Learn how to get an SBOM on Docker Desktop with a single command. Find out more here → https://dockr.ly/3mWx64O
Did you know Docker can create a Software Bill of Material (SBOM) now? There’s a new command called ‘docker sbom’ that analyzes a container image and then returns an SBOM describing its contents. It seems like everyone is talking about how important SBOMs are, but there’s not always a lot of information on how to actually create an SBOM or what you can do with that information. Docker and Anchor have teamed up to create an easy button for SBOM generation! The open source project Syft is used to inspect container content and output an SBOM — you already have everything you need to do it included in Docker Desktop and Docker for Linux.
This session will explore what an SBOM is and why it’s useful to generate an SBOM for the software you build and consume. We will also show how the ‘docker sbom’ command works as part of a short demo. Just generating an SBOM is only the start of a much larger story. We’ll show you examples of using an SBOM from ‘docker sbom’ to understand what’s in a container, how up to date the contents are, and making decisions about container images using this data.
There are also exciting future plans around Docker, containers, and SBOMs. The future will hold things such as automatic SBOM generation, including the SBOMs right in container images in the registry, and shipping SBOM content in the official container images.
Most importantly this is all part of an open source project that needs your feedback, help, and ideas. Come work with Docker and Anchor to build the future of SBOM.
• Speakers :
- Dan Luhring, Manager of Open Source Engineering at Anchore
- Justin Cormack, Chief Technology Officer at Docker
--
Join the conversation!
LinkedIn → https://dockr.ly/LinkedIn
Twitter → https://dockr.ly/Twitter
Facebook → https://dockr.ly/Facebook
Instagram → https://dockr.ly/Instagram