From SBOM to Call Graphs: Harnessing OSS Tools to Streamline Update Impact Analysis in Cloud Services
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore a method for streamlining update impact analysis in cloud services using open-source software tools. Learn how to leverage Software Bill of Materials (SBOM), Infrastructure as Code (IaC), ctags, git, and NetworkX to address the challenges of maintaining modern cloud services that heavily rely on open-source packages. Discover techniques for simulating updates based on SBOM, extracting change history, and performing change impact analysis through call graphs. Gain insights into implementing this approach in commercial systems to expedite update decisions and define clearer verification scopes for web applications developed in Node.js and other environments with complex package dependencies.
Syllabus
From SBOM to Call Graphs: Harnessing OSS Tools to Streamline Update Impact Analys... Noboru Iwamatsu
Taught by
Linux Foundation
Tags
Related Courses
Target Rich Cyber PoorBSidesLV via YouTube The A's, B's, and Four C's of Testing Cloud-Native Applications
LASCON via YouTube SBOM Challenges and How to Fix Them
BSidesLV via YouTube The Case for Software Bill of Materials
BSidesLV via YouTube Collaborating to Improve Open Source Security - How the Ecosystem Is Stepping Up
RSA Conference via YouTube