Event language
UI language
The log4j breach made headlines across the world due to its impact and showed once more how the world runs on open source. But do you know which open source you rely on in your software or organization? <br><br>In this talk Sankalpa and Thomas will present how you can use <a href="https://github.com/oss-review-toolkit/ort" rel="nofollow" target="_blank">OSS Review Toolkit</a> (ORT) in your CI/CD workflows to see which FOSS dependencies are used, do license/security compliance, and generate SBOMs (software bill of materials). Included in our talk will be a demonstration of OSS Review Toolkit in GitLab CI and how its various features can be used to automated FOSS reviews requirements (incl. <a href="https://cyclonedx.org/" rel="nofollow" target="_blank">CycloneDX</a> and <a href="https://spdx.dev" rel="nofollow" target="_blank">SPDX</a> SBOM generation) and use crowdsourcing within an organization and the FOSS community to overcome challenges such as dependencies not detected, incorrect licensing, large amounts of scan results or missing/incorrect FOSS package.