Open Community Experience (OCX)

Generating SBOM: Understanding the why, mastering the how & learning from Eclipse Kura's experience

40:28 · 21 Apr 2026 – 23 Apr 2026 · YouTube

About this talk

This talk, presented by Mattia Dal Ben from Eurotech S.p.A. and Ioana Iliescu from the Eclipse Foundation, explores the significance of software bill of materials (SBOMs) in enhancing software supply chain security. It examines the complexities of modern software dependencies and highlights SBOMs as essential tools for improving vulnerability tracking and incident response. The speakers discuss the challenges organizations face when adopting SBOMs, including integration into CI/CD pipelines and managing differing standards like SPDX and CycloneDX. A case study from Eclipse Kura illustrates practical experiences with SBOM generation and implementation, showcasing how these tools can optimize workflows and support continuous vulnerability monitoring.