The API That Could Transform Software Transparency | OWASP AppSec Global 2025 with Olle E Johansson

Channel:
Subscribers:
4,690
Published on ● Video Link: https://www.youtube.com/watch?v=Nkrp4mfj7AQ



Duration: 0:00
56 views
3


The introduction of the Cyber Resilience Act (CRA) marks a major shift for the software industry: for the first time, manufacturers are being held accountable for the cybersecurity of their products. Olle E. Johansson, a long-time open source developer and contributor to the Asterisk PBX project, explains how this new regulation reshapes the role of software creators and introduces the need for transparency across the entire supply chain.

In this episode, Johansson breaks down the complexity of today’s software supply ecosystems—where manufacturers rely heavily on open source components, and end users struggle to identify vulnerabilities buried deep in third-party dependencies. With the CRA in place, the burden now falls on manufacturers to not only track but also report on the components in their products. That includes actively communicating which vulnerabilities affect users—and which do not.

To make this manageable, Johansson introduces the Transparency Exchange API (TEA), a project rooted in the OWASP CycloneDX standard. What started as a simple Software Bill of Materials (SBOM) delivery mechanism has evolved into a broader platform for sharing vulnerability information, attestations, documentation, and even cryptographic data necessary for the post-quantum transition. Standardizing this API through Ecma International is a major step toward a scalable, automated supply chain security infrastructure.

The episode also highlights the importance of automation and shared data formats in enabling companies to react quickly to threats like Log4j. Johansson notes that, historically, security teams spent countless hours manually assessing whether they were affected by a specific vulnerability. The Transparency Exchange API aims to change that by automating the entire feedback loop from developer to manufacturer to end user.

Although still in beta, the project is gaining traction with organizations like the Apache Foundation integrating it into their release processes. Johansson emphasizes that community feedback is essential and invites listeners to engage through GitHub to help shape the project’s future.

For Johansson, OWASP stands for global knowledge and collaboration in application security. As Europe’s regulatory influence grows, initiatives like this are essential to build a stronger, more accountable software ecosystem.GUEST: Olle E Johansson | Co-Founder, SBOM Europe | https://www.linkedin.com/in/ollejohansson/

HOST:Sean Martin, Co-Founder at ITSPmagazine and Host of Redefining CyberSecurity Podcast | https://www.seanmartin.com/

SPONSORS

Manicode Security: https://itspm.ag/manicode-security-7q8i

RESOURCES

CycloneDX/transparency-exchange-api on GitHub: https://github.com/CycloneDX/transparency-exchange-api

VIDEO: The Cyber Resilience Act: How the EU is Reshaping Digital Product Security | With Sarah Fluchs:    • The Cyber Resilience Act: How the EU is Re...  

Learn more and catch more stories from OWASP AppSec Global 2025 Barcelona coverage: https://www.itspmagazine.com/owasp-global-appsec-barcelona-2025-application-security-event-coverage-in-catalunya-spain

Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage

Want to tell your Brand Story Briefing as part of our event coverage? Learn More 👉 https://itspm.ag/evtcovbrf

Want Sean and Marco to be part of your event or conference? Let Us Know 👉 https://www.itspmagazine.com/contact-us




Other Videos By ITSPmagazine


2025-05-31Chats on the Road to Infosecurity London, Kick-Off Episode — On Location with Sean and Marco
2025-05-30From Dashboards to Decisions: Why Your Security Metrics Might Be Leading You Astray | An OWASP Ap...
2025-05-30From Dashboards to Decisions: Why Your Security Metrics Might Be Leading You Astray | Aram Hovsepyan
2025-05-30From Dashboards to Decisions: Why Your Security Metrics Might Be Leading You Astray | An OWASP Ap...
2025-05-29Why Global Community-Led Innovation Is Driving Real Application Security Progress | An OWASP AppS...
2025-05-29Holding the Line on Quality in an AI-Driven SDLC | An OWASP AppSec Global 2025 Conversation with ...
2025-05-29Holding the Line on Quality in an AI-Driven SDLC | An OWASP AppSec Global 2025 Conversation with ...
2025-05-29Why Global Community-Led Innovation Is Driving Real Application Security Progress
2025-05-29Why Global Community-Led Innovation Is Driving Real Application Security Progress | An OWASP AppS...
2025-05-29Holding the Line on Quality in an AI-Driven SDLC | OWASP AppSec Global 2025 w/ Sarah-Jane Madden
2025-05-28The API That Could Transform Software Transparency | OWASP AppSec Global 2025 with Olle E Johansson
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Want to Use
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Actually ...
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Actually ...
2025-05-26The 30s | A Conversation with Bryan Wish | After 40 Podcast with Dr. Deborah Heiser
2025-05-26The 30s | A Conversation with Bryan Wish | After 40 Podcast with Dr. Deborah Heiser
2025-05-26Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow
2025-05-25Outside the Ivory Tower: Connecting Practice and Science—Why Human-Centered Cybersecurity Needs Both
2025-05-25Teaser: Measuring the Blast Radius of Tech Experimentation
2025-05-25Outside the Ivory Tower: Connecting Practice and Science — Why Human-Centered Cybersecurity Needs...
2025-05-25Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow | A Conversation wi...