Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

Your SBOM Is Lying To You - Let's Make It Honest

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Discover why Software Bills of Material (SBOMs) often contain inaccuracies and learn how to create more reliable, cryptographically verifiable SBOMs in this conference talk from New York University researchers. Explore the critical role SBOMs play in improving visibility and security within the software supply chain, particularly as open-source code becomes increasingly prevalent in modern development. Examine real-world security incidents like SolarWinds (2020) and Kaseya (2021) that demonstrate the urgent need for stronger software supply chain security measures. Understand the common causes of SBOM inaccuracies, including challenges with dependency management file analysis (such as cargo.toml for Rust projects), and how these inaccuracies create vulnerabilities that attackers can exploit. Learn about SBOMit, an OpenSSF sandbox project that leverages in-toto attestations to address these accuracy issues by capturing supply chain steps as they occur in real-time. Gain insights into how SBOMit's cryptographically verifiable approach enhances SBOM accuracy, mitigates tampering risks, and strengthens overall security across the CNCF ecosystem, providing practical solutions for organizations seeking to improve their software supply chain transparency and security posture.

Syllabus

Your SBOM Is Lying To You – Let’s Make It Honest - Justin Cappos & Yuchen Zhang, New York University

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of Your SBOM Is Lying To You - Let's Make It Honest

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.