Files
mehl.mx/content/blog/2023-10-ospology-sbom-introduction/index.md
2026-02-22 11:32:37 +01:00

1.4 KiB
Raw Blame History

title, date, categories, tags, headerimage, slides, event
title date categories tags headerimage slides event
SBOMs A Short Introduction 2023-10-10
english
presentation
SupplyChain
OSPO
Security
DeutscheBahn
src
firstslide.jpg
https://up.mehl.mx/slides/2023-10-10-SBOMs-A-Short-Introduction-OSPOlogy.pdf
name href
OSPOlogy Live Frankfurt https://community.linuxfoundation.org/events/details/lfhq-ospology-european-chapter-presents-ospologylive-frankfurt/

At OSPOlogy Live Frankfurt in October 2023, I gave an introduction to Software Bills of Materials (SBOMs) for the OSPO community. Everyone had heard of SBOMs by then they seemed ubiquitous, with shiny tools sprouting up everywhere. But what were they actually all about? What were the real use cases? And what often caused practical applications to fail? This talk aimed to provide a common understanding without the marketing-speak.

The session covered the fundamental concepts of SBOMs, explored concrete use cases where they add value, and discussed the challenges organizations face when trying to implement them in practice. Drawing from my experience working with software supply chain transparency at Deutsche Bahn, I highlighted common pitfalls and offered practical insights for OSPOs looking to make sense of the SBOM landscape.

This was part of a two-day event hosted by SAP's OSPO and co-organized with TODO Group, InnerSource Commons, LF Energy, OpenChain, SPDX, CHAOSS, and OpenSSF projects.