KubeCon + CloudNativeCon Europe

SBπŸ’£πŸ’£M: Making SBOMs Play Together - Jacopo Bufalino, CNAM & Agathe Blaise, Thales SIX GTS France

29:21 Β· 23 Mar 2026 – 26 Mar 2026 Β· YouTube

About this talk

This talk addresses the transformative impact of the Cyber Resilience Act (CRA) on software security, emphasizing the need for secure code verification throughout its lifecycle. The speakers, Jacopo Bufalino from CNAM and Agathe Blaise from Thales SIX GTS France, dive into the concept of Software Bill of Materials (SBOM) as a tool for identifying hidden dependencies and vulnerabilities within applications. They analyze the reasons behind the discrepancies in SBOMs and vulnerability reports across different tools, particularly in complex containerized environments. Additionally, the session covers strategies for developers to ensure their tools comply with CRA and discusses the necessary evolution of the ecosystem to achieve a secure and transparent software supply chain.