Skip to main content

TEA - Let the SBOM ride down the software supply chain!

H.2213 | Day 2 | 13:00 - 13:30 | Speakers: Olle E. Johansson

TEA - Let the SBOM ride down the software supply chain!
A picture of a devroom at FOSDEM 2024

Stream opens at 13:00 (Europe/Brussels)

Get involved in the conversation!Join the chat

Notes

Abstract

The SBOM file is a carrier of software transparency data. It is meant to be shared across the borders of a software supply chain, together with other artefacts like VEX files, SCITT statements, IN-TOTO attestations and much more. The OWASP Transparency Exchange API is going to be a standard for this exchange with a focus on discovery and retrieval of these objects and as a second step, a way to reach and query actual data within objects. In this talk, you will get an overview of the TEA platform, a status update of how far the project has come towards writing enough specifications and starting to test implementations.

Attachments

Speakers

Olle E. Johansson

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.