Files
mehl.mx/content/blog/2023-10-ospology-sbom-introduction/index.md

24 lines
1.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "SBOMs A Short Introduction"
date: 2023-10-10
categories:
- english
- presentation
tags:
- SupplyChain
- OSPO
- Security
headerimage:
src: firstslide.jpg
slides: https://up.mehl.mx/slides/2023-10-10-SBOMs-A-Short-Introduction-OSPOlogy.pdf
event:
name: OSPOlogy Live Frankfurt
href: https://community.linuxfoundation.org/events/details/lfhq-ospology-european-chapter-presents-ospologylive-frankfurt/
---
At OSPOlogy Live Frankfurt in October 2023, I gave an introduction to Software Bills of Materials (SBOMs) for the OSPO community. Everyone had heard of SBOMs by then they seemed ubiquitous, with shiny tools sprouting up everywhere. But what were they actually all about? What were the real use cases? And what often caused practical applications to fail? This talk aimed to provide a common understanding without the marketing-speak.
The session covered the fundamental concepts of SBOMs, explored concrete use cases where they add value, and discussed the challenges organizations face when trying to implement them in practice. Drawing from my experience working with software supply chain transparency at Deutsche Bahn, I highlighted common pitfalls and offered practical insights for OSPOs looking to make sense of the SBOM landscape.
This was part of a two-day event hosted by SAP's OSPO and co-organized with TODO Group, InnerSource Commons, LF Energy, OpenChain, SPDX, CHAOSS, and OpenSSF projects.