Главная
Study mode:
on
1
Intro
2
Outline
3
Protecting the Software Supply Chain
4
Regulatory Agencies have taken notice
5
Build Images from Source Code
6
Simplified Build Flow
7
"Nutrition Information" for Software
8
Recipe Metadata
9
SPDX Generation
10
Yocto Project role in the Software Supply Chain
11
Yocto SPDX Features
12
What can we generate SPDX documents for?
13
SPDX Relationships
14
Future Improvements
15
Why do we need reproducible builds?
16
Binary output should associate with recipe hashes
17
Enabling Reproducible Builds
18
Reproducibility Testing
19
Extending Quality Assurance Test
20
Buildtools replaces Host tools
21
SPDX 3.0 and the Future
Description:
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only! Grab it Explore the critical role of Software Bill of Materials (SBoMs) in protecting the software supply chain through this 35-minute conference talk. Learn why SBoMs are essential, how to generate them using the Yocto Project, and their practical applications. Discover the unique position of the Yocto Project in describing complex supply chains, understand the regulatory importance of SBoMs, and delve into SPDX generation and relationships. Gain insights into future improvements, the significance of reproducible builds, and the upcoming SPDX 3.0 standard. Equip yourself with knowledge on maintaining comprehensive software supply chain descriptions and leveraging the Yocto Project's rich metadata for enhanced software development practices.

Software Bill of Materials (SBoM) and Supply Chain with the Yocto Project - Generating and Using SBoMs

Yocto Project
Add to list