Brussels / 31 January & 1 February 2026

schedule

SBOMS and supply chains


09 10 11 12 13 14 15 16 17 18
Sunday Welcome to the SBOMs and Supply Chains devroom!
When One Product Has Three SBOMs: Lessons from Embedded Vulnerability Management
Contextual SBOMs and impact on vulnerability management
Beyond SBOM: Integrating VEX into Open Source Workflows
From Passive Data to Active Defense: Supply Chain Policy-as-Code with Conforma
CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use

Read the Call for Papers at https://lists.fosdem.org/pipermail/fosdem/2025q4/003702.html.

Event Speakers Start End

Sunday

  Welcome to the SBOMs and Supply Chains devroom!
Alexios Zavras (zvr), Kate Stewart, Adolfo García Veytia, Thomas Steenbergen 09:00 09:10
  When One Product Has Three SBOMs: Lessons from Embedded Vulnerability Management
Marta Rybczynska 09:30 10:00
  Contextual SBOMs and impact on vulnerability management
Erik Mravec, Martin Jediný 10:00 10:30
  Beyond SBOM: Integrating VEX into Open Source Workflows
Piotr P. Karwasz 10:30 11:00
  From Passive Data to Active Defense: Supply Chain Policy-as-Code with Conforma
Stefano Pentassuglia 11:00 11:30
  CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
Viktor Petersson 11:30 12:00
  Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use
Max Mehl, Henry Sachs 12:00 12:20