About this talk
This talk discusses open source-based supply chain management at scale, presented by experts from Bosch involved in the OpenChain project. The speakers address the challenges posed by regulatory non-functional requirements that create a gap between development teams and regulatory officers. They emphasize the necessity for collaboration among different stakeholders to bridge this gap and effectively manage software components throughout various levels of an organization. The session includes insights into the importance of automation, tools, metadata, and team collaboration for achieving effective compliance and risk management. They also highlight the development of a capability map that allows organizations to align their approaches to open source management and share common solutions through a community-driven platform.
Full transcript
[music] Hello, welcome everybody to our talk today open sourcebased supply chain management at scale. So my name is Marca Kutzman from Robot Boschkin Baha. I'm software management open source consultant and >> yeah uh again uh I'm Nico uh really enjoyed it. Uh you joined our session similar to Marcel we are teammates in the same team. So I do software and open source management in Bosch and a
member of the Bosch also. >> Yeah. What is perhaps interesting for the community we're not only Bosch but we're also heavily involved in the open chain project. So I'm board member, Nicola is ambassador. So that you get a little bit the context and uh the title mentioned at scale. So we thought okay this time we would start with a big picture. What what do we consider as
a context? So what is um the the the context where we want to do open source management based on open source at scale. So originally uh um there were development teams that had nice ideas that um develop products, right? Um I called it a specifically product with digital elements. Uh you guess why I guess uh and everyone was happy I would guess. Um but then there came
all those regulations. The regulations came with non-functional requirements. uh and that uh forced or still forcing those teams um to care about software management. Yeah. So they need to check their digital elements and therefore we also need methods processes to to turn unclear digital elements into clear digital digital elements. Um and what is now uh important for the overall picture the context is um the ones who
define those um non-functional requirements typically regulators officers quality managers that have also their context. They're very um knowledgeable in their area but typically as we observe do not talk the same language than the development team. So there's a big gap in between then and we need to bridge that gap and we need to translate sometimes those non-functional requirements um to the teams. So that's one point. The
other point uh is that um typically those officers especially in big organizations they do not only want to know everything about one project but also about everything that happens in the company. And therefore we came up with this uh third role that was not there uh earlier that is those representatives. So you might all have that in your organizations. So security officers, quality manager partners, cyber security
partners. Um and why is this relevant? Because um here the needs of the uh upper right parts they at the end they only want to have a dashboard where everything is green, right? And then they're happy. The development teams they are happy if they can script everything away or workaround. So typically we want to avoid that workaround. So um ideally then u they can automate it and
keep the coders coding. Um we had started this as a community more yeah I think we are now at least in the 10th year that we do this um in the context of open chain. Uh started this with copyrights licenses. the ISO 5230. Um then came to cyber security vulnerabilities. I think everyone knows today about that ISO 18974 and um as it is called the um regulation
tsunami uh uh started few months ago. So we we need to expect also others with AI etc etc. Um and what we observed is that well tooling automation is cool also those dashboards are good but at the end you also need more than just tools. So you need meta data also you need trainings you need knowledge. So subject matter knowledge, technical knowledge, you need teams that develop
and maintain and and operate things and partially also do manual support. And uh this is as the open chain touring group we then came up with this capability map so that we said okay we cannot we started with a tool map and then finally ended up in a capability map because it's potentially not always a tool that we talk about. Um and coming back to the context
um so at scale what does that mean? So you have all those three different levels and each of those stakeholders have different needs. The thing is and I guess if I look into the room each of us has different contexts. So either we operate in different markets we have we are operating in different countries. We have different risk appetites. We have different software technologies. You name it.
I just listed some of those boxes here and um at scale is then very very complex, right? Because uh you cannot have one thing that fits all and this is why we came up then um with another idea and discussed okay we should then not collaborate heavily on the solutions but in this case we should start also collaborating on the problems. So collecting use cases and uh
then when we match each other and say okay we have the same problem space let's work together let's collaborate on the solutions or or ideally there is already a commu solution out there of someone and we can just reuse some often we we just didn't know about each other and there was this matchmaking not done and and therefore also as our first call to action so we
would love in the project also to have your problems, your use cases so that we can also uh add them to our project and and check and uh how we can do the further matchmaking and um how we did this is uh because that is then also challenging. of all, how can we um know or how can how can I search then if I know someone uh
or if someone else has the same use case and um so the idea came up um yeah for at least for the presentation I thought when I looked at my browser um that I didn't use at that time okay there is another uh online shopping uh history uh where I thought yeah that Perhaps not bad because also for online shopping you also need to first check okay
are you men, women, kid whatever then filter filter filter until you know okay now I have exactly the same point where said okay and here for this I need a solution so here I need socks or underwear or whatever and uh now if you can transfer this picture to what I just said on the big picture that is so the the initial idea we say okay if
we have a system where we can match each other say okay I am uh in the cloud sector working for financial uh um in Java Maven whatever etc etc you name it you can uh come down and then ideally you find already there use cases that are interesting for you um the whole setup isn't exactly split in those um three levels that I showed but you see
four levels um so here we have uh the highest level added as we are the open chain community. We also care about the full supply chain. So the uh it's very small. So you see it later a little bit bigger where we said okay ideally we have um also a level where we talk about what happens along the supply chain because some of the discussions need to
be done on a u that you cannot solve on your own but that you need to solve as a full supply chain. So here we would have the supply chain level level below then the portfolio level where you can then just take one out uh one link out of this um of this supply chain. If you take an organization, that organization might have several products in their
portfolio and then you can go one level down say okay let's take one of those products out of the portfolio and look at that and latest is the the lowest level then okay now let's look in this product that might have civil deliverables components you name it and then look at the component level each of those levels uh once you know okay uh are you more on
the upper right side or in the lower left side um uh has the standard structure where we see okay there's a problem space where we collect the use cases then we try to have some common wording uh architecture that well we need some common semantics about what is uh um yeah like in the closest case okay u uh a jumper pants socks etc uh and then finally
then also um the documentation about existing um um blueprints um and how that look like. So um so we standardize we just use the um um the use case description formal as a product owner or product responsible I want to have a blueprint for software component life cycles. So that whatever you want. Um and there this would be found in the product uh software management products or
service level because well have a product owner or product responsible and then uh you can find then um there if you want already one blueprint. So it's it's still very uh basic. So therefore also we uh need to to get more contributors uh they would find a component life cycle process right so we can just pick it and and reuse it um if you have exactly that
many um second example so as a security manager I think that is uh also very um very popular today I want to have a product dashboard so that I can continuously monitor um the security status so here in this case we would on be on the portfolio level because we want to um yeah monitor all your products, right? Uh so such a use case would find on
the portfolio level and here um we would see then already some proposed uh blueprints like with OASP dependency track but also now we have those features in the or server. Uh and then you can click there and find out okay does that fit this blueprint fit because we do not claim to have the solution for everything. Um and that that fits because you saw that we all
uh differentiate that heavily in in so many places that you might fight with legacy in your infrastructure. You cannot change things from one day to another. So you just need to live what you have. But nevertheless we we we share the same problem space. So nevertheless we could then also exchange how we did do how did we do it? How can you do it etc. So and
that's is what I think is the strength of our community and um with that I would hand over to Nicola to uh go into deeper uh with one specific use case. >> Okay. Yeah. Uh so um we're through with the history lesson but I'll just add a few um like an extra comment of how we started with uh the supply chain simulation. So Marcel already mentioned that
um as the open chain community we're focused on open and secure supply chain but also uh both of us being part of the BCH hospital we have some let's say internal cases of of people trying to to figure out internal issues in their builds in their projects u some results popping up trying to reproduce them and all that. So this was like one of the many um
instances that we have or use cases to start building this this concept for the supply chain simulation. So people could actually >> of the benefit or curse if you want of a >> talk about benefits you have your own your own internal supply chain. uh we'll talk about the overall benefits regarding of uh whatever you are uh in the link uh of the supply chain or you
have a uh fully built supply chain yourself. Uh so um we will really focus on the representation or two different simulation cases when what you can see here is the right case is a basically a supply chain that is technically broken. So there is an appropriate use of of open source or the clear coded uh left side where you have uh basically a regular use of open
source and the different actors within all the different supply chain uh supply chain links um to represent uh whether you're integrator whether you're a manufacturer and all the different uh parts of the supply chain. So uh this would actually allow us to have uh different links in the chain to have different contexts uh contexts different use cases and different problem spaces. Something that Marcel really uh try
to to highlight is uh everyone has uh different or in many cases quite similar problem spaces. We just don't know about uh them. So we cannot really uh try to resolve them together. Uh and from here the benefits uh that we already mentioned there are a lot of different benefits that we try to highlight for uh why uh we have this supply chain simulation available and the
tools that are part of the the simulation itself whether you can use it for trainings for showcasing of like what we do now whether you want to uh test your tool chain infrastructure whether you can uh benchmark tools that you use on a daily basis or regular part of your uh let's a delivery process. Uh whether it's a reference for discussions part of these conferences that we
attend regularly. This is like one of the main topics that we we usually discuss uh as part of the tooling work group. Uh and from there on we actually uh go to the setup uh end to end and how it looks in in principle. So on the left side you have uh the first um supply chain link or the the first main actor is uh the representation
of the software vendor. So on the left side you have the typical upstream project. We will talk about our uh dummy projects represent and on the left side is basically the simulation of a software vendor. in the middle uh you have uh here the clear example with with or server and we'll do u more extensive reference uh to that later and then the manufacturer on the right
side where you have again different tools representing the the manufacturer whether that's uh the dependency track that's already mentioned whether it's a software 360 uh eclipse duko now or >> because yeah there is this discussion of how to to properly pronounce it past few weeks and different events uh and uh yeah these are the main uh actors as we call them as part of uh this simulation
uh showcase uh and uh this is already an existing blueprint so this is something that's added to the Eclipse of guidance structure so you have the problem space you have generic software supplying chain infrastructure and all the the blueprints that are part of of this particular um blueprint uh all the different information, different parts, step-by-step guide on on how to do the simulation uh yourself. Uh we
will go on a I would say surface level high level high level explanation of uh what the simulation really is, what tools are used and uh everything that you can do also yourself. Um as Marcel already mentioned, there is a lot of information, a lot of uh links that are included in the slides and this is something that we will provide later. So you can basically use
all the documentation and all the links that we left for you. Not just the QR codes but uh all available documentation references to previous demos, showcases and all that based on uh the different tools that are used. Uh and here we have actually mapped what we've used as an example to this uh end toend setup. uh as I've already mentioned on the left side we have the
demi repositories uh as uh the uh second actor or uh someone um playing the role of integrator uh in a way we have the the octet test instance of of the or server uh uh I already will will me mention sebastian and uh the reference to to the matrix channel of the whole eclipseopsis [clears throat] project where you can find uh people that are the core maintainers
of of the reference implementation of the tooling and uh they can help you or you can contribute. Uh we have the sepia docker something that I presented almost a year ago uh that is part of a again open chain open source project that was kicked off by bosch and it's technically a validator uh asbomb validator um it has also other features but we won't go into that
much detail about them again when the time comes to uh add more details about sepia specifically there is also link to to the real showcase that I've did uh with that uh at the open source summit last year in uh Amsterdam. Um we've already mentioned uh Eclipse uh the suku basically an asbomb portal something that you can use to again uh simulate a way of uh uh
just managing and maintaining uh asbombs and then the dependency uh track docker >> it should still be yellow because that's not available publicly unfortunately. >> Yes. Yeah, that is uh as I said, yeah, that's one of the potential several blueprints that we have at the moment and it's the focus of what we're showcasing today. >> We do not claim that's the only one. So also if we
get some scan code io blueprint or whatever you name it um we have so many fosite uh uh cool open-source solutions available and that's also what we try to promote then right that people get more aware look you do not need to use vendor commercial vendor solutions because here we have really a publicly available running um simulation that shows that runs end to end and you do
not have to pay any money. You can just use it. >> Yeah. If I go back, uh the whole point of of this end to end setup is to actually showcase the availability of the open-source tools that are part of the community and something that someone could just start and use and rely on uh proprietary tooling. that does this does not include a potential blueprint that is
a mix of open source and proprietary tools or any other possible mix and matches of of tools for your particular use case. This is something that we've already mentioned. If you contribute uh let's say a problem that you have that we can map in the in the problem space and then we can map it to a blueprint then we can have another example like that that we
have a mix of of different tools that are used for for a possible different uh simulation or an example of an existing supply chain that it's being >> when we had of often in the beginning I still remember but that is already decade ago I have to admit um but that we have from our supply chain suppliers that said Okay. Well, you as a big corporation, you
can you can uh have this very um expensive licensed propriety solutions to do this. And this sounded uh and and we're potentially a smaller supplier. We we're not allowed to do or we cannot afford that. Uh so that sounded like a kind of excuse. And uh this is also one of the uh ambitions that we had together with semens, with SAP, with all the others um to
um to provide stuff that is really fully open available and sorry uh supply chain no excuse. It's all it's all there. It's all open source. >> Okay. And uh back to the simulation itself. Uh so we start with uh our first main actor and that's the software vendor. So as you remember to two two slides ago basically um you have uh the list of the dummy repositories
that we have currently available. It says three to four technically we have three fully working uh forked dummy repositories. Four is in preparation. So um there is uh uh this uh scenario that we use them as I even mentioned when I started it's whether to reproduce issues that we have internally or just testing them inest ingesting vulnerability all of these different benefits that we mentioned you can
basically use the dummies and Marcel and I actually had a presentation at the previous OCX as far as I remember that we did uh the kickoff presentation of the the dummies as a whole and 14 haded as a list of prepared dummies at the time. That list is slowly but surely getting larger. So we're trying to uh communicate with people to contribute uh examples for for projects
that we can use as uh in detail. Um, Marcel and I are typically the the contact uh people that that we try to uh get this thing going, but we have also other uh colleagues within our company that are uh also helping with with trying to establish uh new dummies. also benefits. we go back to whether you use it as a base for benchmarking, whether you use
it for showcasing or testing, whether you use it to uh just play around uh with it, whether you use it for uh we even had that idea and I think that's something that's in action to base a training material on them for new people whether they're in university or still even in high school to to really get the grips of what open source is, what is a
basic project. uh the sort of I would say the disadvantage what we initially started with is was based on like uh hello world plus kind of uh projects that are really really basic. So they don't have any dependencies they don't have uh the typical information that we need in a way to to test an SC tool as SCA tool or trying to benchmark it. So in a
way this is why we uh started leaning into more complex than the typical hello world plus kind of of a project and the the overall benefit it's not just for for tool vendors it's not just for regular users it's also for the expert community. So you can see all the different benefits that we've already mentioned a lot but whether it's benchmarking whether it's uh testing irregular behavior
whether it's reproducing issues there are a lot of lot of benefits that we've mapped out here and I won't go into that much detail about them specifically about the uh history of of how we started first we forked um the go repository then the second one that we added to the This was a Java Maven project and then a JavaScript. You can see an uh extract from
uh the usage of the I would say the most common languages and basically JavaScript Java word let's say on the top of uh the list. Uh we are currently in the process of adding this uh a formentioned four uh dummy to our list that is basically a python uh python dummy and uh the only precondition for us is in a way is that uh all of these
projects are maintained by the upstream project. So that is I would say the the main precondition that we have. So their life projects in a way and they have proper documentation. So especially for someone that is rather new to the topic, it's easier for them to understand what that project's all about >> and also having back the link to the specialists to the experts because yeah well
obviously we also came up with the idea well we could just generate AI generate some dummies but then we would lose exactly this this benefit to have this backlink upstream >> and the next call to action is that we need you and I've already mentioned that but this is like the time for uh actually to do this goal is that you can help us to find upstream
projects that we could use as a base for uh the dummies and that we can cover the whole landscape. We can map different issues or different problem space uh issues that we've mapped in the documentation of of Eclipse guidance to then map to potential blueprints thus helping uh the overall uh open source community to to tackle common issues that we all have and in addition to that
if you could directly contribute uh to even to the existing dummies that we have currently in existence from the uh Java Maven dummy. We have a specific branch for um basically testing and showcasing the injection of of work for aj uh 2.14. If we have time at the end, I think that we could actually do a live demo. Uh let's see how we fare with time. But
but generally speaking here, we we focus on you. We ask you to contribute your your cases, it showcases and um test cases. Uh specifically this link here just uh uh represents uh the guidance that we left in the read me on you uh for you how you can add these showcases or test cases to the existing projects that we have as uh basically a branch and how
then we can tackle it together or you can do all the stuff yourself and document it and then we just add it as an existing blueprint. So interesting cases with transitive dependencies, ideally very complex that really bring our tooling to the to the edge and where you can really run the tool on and or you you use it and try it at home with your tooling or
commercial tooling and then that you can see okay it works or not. >> Okay. And then we move to main actor number two that's the software integrator. Uh we've already mentioned uh the octet or server uh and we have Sebastian in the room but I will um we'll talk about this uh later on. Um he provided Marcel with a um access to the test instance to be
part of uh to be part of uh the simulation uh for for basically for this. And when Marcel did a a live demo as part of uh a monthly meeting I think back in December uh last year as part of uh monthly meeting of the open chain tooling work group. So we also have a link to that uh in the next slide. So this is exactly what
I'm um what I'm mentioning. Um so specifics about this is uh we you here again you have the link to um the open chain project and where the demo was uh done link to the specific documentation also link to the eclipse of opsis matrix channel this is where you can find sebastian uh Martin uh Sebastian uh and all the core maintainers of of or server basically the
I'll say the tool behind and uh DSCA that we used for for this uh A bit uh of details about what is open source review toolkit and what it's basically uh made of or what you use it for. So, so the the the virtual the virtual uh conveyor belts and the different uh we call it phases when we typically use it but these are basically a different
tools part of uh the analysis that is done and then the output of the tool but I won't talk about this because tomorrow uh they are actually in the room and you can find them again um tomorrow Sebastian and Martin they do have a talk that goes on the technical level and what is actually or server or eclipseopsis or server all about. So I'll urge you to
join their talk tomorrow and if you're interested in the uh technical bits of of uh Eclipseopsis or server um please join their talk tomorrow. Uh and the last uh main actor of the supply chain this is the manufacturer. So uh dependency track or Eclipse disco could be used basically to uh simulate the manufacturer you uh being the OEM you being someone that is maintaining the information that
is produced or the reports that are produced by your SCA tooling. Um we go again into a bit of detail about later uh about this. So if you need access to a dependency track um currently there is not available a dependency track uh public test instance but I'll say like a huge quotation mark uh yet uh you can use a docker setup for that or uh as
I've already mentioned portal to basically manage uh the generated or produced sbomb by your SCA tooling uh link to uh how to use the tool and what to do um with it is there in in the details uh direct YouTube link for that a few words uh about sepia the this is was part of let's say in between this is not we don't consider it like a
a standalone uh actor in the supply chain simulation but it's more or less uh an additional tool that we use uh internally ally but it's has been an open- source project in about an year now. It was open sourced in April last year. Uh again in the details you'll find a link for the deep dive or the detailed showcasing that we did about this last year and
what SPA is actually about. Just a few things from from currently available features. You can edit sbombs. The the main validation is done based on uh predefined schema that you have. Uh it works with cyondx. It works with uh spdx and you generally choose what schema to use and then you validate against it. If you have invalid results, you can directly edit them uh and then revalidate
again to make sure that the end result or the end sbomb is valid against what you what data you need uh to be present. Uh you can also merge multiple uh sbombs and currently the team are working on conversion between the different uh between the different formats. Uh again if you need more details contact me or Rakkesh who is the the team lead of the development of
of of that tooling. Um I mentioned earlier there is a full demo that Marcel did in uh December of last year of the full visual representation and the full use of tools u that are part of the whole supply chain simulation. So we won't go into that direction uh based on the time that we have because that has to be typically its own thing uh with the
different tools and explaining what to do and how to use them. So if you're interested again link will be part of the slides when they share sh we share them later and you can actually check uh the recording >> or just contact us or hear clicks from double open or here from about code or Thomas or Helio. So just look left and right. Perhaps you will find
some people that can help you. But worst case we can do the matchmaking or you just contact me. You're welcome. >> Yeah. And the next part is for you. >> Talk a bit about the tooling work group. >> Yeah. So uh the tooling work group um is um as so there I'm happy that also some colleagues are in in the in the room. Um um as we
said we we already um there for now we're in the 10th year so we have part we'll have a party soon. Um that's point number one. Uh point number two before you leave the room uh I would really invite you to our uh next uh first Wednesday session. So we u meet twice a month every first and third Monday. Uh sorry Wednesday. uh the first Wednesday in
the European morning um that we also have our Asian colleagues have uh from Japan and China, India etc have the chance to easily access and the third Wednesday is then in the European afternoon where we also have then uh colleagues from from the east coast so that they that's not too early for them that's point number one you see also um on the upper left this is
exactly what we started uh years ago with as as a vision Yeah, we're building an open source compliance management tool chain ecosystem with open source tools as an open source project. Yeah. And uh and the last bullet point and I would say okay mission completed so far provide reference tools since that can be used without fees by anybody and that was exactly now the idea here and
please reach out to us. So if you want to try that at home we we will make that happen. Um then uh in the next uh Monday session 6th of May that is very interesting because now obviously we had to uh just cut out one of the blueprints and that's very very important for me. So there are other blueprints and we also learned the hard the hard
way. Um there's no silver bullet that matches all. So also I would also invite you not only to um the talk from Sebastian Martin about your server but the session before uh Helio and and Thomas will also uh provide a blueprint uh more or less that also focuses as far as I read also on the uh on the huge benefit in my point of view to have
this all um configuration as code because that is also what you typically do not find in commercial tools um And why I say this is this session um on the first Wednesday uh of May is where we have Phelix Rashman from the Wii Bum uh who with his team made um a scientific research on open-source tools uh and um um developed a method a model how what
needs to be compared how can it be compared and that's also at scale so that this is not a one-time thing but then you can do it again and again. So, and that is I think a real cool thing. First of all, you'll see there's not only one open publicly available tool, but there are several and there's even research work. It's a kind of a preview because
they're in uh still in the process of publishing it. And also they um as far as I understood Felix so I hope I don't say something wrong that also this um this docker setup everything for the testing will also be open source that that we can also use it as a community later and with that um our summary. Yeah. So I more or less said it if
I um you can try all of this at home. If you um have any issues or you want to check it out first, please join us in the in the group on the mailing list in Slack in Metrics. Um so uh we share the slide deck later. Um uh we have all the QR codes and um yeah we I think we are very open community also. if
you um do not dare to share your solution because I think you think that might um not be the right one or you're unsure. It's always the right one because you made it for you. It's just a question. Um and if it works for you, but may it work also for someone else and therefore it's important that you make it public uh and and just provide your
blueprint so that other people can see it. Uh and here you see on our website oss compliancetooling.org work. We have also a tool list. Yeah, not a blue um a blueprint uh collection but here we have the um the tool list of open source tools where we try also to keep them up to date. What is also a little bit challenging also with the dates I think
we got the feedback that we need to update the the main page for that. Um but um that's one point and you could ask so why didn't you put then all these blueprints also there uh that is very easy because here as you can read this is only open source so we do not want to have any um commercial tooling here in auapsis you would also be
welcome um to provide blueprints with um with open u with publicly sorry with commercial [laughter] I really use commercial tooling as a um also setups because we're we're also aware that um um yeah there are specific needs where you need that or you have constraints and and also I think we're um uh very well interacting and collaborating also with um uh commercial and with that yeah thank
you very much and uh I think we have uh room for um questions or as additions from our experts in the room. >> Yeah. Um do we have a microphone or we just repeat a question I guess? >> There. Yes. >> Is it working? >> So one hand. >> So we probably have just a couple of minutes. We have a hard spot. >> Hi. Thanks for the
presentation. Um I have Yeah. two questions. How is it decided to uh that a blueprint that was contributed is going to be public available? I assume it's created somehow, right? >> Uh the blueprint is just a a playground if you want because we um we wanted you to to get a feeling um how it works and to prove it's it's it's available. So if you then really
want to productize and then uh run it um in your company, I think we should then also discuss this more in the detail in the community because there you can imagine we all learned our lessons and this also depends on your company infrastructure etc etc but by by default and uh Sebastian is directly sitting behind you so and that's the beauty for was the beauty for me
in this um uh for the simulation because I didn't have to use my heavily uh sweating installed docker installation of all this but I could just use his service and that was a dream right so having a test user having a sandbox uh uploading then uh my repository uh and it was fully analyzed and this is uh what I was most astonished and then thank you really
for for the maintainers it looks exactly the same in our internal instance uh and that's also I a very >> if you're asking for the for the format of the blueprint itself, I think it follows like a pretty common logic or sort of a bit of a like a self-explanatory way of how you will describe uh your way of resolving a certain issue that's already documented. So
in a way it you cannot really uh provide a template for everything because again uh the blueprints are sort of unique on their own based on what's their uh purposes or what's the issue that they're resolving. So in a way you have to follow a certain structure but that structure is flexible based on what you use the the blueprint for in a way >> and your feedback
is very very welcome. So if you see okay because created for us uh we're in our tunnel right for us it's potentially everything is evident but someone who comes in new >> uh has fresh questions and we need that questions that we also know what do we need to answer in this >> a blueprint for curating blueprints >> yeah [laughter] >> uh anyone else >> then no
other questions I would like to ask so that this did I didn't get it Right. With the sepia validator, does it validate a format or a content? >> Yeah, the inclusion of sepia to this, it's not technically part of the the full simulation case, but it's an additional tool that you can use before. So, for example, if you use the the test instance in uh the octed
test instance and you generate a uh sbomb at the end, you can validate that sbomb with sepia before, for example, uploading it uploading it to dependency track. validate against your own schema. >> So that is for for example for your particular use case you have a defined schema that you want to make sure that the produced asbomb is valid against the information that you need. So that's
why sepia was mentioned but it's not part of the I think that we are out of time because I saw a hand uh catch us outside and we'll try to to fall up. So thank >> Thank you very much. >> [music]