Cloud Native
Security Talks
RSS

KubeCon Europe 2026

SB💣💣M: Making SBOMs Play Together

Jacopo Bufalino, CNAM & Agathe Blaise, Thales SIX GTS France

Abstract

The Cyber Resilience Act (CRA) is transforming how we approach software security, demanding not only safer code but proof that it remains secure throughout its lifecycle. At the core of this is the SBOM– a transparent inventory of all components inside an application, built to reveal hidden dependencies and vulnerabilities. A growing ecosystem of open-source and cloud-based tools promises to generate these SBOMs and automatically map vulnerabilities. Yet in practice, these tools often produce conflicting results, inconsistent package lists, and mismatched vulnerability reports, especially when scanning complex container images. In this talk, we dissect why SBOMs and vulnerability reports diverge across tools, uncover the technical roots of these discrepancies in containerized environments, and discuss how developers can ensure their tooling remains CRA-compliant. Finally, we explore how the ecosystem must evolve to deliver a transparent, trustworthy, and secure software supply chain.

More from KubeCon Europe 2026

Open in the index →
  1. When Multitenancy Goes Wrong: A Deep Dive Into Kcp’s First CVEMarvin Beckers, ClickHouse 2026-03-24
  2. What LLMs Do, and Don't, Know About Securing KubernetesRory McCune, Datadog 2026-03-24
  3. Real-World Supply-Chain SecurityAlex Leong, Buoyant 2026-03-24
  4. Privacy as Infrastructure: Declarative Data Protection for AI on KubernetesJoaquin Rodriguez, Microsoft & Krishnendu Dasgupta, AXONVERTEX AI 2026-03-24
  5. Policy Engines for Kubernetes: Picking One Without Losing Your MindNabarun Pal, Broadcom 2026-03-24
  6. Why Security of Kubernetes Comes Down to Linux SecurityMarina Moore, Edera 2026-03-25
  7. Why Isn't the Fix in My Container? Tracking CVE Propagation Across 10,000 ProjectsMor Weinberger, Echo Security & Lior Kaplan, Kaplan Open Source 2026-03-25
  8. Signed, Sealed, Delivered: Why Reverse Proxies Outperform VPNsPeter ONeill, Teleport & Boris Kurktchiev, Independent 2026-03-25
  9. Kubernetes Third Party Audit ReviewIain Smart, AmberWolf; Amir Montazery, Open Source Technology Improvement Fund; Rey Lejano, Red Hat; Tabitha Sable, Datadog; Pietro Tirenna, Shielder 2026-03-25
  10. Kubernetes Security at Shopify Scale: Automating Security Across an Infrastructure MonorepoJie Wu & Pulkit Garg, Shopify 2026-03-25
  11. Invisible Guardrails: Enabling Developer Velocity With a Secure PlatformJames Elías Sigurðarson & Vignir Hafsteinsson, Asana 2026-03-25
  12. How To Break Multi-Tenancy Again and Again ...and What We Can Learn From ItLorin Lehawany & Sven Nobis, ERNW 2026-03-25
  13. Hacking GPU Observability: eBPF & Ephemeral Containers in Action on KubernetesBrandon Kang, Akamai Technologies 2026-03-25
  14. Hack Me If You Can: Learning Kubernetes Security Through a Role-Play BattleAoi Takahashi, Recruit Co., Ltd. & Keita Mochizuki, NTT DATA Japan Corporation 2026-03-25
  15. Exploring NRI for Automated CA Trust InjectionTsuzuki Tsuchiya & Kento Kubo, LY Corporation 2026-03-25
  16. Detect, Decide, Defend: Building Cloud Native Security That Fights BackMatthias Bertschy, ARMO 2026-03-25
  17. Bob and Alice Revisited: Understanding Encryption in KubernetesJackie Maertens & Mitch Connors, Microsoft 2026-03-25
  18. Automating and Scaling of Threat Modelling for Cloud Native ArchitectureHanna Papirna & Emma Yuan Fang, EPAM Systems 2026-03-25
  19. Automate Once, Run Anywhere: The Docker Moment for Security WorkflowsNancy Chauhan & Aseem Shrey, ShipSecAI 2026-03-25
  20. Audit-Ready Kubernetes: How Chase UK Leveraged Policy as Code for Continuous ComplianceJim Bugwadia, Nirmata & Nischay Goyal, JP Morgan Chase 2026-03-25
  21. The Shared Service Blueprint: A Guide to Multi-Tenancy, Illustrated With KEDAAya Igarashi, Preferred Networks, Inc. 2026-03-26
  22. Tailor Made: Dynamic Fine-Grained Authorization for API TrafficErica Hughberg, Tetrate & Andres Aguiar, Okta 2026-03-26
  23. SPIFFE Meets OAuth: Federated Identity for Cloud Native WorkloadsYoshiyuki Tabata, Hitachi, Ltd. 2026-03-26