Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Trust but Verify - Uncovering the Hidden Risks of Inaccurate SBOMs With JBomAudit

Linux Foundation via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the critical security implications of inaccurate Software Bill of Materials (SBOMs) in this 39-minute conference talk from the Linux Foundation. Discover how incomplete and incorrect SBOMs can lead to overlooked vulnerabilities and wasted resources on non-existent security issues, despite their increasing adoption for supply chain transparency. Learn about JBomAudit, an open-source tool designed to automatically verify Java SBOMs by systematically assessing their correctness and completeness against NTIA minimum requirements. Examine the technical details of how JBomAudit identifies missing and incorrect dependencies, and review findings from a comprehensive analysis of over 25,000 Java SBOMs that reveals the widespread prevalence of non-compliant SBOMs and their security implications. Understand common pitfalls in SBOM generation, analyze root causes of non-compliance, and gain actionable recommendations for improving SBOM quality to better protect against software supply chain attacks.

Syllabus

Trust but Verify: Uncovering the Hidden Risks of Inaccurate SBOMs With J... Yue Xiao & Dhilung Kirat

Taught by

Linux Foundation

Reviews

Start your review of Trust but Verify - Uncovering the Hidden Risks of Inaccurate SBOMs With JBomAudit

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.