ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

SPDX SBOM Format Deep Dive: Compliance, Security & the Future of Software Metadata

SPDX SBOM format

SPDX 3.0

Software Bill of Materials

Kate Stewart

Gary O’Neall

Linux Foundation SPDX

SBOM compliance

open source license audit

software transparency

CI/CD security

Zephyr SBOM

Yocto SBOM

Linux kernel SBOM

supply chain security

open source governance

software safety standards

Автор: Nerding Out With Viktor

Загружено: 2025-01-16

Просмотров: 131

Описание: What makes the SPDX SBOM format a cornerstone of modern software transparency? In this episode of Nerding Out with Viktor, host Viktor Petersson is joined by Kate Stewart (Linux Foundation) and Gary O’Neall (SPDX contributor) to explore how SPDX evolved from a license compliance tool into a critical standard for security, supply chain management, and regulatory readiness.

They discuss real-world use cases from Zephyr, Yocto, and the Linux kernel, explain the challenges of circular dependencies and incomplete metadata, and walk through how SPDX is adapting to safety-critical systems and CI/CD pipelines. You'll also hear how global regulation from NIST to the EU CRA is pushing SBOM adoption forward.

Whether you're an open source maintainer, security engineer, or developer navigating compliance, this episode unpacks the complexity of SBOMs in a practical, accessible way.

You’ll learn about:
*How SPDX started and why it matters today
*SPDX’s shift from licensing to full software transparency
*Build-time SBOM generation in embedded systems
*How graph-based modeling helps map software relationships
*Challenges with circular dependencies & CI/CD pipelines
*SPDX’s role in meeting global regulatory requirements

Timestamps:
00:00 - Intro & guest welcome
03:00 - The origin of SPDX in licensing & M&A
08:00 - SPDX use cases beyond license compliance
12:00 - Build-time SBOMs: Zephyr, Yocto & embedded use
18:00 - Graph modeling, circular dependencies & known unknowns
25:00 - SBOM completeness, CI/CD integration & SPDX 3.0
32:00 - SPDX license list, tooling gaps & cleanup efforts
38:00 - Kernel SBOMs & working with the Linux Foundation
44:00 - Regulatory push: CRA, NIST, PCI DSS & more
48:00 - Community-driven development & contributing to SPDX

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
SPDX SBOM Format Deep Dive: Compliance, Security & the Future of Software Metadata

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]