SOFTWARE ADG GENERATION TOPIC CALL
SVIP, in partnership with CISA, has announced the Software Artifact Dependency Graph Generation at Scale Topic Call to support CISA’s effort to understand, manage, and reduce risk to the software that powers the cyber and physical infrastructure that Americans and global populations rely on.
The proposed solutions should complement and enhance existing approaches to software identification, enriching the software vulnerability data with intrinsic identifiers, such as artifact dependency graphs (ADGs), that are unique to a component’s contents to both mitigate software vulnerabilities and “bake in” security.
Software ADGs are intrinsic identifiers that are unique to a software component’s contents. They can provide actionable information regarding the dependencies the software incorporates, which increases transparency in software composition and provides standard, machine-readable decision support at an enterprise scale.
This solicitation seeks foundational open source capabilities for compiled languages as well as value-added services that utilize the foundational capabilities.
Foundational open source capabilities sought include:
- Automatic compile time generation of ADGs via integration with open-source compliers and open software build tool chains
- Automatic build-tool-based generation of ADGs for interpreted languages via integration with open source build toolchains
- Automatic post-build package generation of ADGs integrated with open-source post-build package tools
Value-added services sought include:
- Services and products that enable public correlations across generated ADGs
- Services and products that leverage ADGs for additional functionality to be used by Enterprise, System Administrator and Developer communities
By enabling both open source capabilities and value added services that leverage them, DHS seeks to accelerate progress in the domains of software composition analysis and vulnerability management to complement and enhance existing approaches to software identification.
THE APPLICATION SUBMISSION DEADLINE IS 12:00 PM PT / 3:00 PM ET ON DECEMBER 16, 2024. You can find the full solicitation text, including descriptive use case examples, detailed technical background and requirements, application submission instructions and timelines, templates, and resources by viewing the SAM.gov Other Transaction Solicitation (Call 70RSAT24R00000042).