Securing Open Source With SBOM: From Visibility To Trust - Heejo Lee, Korea University
Securing Open Source With SBOM: From Visibility To Trust - Heejo Lee, Korea University
A Software Bill of Materials (SBOM) is a comprehensive inventory of all software components within a product, including open-source software (OSS). However, applying SBOMs to OSS projects presents several technical challenges, such as identifying modified OSS components, analyzing third-party dependencies, and verifying security vulnerabilities. In this talk, we introduce IoTcube.net, an automated platform for SBOM generation and vulnerability verification, which integrates with OpenSSF Guac and OpenVEX to enhance the usability and interoperability of SBOM documents. We then propose collaborative initiatives to strengthen OSS security such as standard representation of OSS and licenses, vulnerability management of unpatched OSS components, and recommendation of SBOM management followed by a discussion on potential joint efforts.
The Linux Foundation
The Linux Foundation is a nonprofit consortium dedicated to fostering the growth of Linux and collaborative software development. Founded in 2000, the organization sponsors the work of Linux creator Linus Torvalds and promotes, protects and advances the L...