Composing the Ultimate SBOM - Creating Accurate and Modular Software Bill of Materials
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore the concept of composing Software Bills of Materials (SBOMs) in this insightful conference talk by Ivana Atanasova and Velichka Atanasova from VMware. Discover why post-build scanning falls short in producing accurate SBOMs and learn about the innovative "sum-of-parts" approach using Micro-SBOMs. Understand the importance of representing software's modular nature in SBOM creation and management. Gain knowledge on the process of "composing" multiple Micro-SBOMs into a comprehensive, high-level SBOM. Witness a demonstration of a proof-of-concept SPDX SBOM composition tool and learn about its potential to streamline SBOM consumption. Delve into the operationalization of SBOMs and the need for more modular composition techniques. Engage with the speakers' insights on enhancing compliance and security benefits through improved SBOM creation methods.
Syllabus
Composing the Ultimate SBOM - Ivana Atanasova & Velichka Atanasova, VMware
Taught by
Linux Foundation
Tags
Related Courses
SPDX 3.0 Overview - Introduction to Software Package Data ExchangeLinux Foundation via YouTube Software Part Catalog Management for Successful SBOM Creation
Linux Foundation via YouTube Our Journey to Open Source - From a Conservative Japanese Company
Linux Foundation via YouTube SW360 SBOM - Managing Vulnerability Information, SPDX Documents and Dependency Networks
Linux Foundation via YouTube OpenDataology: Fixing Dataset Licensing for AI - A Call to Arms
Linux Foundation via YouTube