Post #2664626
2026-03-02 16:38 UTC
Actually, there were two presentations at #FOSDEM. In the first, I focused on the strategic aspects and context of the Cyber Resilience Act (#CRA).
Why does DB need transparency of its software supply chains? Why is it damn hard to achieve this? How did we come from idea to strategy to implementation? And why do we need less a technological and rather an organizational and cultural shift to succeed?
Answers to these questions in the recording and slides.
https://mehl.mx/blog/2026/software-supply-chain-strategy-at-deutsche-bahn/
[🧵 2/3]
Replies (1)
-
@mxmehl@mastodon.social 2026-03-02 16:40
The second presentation overlapped slightly with the first, but emphasized the tooling aspect: • #SBOM lifecycle and blueprint • Our modular SBOM toolchain for generation, refinement, analysis and storage • Integration into DevOps workflows • Our central compliance portal for teams and governance owners • And how we delight our various users. This is all heavily based on many great #OpenSource projects, such as those by @anchore@mstdn.business and @homebrew@fosstodon.org. https://mehl.mx/blog/2026/deutsche-bahns-approach-to-large-scale-sbom-collection-and-use/ [🧵 3/3]