Brussels / 1 & 2 February 2025

schedule

Software Bill of Materials (SBOM)


09 10 11 12 13 14 15 16 17 18
Sunday Welcome to the SBOM devroom
SBOMs and cryptographic algorithms: status and next steps
Intro to the SPDXFunctional Safety Model
A retrospective on Google’s SBOM implementation
SBOM journey for an Open Source Project - Apache NuttX RTOS
Lessons learned from integrating SBOM in a supply chain
A Novel Ontology for Enhanced SBOM Data Modeling with TOSCA
Discover Dependency License Information Using SBOMs and ClearlyDefined
Persistent Copyright & Licensing Information in Client-side JS, CSS &sim. (proposal)
The Breadth and Depth of SBOMs
Struggles with making SBOMs for C apps
TEA - Let the SBOM ride down the software supply chain!
BASIL an open source tool that supports requirements traceability with design SBOM
Where in the OSS Supply Chain do SBOM attributes come from?
Implementing a triage process supporting all flavours of VEX
Airflow Beach Cleaning - Securing Supply Chain
Connecting SBOMs with OSS Project Health to Better Understand Dependencies
Towards Quality SBOMs: the OpenChain Telco SBOM Guide
Open Discussion

Read the Call for Papers at https://lists.fosdem.org/pipermail/fosdem/2024q4/003605.html.

Event Speakers Start End

Sunday

  Welcome to the SBOM devroom
Alexios Zavras (zvr), Adolfo García Veytia, Kate Stewart 09:00 09:10
  SBOMs and cryptographic algorithms: status and next steps
Agustin Benito Bethencourt 09:10 09:30
  Intro to the SPDXFunctional Safety Model
Nicole Pappler 09:30 10:00
  A retrospective on Google’s SBOM implementation
Brandon Lum, Marco Deicas 10:00 10:30
  SBOM journey for an Open Source Project - Apache NuttX RTOS
Alin Jerpelea 10:30 11:00
  Lessons learned from integrating SBOM in a supply chain
Sébastien DOUHERET 11:00 11:20
  A Novel Ontology for Enhanced SBOM Data Modeling with TOSCA
Alexios Zavras (zvr) 11:20 11:40
  Discover Dependency License Information Using SBOMs and ClearlyDefined
Jeff Mendoza, Qing Tomlinson 11:40 12:00
  Persistent Copyright & Licensing Information in Client-side JS, CSS &sim. (proposal)
Matija Šuklje 12:00 12:20
  The Breadth and Depth of SBOMs
Michael Lieberman 12:20 12:40
  Struggles with making SBOMs for C apps
Chris Swan 12:40 13:00
  TEA - Let the SBOM ride down the software supply chain!
Olle E. Johansson 13:00 13:30
  BASIL an open source tool that supports requirements traceability with design SBOM
Luigi Pellecchia 13:30 14:00
  Where in the OSS Supply Chain do SBOM attributes come from?
Salve J. Nilsen 14:00 14:30
  Implementing a triage process supporting all flavours of VEX
Anthony Harrison 14:30 15:00
  Airflow Beach Cleaning - Securing Supply Chain
Jarek Potiuk, Munawar Hafiz, Michael Winser 15:00 15:30
  Connecting SBOMs with OSS Project Health to Better Understand Dependencies
Georg Link 15:30 16:00
  Towards Quality SBOMs: the OpenChain Telco SBOM Guide
Marc-Etienne Vargenau 16:00 16:30
  Open Discussion
Alexios Zavras (zvr), Adolfo García Veytia, Kate Stewart 16:30 17:00