Your SBOM Is Lying To You - Let's Make It Honest
CNCF [Cloud Native Computing Foundation] via YouTube
Build GenAI Apps from Scratch — UCSB PaCE Certificate Program
Get 20% off all career paths from fullstack to AI
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Discover why Software Bills of Material (SBOMs) often contain inaccuracies and learn how to create more reliable, cryptographically verifiable SBOMs in this conference talk from New York University researchers. Explore the critical role SBOMs play in improving visibility and security within the software supply chain, particularly as open-source code becomes increasingly prevalent in modern development. Examine real-world security incidents like SolarWinds (2020) and Kaseya (2021) that demonstrate the urgent need for stronger software supply chain security measures. Understand the common causes of SBOM inaccuracies, including challenges with dependency management file analysis (such as cargo.toml for Rust projects), and how these inaccuracies create vulnerabilities that attackers can exploit. Learn about SBOMit, an OpenSSF sandbox project that leverages in-toto attestations to address these accuracy issues by capturing supply chain steps as they occur in real-time. Gain insights into how SBOMit's cryptographically verifiable approach enhances SBOM accuracy, mitigates tampering risks, and strengthens overall security across the CNCF ecosystem, providing practical solutions for organizations seeking to improve their software supply chain transparency and security posture.
Syllabus
Your SBOM Is Lying To You – Let’s Make It Honest - Justin Cappos & Yuchen Zhang, New York University
Taught by
CNCF [Cloud Native Computing Foundation]