Securing your Software with SBOMs

Опубликовано: 14 Апрель 2026
на канале: The Geek Narrator
247
5

Hey Everyone,

In this episode we talk about SBOMs, Software Supply Chain and securing software artifact. We have invited Barak Brudo from Scribe Security, to talk to us about SBOM and explain us some of the key things to understand while adopting SBOMs.

We have also covered practical examples from past vulnerabilities like colors, log4j etc and how SBOM could have helped.

Chapters:
00:00 Introduction
03:12 What is an SBOM?
06:30 What is a Software Supply Chain?
08:11 Why is it a good idea to have an SBOM for securing your software supply chain?
15:10 What does an SBOM have? Types of dependencies.
18:05 History of SBOM
21:21 Where is CI/CD does SBOM fit?
23:00 How frequently should an SBOM be created?
24:20 Examples of Vulnerability (colors, log4j) How could SBOM have helped?
29:20 How do we protect the SBOM?
32:35 Is it more relevant to open source software world?
36:20 Who's job is it? SRE? Devs? DevOps?
38:40 Is it an expensive process? Does it slow down the Software development?
40:40 What are the misconceptions around SBOMs?
44:11 What are the limitations of SBOM?
46:00 What is the future of SBOM?

Some important links:
Cyclonedx page: https://cyclonedx.org/tool-center/

Colors vulnerability: https://fossa.com/blog/npm-packages-c...

SBOM: https://www.cisa.gov/sbom

Log4J Vulnerability: https://logging.apache.org/log4j/2.x/...

Barak Brudo :   / barakbrudo  

Please subscribe to the channel and hit the like button if this episode sparked more curiosity in you.

Cheers,
The GeekNarrator