YoVDO

OSPO-Ready Yocto Projects - The Data You Didn't Know You Had

Offered By: Yocto Project via YouTube

Tags

Yocto Project Courses Graph Databases Courses Software Bill of Materials Courses OSPO Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Discover how to make Yocto Projects OSPO-ready in this 23-minute conference talk by Alberto Pianon. Learn about a proof-of-concept that creates a dynamic representation of a Yocto project SBOM in a graph database, enabling valuable datapoints for Open Source Program Offices (OSPOs). Explore how this approach can help detect license incompatibilities, generate detailed SBOMs with file-level license metadata, and identify offending binary files in IP compliance cases. Gain insights into the process of collecting file checksums during various build stages and creating a graph database with relationships between files. Understand how this database, combined with file-level license data, allows for automated compliance checks in a Yocto environment. See a demonstration of the graph database developed by the Oniro Compliance R&D Team, including a dynamic and browseable graphic representation. Discover potential ways to implement this solution in Yocto and learn how it can significantly improve OSPO readiness for your projects.

Syllabus

OSPO-ready Yocto Projects: the data you didn't know to have, Alberto Pianon


Taught by

Yocto Project

Related Courses

Target Rich Cyber Poor
BSidesLV via YouTube
The A's, B's, and Four C's of Testing Cloud-Native Applications
LASCON via YouTube
SBOM Challenges and How to Fix Them
BSidesLV via YouTube
The Case for Software Bill of Materials
BSidesLV via YouTube
Collaborating to Improve Open Source Security - How the Ecosystem Is Stepping Up
RSA Conference via YouTube