
Security News
Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.
Socket is joining TC54 to help develop standards for software supply chain security, contributing to the evolution of SBOMs, CycloneDX, and Package URL specifications.

January 31, 2025
2 min read


We're excited to share that Socket has officially joined TC54! This marks an important step in our commitment to improving software supply chain security, and we’re looking forward to contributing to the evolution of key technologies like Software Bill of Materials (SBOMs), CycloneDX, and Package URLs (PURL).
TC54 is a technical committee dedicated to standardizing core data formats, APIs, and algorithms that advance software and system transparency. It oversees key specifications such as PURL, a format for identifying software packages across ecosystems, and is chartered to oversee the OWASP CycloneDX Bill of Materials (SBOM) specification and to develop new standards that enhance transparency and identity across the supply chain.
TC54 was established in December 2023 as a joint initiative between Ecma International and the OWASP Foundation, both of which have long been committed to open industry standards. These organizations have driven a series of advancements in software transparency, beginning with the introduction of CycloneDX v1.0 in 2018.
Over the years, CycloneDX has evolved significantly, incorporating features like component lineage tracking, vulnerability disclosure, AI transparency, and post-quantum cryptographic readiness. In June 2024, CycloneDX v1.6 was ratified as an Ecma international standard and published as ECMA-424.
At Socket, we believe in securing the open source ecosystem at its core, and that starts with improving visibility and standardization around software dependencies. By participating in TC54, we have an opportunity to collaborate with industry leaders and help refine these crucial standards to make them more robust, flexible, and developer-friendly.
“As a supply chain security company, it's important for us to be involved in the open source and standards process,” Socket engineer and TC54 contributor John-David Dalton said. “We are part of the community as well as the ecosystem we protect.”
While our involvement is just beginning, our team is already actively contributing to TC54’s initiatives:
Our participation in TC54 is just getting started, but we’re eager to contribute, learn, and collaborate. By working on standards like PURL and CycloneDX, we aim to make software supply chain security more effective and accessible for everyone.
“The future of software security depends on strong, open, community-driven standards,” Socket CEO Feross Aboukhadijeh said. “Through TC54, we're collaborating with industry leaders to build that future and protect developers worldwide."
We’ll be sharing updates as we make progress—stay tuned for more!

Subscribe to our newsletter
Get notified when we publish new security blog posts!

Security News
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.

Security News
OSV withdrew 157 OSV malware reports after automated false positives incorrectly flagged trusted npm and PyPI packages, sending bad records into tools that rely on OSV data.

Research
/Security News
TrapDoor crypto stealer hits 36 malicious packages across npm, PyPI, and Crates.io, targeting crypto, DeFi, AI, and security developers.