Brian Fox on Sonatype’s SBOM Manager at KubeCon Paris 2024
In response to escalating global regulatory pressures and cybersecurity threats, which have resulted in growing requirements to collect and monitor SBOMs (Software Bills of Material), Sonatype, the software supply chain optimization company, announced its cutting-edge SBOM Manager. This solution streamlines management, continuous monitoring, and release workflows of SBOMs empowering organizations to effortlessly understand their SBOMs, ensuring compliance with global regulations and bolstering software supply chain security. Alan Shimel and Brian Fox discuss the launch and more at KubeCon Paris 2024.
Transcript
This is Textron tv. Hello everyone. We're back here, live in Paris on the show floor of a buzzing, buzzing cube con.
As I said earlier, they're expecting about 13,000 people. Ah, this year this will be the largest cube car ever. Um, and I, you know, just looking around the floor, you guys are shooting out.
I don't know what people can see 'cause some of it's blurred, but it's a very busy floor. I'm joined here by my friend Brian Fox. If you don't know Brian, uh, CTO at Sonatype.
Co-founder, yeah, co-founder CTO at Sonatype. I've been interviewing Brian for a long time. 10 minute, 10 years.
A minute. Yeah. Maybe more.
Yeah. Um, but beyond his role at Sonatype, Brian's probably one of the most influential community involved folks in especially on the security side of things. Right.
Uh, Sonotype is a, oh, you guys a platinum or Diamond sponsor? Some high sponsor of Q Con, but Brian, personally, you're involved with OSSF. That's right.
finops Enos. We're, we're involved. Enos.
Yep. Uh, I'm a governing board member of the Open SSF and number, number of the committees there as well. So we're gonna talk about Sona Type, and we're gonna talk about CNCF, but let's, let's first talk about things like open SSF.
And you are, you're a board member. I mean, there's obviously business reasons why you want to be on the board, but Brian, with you, it's, it's a passion as well. Let, let's talk about, I don't mean to embarrass you, but let's talk about that, you know, for a bit.
What, what drives you to be involved like that? Yeah, I mean, you know, it's been since 2011 probably, that, that, uh, those of us at Sonotype have been observing this problem with what everybody talks about now, supply chain security. Mm-Hmm.
Um, and so we've been on a mission for how many years? Is that? 13, 14 years at this point.
Yep. To try to help large organizations do a better job of managing their open source dependencies from a security and license compliance and architecture risk. Uh, we know that, um, doing a good job on this can lead to better outcomes for the company, but also makes them much more efficient.
You know, so many people think about it, it's a tax, I have to do this to make things more secure, but we know that that's actually not true. That, that it unlocks productivity, but the market in general has been very resistant to change, and it's just human nature. Yeah.
And so, you know, uh, the last couple of years we've been involved with others at the open SSF working with the US government, with csa, with ONCD, trying to help really, you know, elevate the message, spread the word, and help work with the regulators. You know, after Solar Winds and log for a shell. Um, a lot of people sat up and paid attention.
Unfortunately, not all of that attention was, was, um, focused in the right area. And so that's what I've been spending a lot of time trying to help shape that policy, help inform the legislators so that we get, you know, sensible legislation that helps us all be better, not punitive legislation that can really undo things. Well, I, I remember speaking to you, I guess it was last year, you know, we're here in Paris and, and so we shouldn't focus on maybe just US regulatory, uh, challenges, but the EU Yeah.
Generally is a, a step or two ahead. They, they have more of a, a will, if you will, to do something, but they don't necessarily, and I, and I, it's not the eu I think it's all politicians and, you know, I'm here, I'm from the government and I'm here to help kind of thing. Yeah.
Um, they, they don't really understand the issues. Yes. Right?
Yes. They, they have good intentions. Yes.
But the road to hell is, is lying with good intentions. It paid with good intentions. Yes.
Yes. Uh, yeah. It's true that the legislators in, in the EU have moved quickly with the Cyber Resiliency Act, the product liability directives, the AI Act, all of that, I think generally is good.
Many of us spent the last year, 2023, trying to help shape, um, and, and frankly undo a little bit of what the CRA the was focused on, because it was, it was focused on potentially, uh, punishing the open source maintainers, holding them liable for things that were out of their control. And that just comes down from the misunderstanding of, of the policy makers, like from a, from moving the industry forward, trying to hold vendors accountable. I think they were spot on.
Right. The problem was you have no leverage over open source maintainers outside of your jurisdiction. You can't hold them responsible in the same way.
And the danger was potentially that open source could opt out of Europe. It sounds crazy, but people were saying it, people were asking us, for example, at Maven Central, the repo that we run, you know, could you, could you potentially stop our stuff from being downloaded inside of the eu? So it was a very serious thing that I think that the policymakers didn't understand at first, and it took a lot of effort to kind of course correct that.
So we're, we're within the open SSF. We have, uh, you know, we're building further relationships with those folks in Brussels this year to try to help educate that, you know, on the US side, ONCD and CSA have been very involved in the community. We've had many, many, um, summits.
In fact, I was just that one two weeks ago with csa where they convened all of the package repository folks together, and many of the other leaders in, in prominent foundations, Apache Eclipse, uh, open, SSF, to talk about the problem, the sustainable funding challenge that we all face. Right. So I think on the US side, they're doing a great job of getting informed actual regulatory action is slow at the moment.
On the eu it's almost the opposite. And so we need to kind of smooth those things out, and I think we'll be in a good shape. Excellent.
Good stuff. Good. Good.
Uh, got a briefing right here from Ryan. Um, Brian, if you don't mind, let, let's focus, pivot over now to Sonatype. Sure.
Specifically, as you mentioned, Sonatype has been the maintain maintainers of Maven Central for as long as I forever, I think there's been a Maven Central, right? Yeah. Um, and as such, you know, you've been at the forefront of, uh, you want to call it DevSecOps, you want to call it now, software, supply chain security, um, of, of, you know, this whole movement, what's new?
Is there new, right? Because I think part of the issue is you keep fighting that same battle. You keep fighting on the same battlefield.
Yeah. Yeah. But there's new, So I think fronts open.
I think the new thing this year, and it, it's not new to me really, but it's new to the rest of the market ish, is, you know, the whole push for SBOs, right? So SBOs, we, we, it was a means to an end for us 11 years ago when we were trying to help organizations. Most of them didn't know what was in their software.
Unfortunately, many of them still don't and are struggling with it. You know, on the US side, they've been pushing the SBO m software bill of materials. If you don't know, um, you know, it, it's required for many government sales.
The FDA will won't even begin to look at approval of a new device without an SBO M as of October, I think. Right? So, so there's a lot of talk pushing that, you know, the, the legislation in the EU references it as well.
So it's, it's a worldwide phenomenon, not just us. And so, you know, what I've observed in just the last year, um, is a major pivot. So about a year ago, I went to some sessions.
Everybody was kind of grappling with, why are they making us do this? It's really hard to do this. We don't know how to do this all for reasons that they would never want to tell their customers things.
Like, we don't have anybody that knows how to maintain that stuff, where we, we don't track what's in it. Right. Things that, that would Yeah.
Because I, consumers would be horrified about, that was the conversation last year. This year, the conversation, um, is more focused on, okay, I need to produce SBOs. I'm, I need to ask for SBOs from my vendors.
Um, so they, they've moved from sort of that denial, anger into acceptance. But I think people are still struggling with, okay, now I have all these SBOs, what am I supposed to do with it? Right?
And so that's why yesterday we, we launched, um, the sonotype SBO M manager, which is a, a version of our platform, um, that is focused on people that are procuring software in organizations, um, from many different vendors. Um, and also trying to have a clearing house to be able to provide their SBOs, both from their first party software, but also from their third party stack dependencies and stuff downstream to their, their, uh, customers as well. Sure.
Right. So there's a number of new workflows and use cases that, that are, are coming into play. And it's interesting 'cause the scale of this is much larger than even we expected.
You know, we're, we're used to organizations managing, you know, tens of thousands of applications, which is, is a lot. But the biggest organizations, 10,000, 20,000 is fairly normal. We've had those same organizations talk to us about a need to manage millions of SBOs, uh, which is, which is quite shocking.
Which Brings up the point I wanted to make to you, it all sounds copacetic, right? What a great idea. We need to do this.
I just wanna let this go. I'm not sure if this gets picked up in our mics, but that's loud. But the, the, sometimes the devil's in the details.
And, and you know, what I saw, I, this is coming out of RSA last year. It'll be interesting to see. What I see at RSA this year is sort of a tower of babble of SBOs, right?
So compatibility of SBO formats, because if Sonatype has their format and Company Z has their format, and Company X has their format, and we, this reminds me, remember when RSS feeds first came out? Yeah. Right?
There was RSS one oh, and two oh, Adam, and, and all these different formats. And so if you had an RSS feeder, if you weren't able to read all the different RSS formats, you needed six different readers. Yeah.
Uh, until a company called Feet Burner, if you remember, feet Burner normalized. That's right. The RSS feeds.
Do we have anything that's gonna normalize the SBOs? Yeah, I mean, that's, that's a use case of, of our tool. Um, but the, there's really two main standards for SBOs.
It's SPDX, which is a Linux Foundation, uh, project, and then Cyclone dx, uh, which is, uh, an OASS project. 0. Sonatype contributed, the first security profile extension for it, for example.
Um, because specifically I didn't wanna invent our own bespoke Right, um, uh, Protocol, because that doesn't help the Cause. That's right. It doesn't help the cause.
And so there's really just those two main, and I think, you know, everybody has, uh, uh, come to accept that at this point. And pretty much, I think all the tools are both able to consume and emit, uh, the different SBO formats. Uh, so it's a little bit of extra work, but, you know, it's, it's, it's sort of a solved problem at the moment for people.
So I don't think you need to get too worried about that. I don't see any other standards coming along anytime soon. Uh, you know, we're, we're well past that.
I hope not. Yeah. No, I, I, that, that's, that's good news.
Um, look, we've begun almost this whole interview. We haven't mentioned ai Ai. I was wondering when you were gonna ask, I have to, yeah.
I, I say ai, we get like money or something. I don't know. Um, what, what role is AI gonna have on SBOs and so forth?
Oh, you know, it's interesting. You know, the, the, the conversation around SBOs has sort of, uh, you know, uh, fragmented in a, in a sense, and people are talking about crypto bombs, cloud bombs, AI bombs, right? Because you need to be able to potentially document and disclose what models, what the training set went into the models, right?
So I think the bill of materials concept is here to stay, and there's gonna be many different extensions for different areas. Um, you know, we've, interestingly, we've seen many of our, uh, customers asking us to help them manage the AI usage within their products. So, and, and from my perspective, it looks very much like 10, 15 years ago in open source, where we would talk to policy makers and they would say, we have a policy against it.
We're not using it. And then you go and look at what's in their applications or talk to the developers, and it's open sources everywhere. Everywhere.
Well, the same exact thing is happening with AI and LLMs right now. Yes. So about a month or so ago, we added some new capabilities to help detect, uh, and recognize LLM AI components, AI rest calls, and be able to surface those so that then the governance engine we have in our platform can help, uh, the policy folks Know It's there kind of reason about it.
Right? So, so ai, um, you know, is, is getting into the applications in a fairly large way that many people don't realize. You know, I think that the AI aspects of the whole industry will certainly help.
Uh, the generative AI parts can help, um, you know, with some of the SBOs, you know, filling out descriptions that are rational. It's really good at those things. You know, if you have a component, but you're not sure what the category is or what, how to describe it in the sbo m uh, you, you can use AI techniques to be able to, to help massage some of those things.
Same thing in terms of trying to interpret it. So I think it's gonna be, you know, secretly underneath the hood in both the generative, you know, the, the export and the import of these different formats as, as we're sort of, you know, hanging around the periphery of the formats and, and what the humans can do. Love it.
Brian, we're about outta time. com. That's right.
org. Yeah. Yep.
Yep. I mean, we, we, we didn't touch on the, the state of the software supply chain report. That's an enduring one.
Um, When's that Coming in? October This year is the 10th year. That's right.
It's gonna be huge. And, you know, a lot of the research that we've done over the last 10 years is still completely relevant. Uh, you know, we tend to take a different look at the industry every year.
Um, so we're gonna be going back and looking at a lot of those key findings and trying to update them trends and summarize them. Um, you know, so the team's already hard at work on that. Very cool.
Um, trying to, trying to get that updated. com/sscr, uh, state. Yeah.
So we'll see you at, at RSA. That's Right. We'll see you at the open source summit coming up.
I wanna say June in Seattle, is it? Or April in Seattle? Uh, there's one in June.
There's also one in a couple of weeks. Uh, April. In Seattle.
In Seattle. Yeah. I think we're gonna be, uh, That's right.
What are we doing here? I'm gonna be everywhere. I'm going to Dev Nexus.
I'm going to, uh, v calling. Yeah. No, you would tell me.
You're great. I, you know, God bless you. That's Right.
I picked my spots. That's right. But anyway, Brian, thanks for what you do.
The whole community and continued success with sonotype. Thank you. Brian Fox from Sonotype, as well as board member open, SSF, and a whole bunch of other things here.
Live on Techstrong tv. We're in Paris. We'll be right back.