Skip to main content

A retrospective on Google’s SBOM implementation

H.2213 | Day 2 | 10:00 - 10:30 | Speakers: Brandon Lum, Marco Deicas

A retrospective on Google’s SBOM implementation
A picture of a devroom at FOSDEM 2024

Stream opens at 10:00 (Europe/Brussels)

Get involved in the conversation!Join the chat

Notes

Abstract

This talk takes a look back on how we designed our Google-wide SBOM solution, exploring the technical challenges and trade-offs Google encountered while implementing SBOMs at scale, and how those decisions have aged almost 2 years out! We delve into the intricacies of generating and managing 100Ms SBOMs (~4M SBOMs/wk), ranging from design decisions in SBOM generation, trade-offs between build and analysis SBOMs, to hurdles with finding SBOMs and associating them with products.. We will talk about how we are using SBOMs outside EO14028 compliance, and the challenges around SBOM data quality, accuracy and completeness we face (software identifiers, analysis mishaps, etc.).

Attachments

Speakers

Brandon Lum
Marco Deicas

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.