Who touched my software? Trust beyond the SBOM checkbox
Imagine you buy lunch at the corner of the street every day. It's fast, it's cheap and it tastes great. Where the ingredients came from or who prepared it, you don't know. Most days that's fine. Until the day you get sick and can't trace it back to anything. Food solved this decades ago with labels, inspected kitchens, known handlers and recalls. Software now has its label too: the Cyber Resilience Act makes the SBOM mandatory. Many of us will generate one, file it and move on. But a label on a kitchen nobody inspected tells you very little.
Here is the uncomfortable part for our own community. Open source is the only model where every station of the supply chain can be inspected, and we barely use that strength. Most of us still pull images from public registries and trust dependencies nobody in the room has read. xz showed how close we came: one exhausted maintainer, years of patient social engineering, and a backdoor found because a login took half a second too long. With the Open Build Service and the SUSE Application Collection as worked examples, this talk shows what running every station properly looks like: preserved source, reproducible builds, known packagers and patches that travel back through the same chain. Only then does the SBOM become proof of something.
It closes with four questions any team can answer this week, one for every station of the chain: Where did it come from? Who built it? How did it reach us? Who fixes it when it breaks?
Bert Boerland has been part of the Drupal community for over 25 years. He registered the drupal.org domain in its earliest days and handed it to Dries Buytaert, organized DrupalCon Amsterdam (2005) and co-led DrupalCon Barcelona (2007), founded DrupalJam and the Splash Awards, and served as a Drupal Association board member. He currently chairs Stichting Drupal Nederland and is a 2026 candidate for the Drupal Association's At-Large Board seat. By day he works in enterprise Linux and Kubernetes sales at SUSE. Bert writes and speaks regularly on open source governance, sovereignty and infrastructure funding, and is currently organizing a community working session on FAIR at DrupalCon Rotterdam 2026 with contributors from across the Drupal, TYPO3 and WordPress ecosystems.
