European SBOM user group

Join the European SBOM community to discuss, learn and share knowledge about the Software Bill of Materials – tools, standards, use cases, related xBOMs and much more.

The meetings are every second week, with a summer break. We try to have a short presentation then time for open discussions. If you want to present, please contact us. You don’t have to be an expert, just a topic you want to share or need help to sort out. We also encourage vendors of SBOM tools to contact us and we’ll schedule a time.

Leaders are Anthony Harrison and Olle E. Johansson with invited guest speakers.

Register today using Pretix and we’ll send you a link to the virtual meeting no later than the day before. Registred participants will also get invitations to coming meetings.

Coming events:

October 15
15:00 CET

Introduction to CycloneDX 2.0 with Steve Springett
CycloneDX is developed by OWASP and standardised in ECMA TC54. The new generation – 2.0 – is underway and Steve will give an introduction to it. Steve is the leader of the CycloneDX project and the chairman of the OWASP Foundation. [Register]

Steve Springett

October 29
15:00 CET

Post-quantum-crypto (PQC) migration and CBOMs
The world is facing a big upgrade – and legislators are starting to push for this to happen. The threat of Quantum computers breaking the current cryptography is on the horizon and causes a massive change to new algorithms and protocols. In order to plan ahead and prioritise, organisations needs to take an inventory of their current state – certificates used, protocols used, PKIs and digital signatures. The current threat is actors that harvest communication and data now, to encrypt later when these solutions exist.

This is an introduction and you’re free to chime in with additional information and questions. The session is lead by Olle E. Johansson, co-founder of SBOM Europe and active in OWASP CycloneDX. [Register]

Olle E. Johansson @oej

October 1st
15:00 CET

SBOM: Ask us anything
This is the user group meeting for everyone to be able to ask their questions and help to answer. It’s an open forum focused on software and systems transparency – SBOM, CBOM, HBOM, TMBOM and other xBOMs.

Anthony Harrison

September 17
15:00 CET

Focus on SBOM types and “generated context”
There are several types of SBOMs – and still we’re missing some of them. Let’s go through where we area and discuss which ones that fit into the CRA requirements. Join Anthony Harrison and Olle E. Johansson in this user group meeting!

Anthony Harrison

September 3
15:00 CET

SBOMs and digital signatures
There are many requirements on signed SBOMs, but very few implementation guidelines. Sign with what? Verify with what? In this session we will discuss digital signatures and discuss various solutions. Join Olle E. Johansson in this session! [Slides]

Olle E. Johansson @oej

Previous dates:

  • September 3, 15:00 CET
  • August 20, 15:00 CET
  • May 28th, 15:00 CET
  • June 11th, 15:00 CET