Salve J. Nilsen
Software Bill of Materials devroom – FOSDEM 2024
Note:
-
Salve J. Nilsen, from Oslo, Norway
-
CPAN Security Working Group
-
My offer: Open Source Supply Chain perspective
"Why should I care about SBOMs?"
"This is not my problem"
"Maybe if you pay me"
-
End users are obliged comply to new regulation and demands
- …or get fined
-
They require authoritative + up-to-date metadata, to…
- Do all the good things! (Pedigree, provenance, etc. etc.)
Source: NIST Software Supply Chain Security Guidance
- No supply chain!
- "Third party software"
- No FOSS Communities or Processes
- Your Open Source Colleagues
- Your Unpaid Open Source Colleagues
- Do NOT relegate them to the "Third party software" category — They are your partners, caring about your Open Source infrastructure and foundation!
-
Become a partner that teaches downstream users how Open Source works, without "simplifying away" people
-
Upstream devs are your partners, colleagues and friends – if you treat them so!
- Salve J. Nilsen
- Mastodon: @[email protected]