انتقل إلى وضع عدم الاتصال باستخدام تطبيق Player FM !
Stacklok's Adolfo García Veytia Digs Into SBOMs and VEX
Manage episode 424208298 series 3564832
The world of software bill of materials (SBOMs) is both complex and fascinating. And few people know the SBOM community better than Adolfo García Veytia — aka Puerco — Staff Software Engineer at Stacklok. Puerco is also a Technical Lead with Kubernetes SIG Release specializing in supply chain improvements to the software that drives the automation behind the release process.
Puerco is one of the original authors of OpenVEX, an OpenSSF project working towards a minimal implementation of VEX that can be easily embedded and attested. He's also a contributor to the SPDX project and a maintainer of several SBOM OSS tools. He’s passionate about writing software with friends, helping new contributors and amplifying the Latinx presence in the cloud-native community.
- 01:04 - Puerco shares his background
- 02:21 - What SBOMs are and why they’re so important
- 06:42 - An overview of standards in the SBOM space
- 09:58 - Puerco details his work on VEX projects
- 14:05 - Puerco enters the rapid-fire portion of the interview
- 15:06 - Advice Puerco would offer aspiring open source or security professionals
- 16:12 - Puerco’s call to action for listeners
Links
24 حلقات
Manage episode 424208298 series 3564832
The world of software bill of materials (SBOMs) is both complex and fascinating. And few people know the SBOM community better than Adolfo García Veytia — aka Puerco — Staff Software Engineer at Stacklok. Puerco is also a Technical Lead with Kubernetes SIG Release specializing in supply chain improvements to the software that drives the automation behind the release process.
Puerco is one of the original authors of OpenVEX, an OpenSSF project working towards a minimal implementation of VEX that can be easily embedded and attested. He's also a contributor to the SPDX project and a maintainer of several SBOM OSS tools. He’s passionate about writing software with friends, helping new contributors and amplifying the Latinx presence in the cloud-native community.
- 01:04 - Puerco shares his background
- 02:21 - What SBOMs are and why they’re so important
- 06:42 - An overview of standards in the SBOM space
- 09:58 - Puerco details his work on VEX projects
- 14:05 - Puerco enters the rapid-fire portion of the interview
- 15:06 - Advice Puerco would offer aspiring open source or security professionals
- 16:12 - Puerco’s call to action for listeners
Links
24 حلقات
كل الحلقات
×
1 Kusari’s Michael Lieberman Talks GUAC, SLSA and Securing the Open Source Supply Chain 21:06

1 Sovereign Tech Agency’s Tara Tarakiyee and Funding Important Open Source Projects 16:47

1 Alpha-Omega’s Michael Winser and Catalyzing Sustainable Improvements in Open Source Security 27:15

1 Jack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security 23:44

1 Red Hat's Rodrigo Freire and the Impact of High-Profile Security Incidents 16:58

1 Canonical’s Stephanie Domas and Security Insight from a Self-Described “Tinkerer” 16:58

1 Intel’s Katherine Druckman and the Impact of Developer Relations 14:23

1 Dell's Sarah Evans and Lisa Bradley and Ensuring Secure Open Source Software at the Enterprise Level 16:24

1 CoSAI, OpenSSF and the Interesting Intersection of Secure AI and Open Source 22:47

1 GitHub’s Mike Hanley and Transforming the “Dept. of No” Into the "Dept. of Yes, And…” 22:43

1 CISA's Aeva Black and the Public Sector View of Open Source Security 12:13

1 Google’s Andrew Pollock and Addressing Open Source Vulnerabilities 12:16

1 Rust Foundation’s Bec Rumbul and Succeeding as a “Non-Techie” in a Tech-Heavy Industry 18:28

1 Sonatype’s Brian Fox and the Perplexing Phenomenon of Downloading Known Vulnerabilities 22:24
مرحبًا بك في مشغل أف ام!
يقوم برنامج مشغل أف أم بمسح الويب للحصول على بودكاست عالية الجودة لتستمتع بها الآن. إنه أفضل تطبيق بودكاست ويعمل على أجهزة اندرويد والأيفون والويب. قم بالتسجيل لمزامنة الاشتراكات عبر الأجهزة.