Utilizing Package-URLs for SBOM Management and Vulnerability Tracking
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore the critical aspects of Software Composition Analysis (SCA) and Software Bill of Materials (SBOM) management in this informative conference talk. Delve into the challenges of identifying and mapping components from supplier SBOMs to internal catalogs and policies. Learn about the importance of consistent software component identification for managing vulnerability risks. Discover how to leverage Package-URLs (PURLs) to standardize SBOM ingestion and automate policy application. Gain insights on utilizing VulnerableCode, a public database of open vulnerability data, to track FOSS vulnerabilities and VEXs using open-source tools and data.
Syllabus
What the &#% Is in That SBOM? How to Provide Users What Software Components Are... - Helio Castro,
Taught by
Linux Foundation
Tags
Related Courses
Inspecting Open Source Software Packages for Security and License CompliancePluralsight DevSecOps Fundamentals
Cybrary Effective Vulnerability Discovery with Machine Learning
Black Hat via YouTube The Devils in the Dependency - Data Driven Software Composition Analysis
Black Hat via YouTube Protect Yourself Against Supply Chain Attacks
NDC Conferences via YouTube