Learn Backend Development Part-Time, Online
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
Learn how to integrate two OpenSSF projects, Zarf and GUAC (Graph for Understanding Artifact Composition), to enhance software supply chain security in both connected and disconnected environments in this 22-minute conference talk. Discover how Zarf enables secure packaging and deployment of software while GUAC aggregates and contextualizes Software Bill of Materials (SBOMs) to improve software provenance and risk assessment. Explore the practical benefits of combining these tools, including secure SBOM packaging and transport capabilities, automated SBOM generation and enrichment processes, and improved traceability and risk assessment specifically designed for airgapped environments. Gain actionable insights into strengthening your organization's supply chain security posture and meeting emerging compliance requirements through the strategic use of these complementary OpenSSF technologies.
Syllabus
Enhancing Supply Chain Security: Integrating Zarf and GUAC for Seamless SBOM Genera... Brandt Keller
Taught by
OpenSSF