The Cloudcast

SBOM and Software Supply Chain

10 snips
Apr 12, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

From CoreOS To Edgebit

  • Rob Szumski described his trajectory from Rackspace to CoreOS and now founding Edgebit to tackle supply chain security.
  • He credits CoreOS experience with exposing dependency sprawl and operational scale problems that led to Edgebit.
INSIGHT

Log4j Forced A Structural Change

  • Log4j exposed how teams cannot reliably answer where a vulnerable dependency is used.
  • Federal directives (Biden administration) accelerated mandatory supply-chain metadata like SBOMs.
INSIGHT

Diverse Team Maturity Drives Tool Gaps

  • Organizations vary from cloud-native teams with automation to fragmented groups with manual, piecemeal security.
  • SBOMs are emerging as the standard metadata to answer what's inside software and supply-chain questions.
Get the Snipd Podcast app to discover more snips from this episode
Get the app