Kubermatic branding element
Video

Watch Mario Fahlandt's talk

Generating a single SBOM is easy. Automating transparency for an entire foundation with more than 200 projects and 3,000 sub-projects is a very different challenge. With the Cyber Resilience Act (CRA) deadlines approaching in 2026 and 2027, handling security manually is no longer an option. In this talk, Mario Fahlandt walks through CNCF’s large-scale initiative to automate supply chain visibility. He presents a data-driven analysis of gaps found across more than 3,000 SBOMs, showing where the cloud-native ecosystem is currently “compliance-blind”. The analysis covers the most common missing metadata, broken dependencies, and unidentified “dark matter”. Mario also shares the problems the team ran into and how they solved them, from accidentally breaking GitHub’s own PR system to the realization that SBOMs are of little use if they cannot surface core issues such as licenses and CVE-affected packages. The talk closes with tools you can apply to your own projects.

Key Takeaways

  • SBOMs at Foundation Scale: What it takes to automate SBOM generation across hundreds of projects and thousands of sub-projects.
  • Where the Ecosystem Is Compliance-Blind: Data on the most common missing metadata, broken dependencies, and unknown components.
  • CRA Readiness: Why making license and CVE data actionable matters as the Cyber Resilience Act deadlines approach, and which tools can help.

Leading Companies Choose Kubermatic

Allianz Vonage CNCF Cube FHE3 Switch inventx Datagroup Krone Charite Justus-Liebig-Universität Gießen Heidelberg University Swisscom Datev BWI