You are viewing the 2025 edition of FOSDEM. Click here to view the 2026 edition
A retrospective on Google’s SBOM implementation
H.2213 | Day 2 | 10:00 - 10:30 | Speakers: Brandon Lum, Marco Deicas
A retrospective on Google’s SBOM implementation
Abstract
This talk takes a look back on how we designed our Google-wide SBOM solution, exploring the technical challenges and trade-offs Google encountered while implementing SBOMs at scale, and how those decisions have aged almost 2 years out! We delve into the intricacies of generating and managing 100Ms SBOMs (~4M SBOMs/wk), ranging from design decisions in SBOM generation, trade-offs between build and analysis SBOMs, to hurdles with finding SBOMs and associating them with products.. We will talk about how we are using SBOMs outside EO14028 compliance, and the challenges around SBOM data quality, accuracy and completeness we face (software identifiers, analysis mishaps, etc.).
Attachments
Speakers
Brandon Lum
Marco Deicas
Links
External Links
Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.
