Brussels / 31 January & 1 February 2026

schedule

UD2.208 (Decroly)


Day Start End Track(s)
Sunday 09:00 17:00 SBOMS and supply chains
09 10 11 12 13 14 15 16 17 18
Sunday Welcome to the SBOMs and Supply Chains devroom!
When One Product Has Three SBOMs: Lessons from Embedded Vulnerability Management
Contextual SBOMs and impact on vulnerability management
Beyond SBOM: Integrating VEX into Open Source Workflows
From Passive Data to Active Defense: Supply Chain Policy-as-Code with Conforma
CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use
LibreOffice and Collabora Online - how we managed to automate SBOM generation for a large legacy project
Forget SBOMs, use PURLs
What is new in SPDX 3.1 which is now a Living Knowledge Graph
A semantic framework for modelling and analysing supply chains through SBOMs
Enhancing Swift’s Supply Chain Security: Build-time SBOM Generation in Swift Package Manager
Generating SBoMs for BuildStream projects

Events

Title Speakers Track Start End

Sunday

  Welcome to the SBOMs and Supply Chains devroom!
Alexios Zavras (zvr), Kate Stewart, Adolfo García Veytia, Thomas Steenbergen SBOMS and supply chains 09:00 09:10
  When One Product Has Three SBOMs: Lessons from Embedded Vulnerability Management
Marta Rybczynska SBOMS and supply chains 09:30 10:00
  Contextual SBOMs and impact on vulnerability management
Erik Mravec, Martin Jediný SBOMS and supply chains 10:00 10:30
  Beyond SBOM: Integrating VEX into Open Source Workflows
Piotr P. Karwasz SBOMS and supply chains 10:30 11:00
  From Passive Data to Active Defense: Supply Chain Policy-as-Code with Conforma
Stefano Pentassuglia SBOMS and supply chains 11:00 11:30
  CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
Viktor Petersson SBOMS and supply chains 11:30 12:00
  Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use
Max Mehl, Henry Sachs SBOMS and supply chains 12:00 12:20
  LibreOffice and Collabora Online - how we managed to automate SBOM generation for a large legacy project
Thorsten Behrens SBOMS and supply chains 12:40 13:00
  Forget SBOMs, use PURLs
Philippe Ombredanne SBOMS and supply chains 13:20 13:40
  What is new in SPDX 3.1 which is now a Living Knowledge Graph
Karen Bennet SBOMS and supply chains 14:00 14:30
  A semantic framework for modelling and analysing supply chains through SBOMs
Giacomo Tenaglia SBOMS and supply chains 14:30 15:00
  Enhancing Swift’s Supply Chain Security: Build-time SBOM Generation in Swift Package Manager
Ev Cheng, Sam Khouri SBOMS and supply chains 16:00 16:30
  Generating SBoMs for BuildStream projects
Abderrahim Kitouni SBOMS and supply chains 16:30 17:00