Software Bill of Materials (SBoM) and Supply Chain with the Yocto Project - Generating and Using SBoMs
Yocto Project via YouTube
Overview
Syllabus
Intro
Outline
Protecting the Software Supply Chain
Regulatory Agencies have taken notice
Build Images from Source Code
Simplified Build Flow
"Nutrition Information" for Software
Recipe Metadata
SPDX Generation
Yocto Project role in the Software Supply Chain
Yocto SPDX Features
What can we generate SPDX documents for?
SPDX Relationships
Future Improvements
Why do we need reproducible builds?
Binary output should associate with recipe hashes
Enabling Reproducible Builds
Reproducibility Testing
Extending Quality Assurance Test
Buildtools replaces Host tools
SPDX 3.0 and the Future
Taught by
Yocto Project