Главная
Study mode:
on
1
Intro
2
Agenda
3
Compliance issues Supplier Product vendor
4
Security issues
5
Issues in software development Compliance issue Understand all the components used Comply with the software license
6
What is SBOM? OSBOM : Software Bill of Materials
7
SBOM in Life Cycle
8
SBOM Implementation Example
9
Solution for creating SPDX
10
Using spdx with Yocto Ometa-spdxscanner Generate a SPDX file by calling FOSSology or ScanCode Toolkit
11
Systems that solve problems
12
Example of system use
13
CodeChecker - Settings
14
PostgreSQL - Settings
15
FOSSology - Settings
16
cve-check & build
17
CodeChecker - Results
18
FOSSology - Results
19
SPDX files
20
Summary & Future work Summary OSBOM is effective for solving software development problems
Description:
Explore license compliance and security management strategies for embedded systems in this 30-minute talk by Yoshihisa Morizumi. Delve into compliance issues faced by suppliers and product vendors, and examine security concerns in software development. Learn about Software Bill of Materials (SBOM) and its implementation throughout the product lifecycle. Discover tools and systems for generating SPDX files, including integration with Yocto Project. Gain insights into using CodeChecker, PostgreSQL, and FOSSology for effective problem-solving in embedded software development. Understand the importance of SBOM in addressing software development challenges and ensuring compliance with software licenses.

License Compliance and Security Management for Embedded Systems

Linux Foundation
Add to list
0:00 / 0:00