Loading…
Wednesday, July 21 • 11:30am - 12:15pm
Deep Dive: Paketo Buildpacks Bill of Materials: We’re Built Different - Sophie Wigmore & Forest Eckhardt, VMware

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
The exploitation of vulnerabilities, like those in the recent high-profile SolarWinds attack, highlight the need for thorough security and compliance auditing. In the Cloud Native technology landscape, there are a variety of purpose-built solutions that help eliminate pain points along the software supply chain. One of these solutions, bill-of-materials (BOM), is an industry standard mechanism for surfacing metadata to be used for security auditing. Cloud Native Buildpacks (CNB) have native support for the BOM baked into the image metadata. The Paketo project, an OSS implementation of CNB, is taking the BOM a step further by populating it with dependency and package metadata from both the build process and the final image. This talk will explore how our approach to BOM provides more convenient and comprehensive insights into vulnerabilities, and how they can be mitigated.

Speakers
FE

Forest Eckhardt

Software Engineer, VMware
Forest is a member of technical staff at VMware working on Paketo Buildpacks, an open source implementation of Cloud Native Buildpacks. He was previously the anchor of the Buildpacks team, and has worked on many iterations of the buildpack concept.
avatar for Sophie Wigmore

Sophie Wigmore

Member of Technical Staff, VMware
Sophie is a software engineer at VMware Tanzu, working on Paketo Buildpacks. She is a maintainer of Paketo tooling, and buildpacks in the Ruby, .NET Core, and PHP ecosystems. She has previously spoken at CF Summit EU and US, and holds a Bachelor's degree in computer science and biology... Read More →



Wednesday July 21, 2021 11:30am - 12:15pm CDT
Virtual 3
  Behind the Curtain Track
  • Audience Experience Level Any
  • Slides Included Yes