アイコン

Nerding Out With Viktor

チャンネル登録者数 651人

99 回視聴 ・ 1いいね ・ 2025/01/17

In this episode of Nerding Out with Viktor, host Viktor Petersson interviews Kate Stewart from the Linux Foundation and Gary O’Neall, a veteran SPDX contributor, about the history and evolution of the Software Package Data Exchange (SPDX). They discuss how SPDX originated as a solution for open-source license compliance and evolved to meet broader demands in security, vulnerability management, and regulatory compliance.

Kate and Gary share insights into the technical hurdles of generating accurate SBOMs, including dealing with circular dependencies and the complexities of incomplete software data. They offer practical examples, such as SBOM integration efforts within the Zephyr and Yocto projects, and highlight ongoing work to implement build-time SBOM generation for the Linux kernel. The conversation also addresses the challenges of maintaining compatibility with existing tools while expanding functionality for new use cases, particularly in safety-critical and CI/CD-driven environments.

The episode emphasizes SPDX’s open, community-driven approach and its growing relevance amid increasing regulatory requirements for software transparency and safety. By illustrating how SPDX supports compliance, security, and supply chain visibility, this discussion provides valuable insights for developers and organizations navigating the complexities of modern software development.

コメント

コメントを取得中...

再生方法の変更

動画のデフォルトの再生方法を設定できます。埋め込みで見れるなら埋め込みで見た方が良いですよ。

現在の再生方法: education