We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

Make your software products trustable

Formal Metadata

Title
Make your software products trustable
Title of Series
Number of Parts
798
Author
Contributors
License
CC Attribution 2.0 Belgium:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
As organizations start their software supply chain security (SSCS) journey, more and more documents (like SBOMs and VEXs) are being created. But having these documents produced will get us just a half-way through. We need ways to store, index, search and analyze potentially large numbers of SSCS documents to become aware of our vulnerabilities and be able to react to them quickly. Meet trustification, an open source project that allows us to store and analyze our security data at scale. Trustification allows users to manage their portfolio of applications, containers and products throughout their lifecycle. Providing transparency of their technical make up and dependencies as well as highlighting their vulnerabilities. In this session, we will describe the Trustification project in detail. We'll start by covering basic requirements for this kind of system. Having a S3 compatible storage, flexible vulnerability collectors, support for powerful query language and ability to find the relationship between different components is the key. We'll go through the architecture and all the services needed to achieve these goals. We'll end up with a brief demo of the working system. After the session you should be able to start using Trustification to make your software products more trusted.