Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Enhancing SBOM Generation - Filling the Gaps to Make Actionable SBOMs

Linux Foundation via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore advanced SBOM (Software Bill of Materials) generation techniques in this 38-minute conference talk from the Linux Foundation. Learn how to move beyond basic SBOM creation tools like Syft or Trivy to produce truly actionable SBOMs that provide meaningful value to downstream users. Discover the comprehensive work conducted by a CISA SBOM Community Tiger Team who developed SBOM Generation Reference Implementations across multiple programming languages and deployment scenarios. Examine the distinct phases of SBOM generation and understand how each step contributes to creating more robust and actionable documentation. Master techniques for expanding the SBOM authoring process to integrate multiple data sources, enhance metadata accuracy, and customize workflows that align with evolving security frameworks while maintaining tool interchangeability and data integrity. Gain practical insights into implementing SBOM generation within CI/CD pipelines using GitHub and GitLab, supporting diverse programming languages, and ensuring interoperability with both CycloneDX and SPDX formats. Address critical ecosystem challenges including supplier identification, license consistency, and benchmarking completeness to create SBOMs that truly serve their intended security and compliance purposes.

Syllabus

Enhancing SBOM Generation: Filling the Gaps To Make Actionable SBO... Ian Dunbar-Hall & Gary O'Neall

Taught by

Linux Foundation

Reviews

Start your review of Enhancing SBOM Generation - Filling the Gaps to Make Actionable SBOMs

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.