + FAQs

2 participants