saw this thread. isn't the issue you're dealing with regarding the SBOM basically the same problem faced with any other piece of software?
How does one know/trust that the app is built with trusted/validated components? thanks On Tue, May 26, 2026, 8:43 PM Dick Brooks via curl-users < [email protected]> wrote: > Dan, > > Thanks for responding, but a "html listing of components" won't work for > our > particular needs. > > Business Cyber Guardian works almost exclusively with the Software Consumer > side to determine trustworthiness of a product before installation. > We produce a "Trust Score" called a "SAGScore" that enables a consumer to > make a risk based decision to install/not install a product, based on a > statistically calculated > SAGSCore, trust score. > > Our risk assessment product, SAG-PM, "needs" an SBOM, and if no SBOM is > provided by the software supplier, then we create an extrapolated SBOM > based > on the distributed package contents. > > My customers want to know "What are you installing in my cyber ecosystem > that could lead to cyber risk". > > We created an SBOM of the curl distribution package (the zip file) as part > of a risk assessment where each leaf node in the zip file is represented as > a component in the extrapolated SBOM file created by SAG-PM. > The curl distribution Package (zip file) contains 359 independent SBOM > components, based on zip file contents. > > These 359 components are then subjected to a "vulnerability search" using > NIST NVD to determine if there are any potential "known vulnerability > risks". > Any discovered risks will lower the trust score (SAGScore). > > An html file listing components is not sufficient for the risk assessment > we > perform. Only an SBOM that contains all of the components contained in a > "distribution package" will work for this risk assessment. > > I hope this helps to explain why we need an SBOM for the "distributed" > (built/distributed package) in order to perform a proper, comprehensive > risk > assessment before installation. > > Thanks, > > Dick Brooks > > Active Member of the CISA Critical Manufacturing Sector, > Sector Coordinating Council - A Public-Private Partnership > Lifetime IEEE Member > Never trust software, always verify and report! T > Risk always exists, but trust must be earned and awarded.T > https://businesscyberguardian.com/ > Email: [email protected] > Tel: +1 978-696-1788 > > > -----Original Message----- > From: curl-users <[email protected]> On Behalf Of Dan > Fandrich via curl-users > Sent: Tuesday, May 26, 2026 7:31 PM > To: [email protected] > Cc: Dan Fandrich <[email protected]> > Subject: Re: curl verification > > On Tue, May 26, 2026 at 02:08:06PM +0100, Jeremy Nicoll via curl-users > wrote: > > On Tue, 26 May 2026, at 13:30, Dick Brooks via curl-users wrote: > > > This SBOM is just an extrapolation based on the zip file contents > > > downloaded from here: > > > https://curl.se/windows/ > > > > Oh! That's confusing. > > > > If one's on the curl website & follows the obvious top-of-page-banner > > "download" option ... one ends up at: https://curl.se/download.html > > > > If you scroll that page down there's lots of other (3rd-party?) curl > > Windows binaries offered. How is someone supposed to find the page: > > > > https://curl.se/windows/ ? > > The curl-provided binaries are listed along with all the other binaries. > You'll see a link to that page in the Windows 32-bit and Windows 64-bit > sections with the label "the curl project". > -- > Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users > Etiquette: https://curl.se/mail/etiquette.html > > -- > Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users > Etiquette: https://curl.se/mail/etiquette.html >
-- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html
