<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/e511ee55a22f4002b3566ce37a178043&quot; frameborder=&quot;0&quot; width=&quot;1728&quot; height=&quot;1296&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1296</height><width>1728</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1296</thumbnail_height><thumbnail_width>1728</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/e511ee55a22f4002b3566ce37a178043-a0dc4f0679dc6ee0.gif</thumbnail_url><duration>383.795</duration><title>Discover Post-Quantum Crypto Risks With CBOMs</title><description>This Loom explains how Spice Labs helps security teams inventory and assess where cryptography is used for post-quantum cryptography without requiring changes from engineering teams. It generates cryptographic bills of materials from post-build artifacts such as Maven packages and Docker images by using a CLI command to discover packages in a configured repository, taking about 1737 milliseconds (roughly 5 seconds) to find 2800 packages in one example. It then uses another command to pull those packages, perform artifact dependency graph survey and static analysis, and generate CycloneDX 1.6 Seabombs, showing findings like MD5 message digest use with call sites and status indicators. On the author’s machine, downloading and processing an artifact takes about 45 seconds per artifact.</description></oembed>