COSCUP x UbuCon Asia 2026 Logo
  • About
  • Session
  • Transportation
  • Venue
  • Communities
  • Sponsors
    • Participate Guide
    • First Timer
    • Activity
    • Speaker Participation
    • Welcome Party
    • For Overseas Visitors
    • Open Source Communities
    • Sponsorship Partners
    • Invitation Letter Guide
  • Staff
  • Fringe Events / BoF
  • Blog
  • CoC
中文

SBOMs Aren't Enough. Secure Your Software Supply Chain End-To-End

Time
2026-08-08 14:10 ~ 14:40
Speaker
Yongjae Chung, Justin Cappos
Room
TR513
Co-write
Cyber Resilience IntermediateEnglish

Abstract

You probably heard that SBOMs are helpful, but did you know that an SBOM only addresses a fraction of what can go wrong in your software supply chain? The SLSA (Supply Chain Levels for Software Artifacts) specification identifies 9 distinct threat areas, spanning from source code, all the way to package distribution. Most development teams address one or two of these and call it a day, leaving gaps that real-world attacks like SolarWinds and Log4J have already exploited. We understand that it is difficult to cover all aspects when it comes to the software supply chain.

How about we make this much easier? In this talk, we will present an overview of the modern software supply chain threat model, and show how you can provide integrity throughout the whole process of your software development life cycle. We will introduce an easy-to-setup, end-to-end open source stack, built from frameworks and tools within the CNCF/OpenSSF ecosystem.

We will cover:

  • gittuf - A security layer for Git repositories
  • in-toto - Cryptographically verifiable attestations that capture what actually happens during your build process
  • SBOMit - Generate verifiable and accurate SBOMs that embed in-toto attestations
  • TUF - A framework for securing package updates

This talk aims to demystify software supply chain security beyond SBOMs, and provide a more holistic view. Our live demo will show a pragmatic way to get started, aiming to lower the entry barrier for open source maintainers and adopters alike.

Speaker

Yongjae Chung

Yongjae Chung

Yongjae is a Master's student at New York University. He is a contributor of gittuf, an incubating project at Open Source Security Foundation.

Justin Cappos

Justin Cappos

I'm a professor at NYU and the creator of five Linux Foundation projects (TUF, in-toto, SBOMit, gittuf, and Uptane). I also created security architectures used by git and most Linux package managers.

Diamond

Canonical

Gold

Consecutive2 YrsInformation Management AssociationConsecutive2 YrsCathay Financial HoldingsConsecutive5 YrsE.SUN BankCumulative12 YrsMySQLCumulative6 YrsBerry AINitra

Silver

Cumulative16 YrsGamesofa Inc.

Bronze

KKTIXNational Center for High-performance ComputingONLYOFFICEQNAP Systems, Inc.Consecutive16 YrsThe Archilife Research FoundationSUN SQUARE Co., Ltd

Friend

Consecutive3 YrsAndes Technology CorporationAppier

Special Thanks

Consecutive2 YrsDepartment of Information Technology, Taipei City GovernmentSiFiveRozeta AI

Co-host

Collaborator9 YrsNTUST - Department of Electronic and Computer Engineering

Co-organizer

Collaborator12 YrsOpen Culture Foundation

COSCUP x UbuCon Asia 2026

Conference for Open Source Coders, Users, and Promoters | Asia's largest open source community conference.

Contact

  • Attendee Services
  • Sponsorship
  • Call for Proposals
  • Marketing

Resources

  • COSCUP Blog
  • Newsletter Subscription
  • Event Photos

Sitemap

  • Home
  • About
  • Transportation
20062007200820092010201120122013201420152016201720182019202020212022202320242025