Generate SWID and CoSWID tags #34

Description

@achrinza

Overview of specifications

ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

Use-cases for SWID and CoSWID Tags

SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

Comparison to CPE

CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

  • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
  • Inability to identify software patches

Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

Relevance to LoopBack project

The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

Further usage

SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

Relevance to LoopBack users

LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

Specifications which incorporate SWID and CoSWID

Tools which leverage SWID and CoSWID Tags

This is a non-exhaustive list.

  • OpenSCAP
  • Jamf
  • NIST SWID Tag Tools
  • Microsoft Assessment and Planning (MAP) Toolkit
  • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

Projects & software which produce SWID an CoSWID Tags

This is a non-exhaustive list.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
     blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    
    Skip to content

    Generate SWID and CoSWID tags #34

    Description

    @achrinza

    Overview of specifications

    ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

    IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

    Use-cases for SWID and CoSWID Tags

    SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

    In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

    Comparison to CPE

    CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

    SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

    • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
    • Inability to identify software patches

    Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

    Relevance to LoopBack project

    The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

    These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

    As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

    Further usage

    SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

    Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

    Relevance to LoopBack users

    LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

    Specifications which incorporate SWID and CoSWID

    Tools which leverage SWID and CoSWID Tags

    This is a non-exhaustive list.

    • OpenSCAP
    • Jamf
    • NIST SWID Tag Tools
    • Microsoft Assessment and Planning (MAP) Toolkit
    • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

    Projects & software which produce SWID an CoSWID Tags

    This is a non-exhaustive list.

    References

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      No labels
      No labels

      Type

      No type

      Projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
      Skip to content

      Generate SWID and CoSWID tags #34

      Description

      @achrinza

      Overview of specifications

      ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

      IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

      Use-cases for SWID and CoSWID Tags

      SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

      In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

      Comparison to CPE

      CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

      SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

      • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
      • Inability to identify software patches

      Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

      Relevance to LoopBack project

      The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

      These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

      As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

      Further usage

      SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

      Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

      Relevance to LoopBack users

      LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

      Specifications which incorporate SWID and CoSWID

      Tools which leverage SWID and CoSWID Tags

      This is a non-exhaustive list.

      • OpenSCAP
      • Jamf
      • NIST SWID Tag Tools
      • Microsoft Assessment and Planning (MAP) Toolkit
      • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

      Projects & software which produce SWID an CoSWID Tags

      This is a non-exhaustive list.

      References

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        No labels
        No labels

        Type

        No type

        Projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
        Skip to content

        Generate SWID and CoSWID tags #34

        Description

        @achrinza

        Overview of specifications

        ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

        IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

        Use-cases for SWID and CoSWID Tags

        SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

        In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

        Comparison to CPE

        CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

        SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

        • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
        • Inability to identify software patches

        Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

        Relevance to LoopBack project

        The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

        These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

        As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

        Further usage

        SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

        Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

        Relevance to LoopBack users

        LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

        Specifications which incorporate SWID and CoSWID

        Tools which leverage SWID and CoSWID Tags

        This is a non-exhaustive list.

        • OpenSCAP
        • Jamf
        • NIST SWID Tag Tools
        • Microsoft Assessment and Planning (MAP) Toolkit
        • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

        Projects & software which produce SWID an CoSWID Tags

        This is a non-exhaustive list.

        References

        Metadata

        Metadata

        Assignees

        No one assigned

          Labels

          No labels
          No labels

          Type

          No type

          Projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
          Skip to content

          Generate SWID and CoSWID tags #34

          Description

          @achrinza

          Overview of specifications

          ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

          IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

          Use-cases for SWID and CoSWID Tags

          SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

          In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

          Comparison to CPE

          CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

          SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

          • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
          • Inability to identify software patches

          Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

          Relevance to LoopBack project

          The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

          These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

          As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

          Further usage

          SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

          Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

          Relevance to LoopBack users

          LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

          Specifications which incorporate SWID and CoSWID

          Tools which leverage SWID and CoSWID Tags

          This is a non-exhaustive list.

          • OpenSCAP
          • Jamf
          • NIST SWID Tag Tools
          • Microsoft Assessment and Planning (MAP) Toolkit
          • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

          Projects & software which produce SWID an CoSWID Tags

          This is a non-exhaustive list.

          References

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            No labels
            No labels

            Type

            No type

            Projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
            Skip to content

            Generate SWID and CoSWID tags #34

            Description

            @achrinza

            Overview of specifications

            ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

            IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

            Use-cases for SWID and CoSWID Tags

            SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

            In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

            Comparison to CPE

            CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

            SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

            • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
            • Inability to identify software patches

            Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

            Relevance to LoopBack project

            The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

            These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

            As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

            Further usage

            SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

            Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

            Relevance to LoopBack users

            LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

            Specifications which incorporate SWID and CoSWID

            Tools which leverage SWID and CoSWID Tags

            This is a non-exhaustive list.

            • OpenSCAP
            • Jamf
            • NIST SWID Tag Tools
            • Microsoft Assessment and Planning (MAP) Toolkit
            • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

            Projects & software which produce SWID an CoSWID Tags

            This is a non-exhaustive list.

            References

            Metadata

            Metadata

            Assignees

            No one assigned

              Labels

              No labels
              No labels

              Type

              No type

              Projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Generate SWID and CoSWID tags #34

              Description

              @achrinza

              Overview of specifications

              ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

              IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

              Use-cases for SWID and CoSWID Tags

              SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

              In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

              Comparison to CPE

              CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

              SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

              • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
              • Inability to identify software patches

              Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

              Relevance to LoopBack project

              The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

              These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

              As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

              Further usage

              SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

              Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

              Relevance to LoopBack users

              LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

              Specifications which incorporate SWID and CoSWID

              Tools which leverage SWID and CoSWID Tags

              This is a non-exhaustive list.

              • OpenSCAP
              • Jamf
              • NIST SWID Tag Tools
              • Microsoft Assessment and Planning (MAP) Toolkit
              • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

              Projects & software which produce SWID an CoSWID Tags

              This is a non-exhaustive list.

              References

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                No labels
                No labels

                Type

                No type

                Projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions

                , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                Skip to content

                Generate SWID and CoSWID tags #34

                Description

                @achrinza

                Overview of specifications

                ISO/IEC 19770-2:2015 SWID (Software Identification) Tags provide an extensible XML-based structure to identify and describe individual software components, patches, and installation bundles.

                IETF draft-ietf-sacm-cowid-22 CoSWID (Concise Software Identification) Tags are a concise representation of SWID tags where SWID tag representations are too large for devices with network and storage constraints.

                Use-cases for SWID and CoSWID Tags

                SWID and CoSWID Tags are designed to support software asset management by providing a standardised representation of the critical attributes of installed software, such as software vendor, name, major, minor and patch versions, etc.

                In more modern use-cases, SWID and CoSWID Tags build the foundation of continuous software attribute and posture collection. This would assist organisations in compliance scanning, vulnerability scanning, and general software inventorying.

                Comparison to CPE

                CPE (Common Product Enumeration) is a specification introduced and developed under the NIST SCAP (Security Content Automation Platform) v1 specification umbrella. CPE is the predecessor to SWID and "is being deprecated and will not be supported as it was in SCAP v1".

                SWID and CoSWID Tags are the successor to CPE. It resolves the following issues with CPE (taken from NIST.CSWP.09102018):

                • Inadequate expression of granular metadata about software releases and version ranges to accurately identify vulnerable software
                • Inability to identify software patches

                Notably, version ranges are ubiquitous in the Node.js and NPM ecosystem. With CPE, every vulnerable version would need to be enumerated. In addition, the more granular expression of SWID Tags enables better extraction of semantic meaning behind the SWID Tag, and how it relates to the other packages and versions released under the LoopBack project.

                Relevance to LoopBack project

                The LoopBack project has ongoing work to revamp its publication of security advisories. As part of this work, the LoopBack project has decided to update the NIST CPE dictionary (see: #3).

                These CPEs are intended to be placed as part of security advisories, and for more general use by the LoopBack community.

                As CPEs are considered deprecated, the LoopBack project should consider publishing SWID Tags alongside CPEs. As CPEs can be generated, there is little cost for maintaining current and future CPEs. Likewise, SWID Tags can also be generated and hence has little maintenance cost beyond initial "generation code" prototyping.

                Further usage

                SWID tags can also be stored in *.swidtag files for discovery by a SWID-aware file system scanner. Hence, LoopBack Node.js modules can be packaged with *.swidtag files for discovery by more generic tools which may not be Node.js module-aware.

                Another use-case is exposure of LoopBack server information as SWID Tags, which are discovered through ROLIE (Resrouce-Oriented Lightweight Information Exchange) Feeds. This would enable for software attribute collection in line with SCAP v2 and SACM (Security Automation and Continuous Monitoring) architecture.

                Relevance to LoopBack users

                LoopBack users can benefit from leveraging existing or potential tooling which understand SWID and CoSWID Tags to aid in managing their IT asset management programme without relying on Node.js-aware scanners. By combining *.swidtag files and publishing of SWID Tags in security advisories, LoopBack users can use generic tools to perform correlation of security advisories against their environment. This is further extended through Vex profiles, which provide a more granular insight to the practical impact of LoopBack dependency vulnerabilities as dictated by the LoopBack Maintainers or by external security researchers

                Specifications which incorporate SWID and CoSWID

                Tools which leverage SWID and CoSWID Tags

                This is a non-exhaustive list.

                • OpenSCAP
                • Jamf
                • NIST SWID Tag Tools
                • Microsoft Assessment and Planning (MAP) Toolkit
                • Microsoft Endpoint Configuration Manager (f.k.a. System Center Configuration Manager, Systems Management Server) Asset Intelligence

                Projects & software which produce SWID an CoSWID Tags

                This is a non-exhaustive list.

                References

                Metadata

                Metadata

                Assignees

                No one assigned

                  Labels

                  No labels
                  No labels

                  Type

                  No type

                  Projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions