> Markdown version of [/events/world-congress-2024/sessions/127-open-source-secure](https://www.wearedevelopers.com/events/world-congress-2024/sessions/127-open-source-secure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Open Source Secure Software Supply Chain in action - **Date:** Thursday, Jul 18, 2024 - **Time:** 13:30–14:00 (30 min) - **Room:** STAGE 9 (600) - **Event:** World Congress 2024 ## Description More than 2/3 of application code is inherited from open source dependencies. It’s important to provide verified and attested code with provenance checks in the whole software development life cycle. Join talk where developers can learn and understand how to use software bill of materials (SBOM) and Vulnerability Exploitability eXchange (VEX) as part of the software supply chain for cloud-native applications. Sign commits, images, and pipelines to create a chain of trust for your open source components and transitive dependencies with open source projects. ## Speaker ### [Natale Vinto](https://www.wearedevelopers.com/@natale-vinto) Developer Advocate Global Lead ## Related talks at this congress - [Supply Chain Security - Strategies and Best Practices](https://www.wearedevelopers.com/events/world-congress-2024/sessions/271-supply-chain) — Hendrik Ebbers - [The Future of Open Source](https://www.wearedevelopers.com/events/world-congress-2024/sessions/325-the-future-of-open) — Scott Chacon - [How your .NET software supply chain is open to attack : and how to fix it](https://www.wearedevelopers.com/events/world-congress-2024/sessions/218-how-your-net) — Andrei Epure - [The internal developer platform and golden paths: Scaffolding for cloud-native development](https://www.wearedevelopers.com/events/world-congress-2024/sessions/71-the-internal) — Natale Vinto