Explore the concept of GitBOM in this informative conference talk by Nell Shamrell-Harrington from Microsoft. Learn about the challenges of tracking dependencies in modern software development and discover how GitBOM addresses these issues. Understand the open-source, minimalist scheme that allows build tools to create compact artifact trees and embed unique references into artifacts at build time. Gain insights into how GitBOM works across different languages, environments, and packaging formats without requiring developer effort. Discover the compatibility of GitBOM with SBOMs and its potential to enhance software supply chain security. Delve into the implementation of GitBOM across various ecosystems and learn how to get involved in this innovative project.
Introducing GitBOM: Tracking Software Dependencies and Improving Supply Chain Security