Tobie,
Regarding: “Best current practise for SBOM in open source projects”
The US Government follows NIST Guidance for SBOM implementation best practices for all software products, which you will find here:
https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains-software-1
This NIST SBOM guidance information is also referenced in the SPDX SBOM V 2.3 spec under appendix K:
https://spdx.github.io/spdx-spec/v2.3/how-to-use/#k19-linking-to-an-sbom-vulnerability-report-for-a-software-product-per-nist-executive-order-14028
There is also an #SBOM SIG on LinkedIn public group (anyone can post/view) where SBOM implementers share insights and best practices on successful SBOM implementation, both SPDX and CycloneDX SBOMs are discussed;
https://www.linkedin.com/groups/13274064/
Thanks,
Dick Brooks

Active Member of the CISA Critical Manufacturing Sector,
Sector Coordinating Council – A Public-Private Partnership
Never trust software, always verify and report! ™
Risk always exists, but trust must be earned and awarded.™
https://businesscyberguardian.com/
Email: dick@xxxxxxxxxxxxxxxxxxxxxxxxx
Tel: +1 978-696-1788
From: open-regulatory-compliance <open-regulatory-compliance-bounces@xxxxxxxxxxx> On Behalf Of Tobie Langel via open-regulatory-compliance
Sent: Thursday, June 19, 2025 1:07 PM
To: Open Regulatory Compliance Working Group <open-regulatory-compliance@xxxxxxxxxxx>
Cc: Tobie Langel <tobie@xxxxxxxxxxxxxx>
Subject: [open-regulatory-compliance] Vulnerability Handling Task Force Meeting Minutes
Hi all,
As agreed during today's call, please use this email thread to discuss topics for potential TF deliverables.
Here are some possible topics that were raised:
- A document describing the role and obligations of stewards
- Best current practise for SBOM in open source projects
- Describing the relation between open source projects and manufacturers in regards to vuln management
Additionally, it might be worth getting acquainted with the deliverables plan as it contains a number of deliverables that might be interesting for this TF to get involved with or to drive.
---
Tobie Langel
Tech Lead ORC WG, Eclipse Foundation
Principal, UnlockOpen