Finance Certifications Goldman Sachs and Amazon Teams Trust
PowerBI Data Analyst - Create visualizations and dashboards from scratch
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This session explains how SBOMs support vulnerability resolution and software supply chain security, including how they compare with dependency scanning. Practical examples use Syft to generate and transform SBOMs, and Grype and bomber for vulnerability scanning.
Syllabus
[VDIASI23] - Olimpiu Pop & Steve Poole - A radiography of a SBOM vulnerability scanner
Taught by
Devoxx
Reviews
4.0 rating, based on 1 Class Central review
Showing Class Central Sort
-
This course by Olimpiu Pop and Steve Poole is a masterclass in software supply chain security. Instead of repeating marketing buzzwords, the instructors provide a brilliant, "X-ray" analysis of how SBOM vulnerability scanners actually function under the hood. I especially loved the clear breakdown of why legacy CPEs fail and why Package URLs (PURLs) are vital for tracking deep, transitive dependencies. The pace is incredibly fast, but the highly engaging instructors break down complex DevSecOps topics with refreshing humor. It is a must-watch for any developer or security engineer aiming to defeat CVE alert fatigue!