Watch and track your favorite playlist.
Curated by: The Linux Foundation (287 videos)
Don't miss out! Join us at the next Open Source Summit in Seoul, South Korea (November 4-5). Join us at the premier vendor-neutral open source conference, where developers and technologists come together to collaborate, share knowledge, and explore the latest innovations and advancements in open source technology. Learn more at https://events.linuxfoundation.org/ Zero-Touch SBOM Generation: Secure Your Build From the Inside Out - Kaushlendra Pratap Singh & Gaurav Mishra, Siemens In the world of continuous delivery, speed is everything - but security and compliance often lag. Open-source developers and DevOps engineers face a key challenge: how do you ship fast and stay audit-ready? With SBOMs becoming mandatory under various regulatory Acts, compliance is no longer optional. This talk shows how to proactively integrate open-source tooling into your pipelines—securely, automatically, and at scale. We’ll discuss how to bring compliance into the early stages of the software development lifecycle—using open-source tools that enable zero-touch, high-quality SBOM generation. Powered by the battle-tested FOSSology toolchain, these solutions integrate seamlessly into your CI/CD pipelines, whether you’re using GitHub Actions or GitLab CI. It automates: • Dependency scanning in Python and Node.js projects • License and copyright detection • SPDX SBOM generation in JSON, YAML, RDF, or Tag formats • Seamless CI-native package scanning on every pull request Lightweight, Docker-based, and already on Docker Hub and GitHub Marketplace, this tool makes compliance and SBOM generation effortless.