The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Patrick Dwyer -- CycloneDX and SBOMs
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Patrick is a Senior Product Security Engineer in the Application Security team at ServiceNow. He is also Co-Leader of the OWASP CycloneDX project. A lightweight Software Bill of Materials (SBOM) standard designed for use in application security contexts and supply chain component analysis. Patrick Dwyer is a senior product security engineer in the application security team at ServiceNow. He's also co-leader of the OWASP CycloneDX project, a lightweight software bill of materials standard designed for use in application security contexts and supply chain component analysis. Patrick joins us to help us understand how CycloneDX fits into the world of protecting your software supply chain. He explains why they started the project and what is the depth and breadth of it, how many people are using it, and what is the future for CycloneDX and software supply chain.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Patrick Dwyer is a senior product security engineer in the application security team at ServiceNow.
→ Learn more about Security Journey
Connect with Patrick Dwyer:
→ CycloneDX
→ ServiceNow
Mentioned in this episode:
→ CycloneDX
→ ServiceNow
→ CycloneDX
→ OWASP Dependency-Track
→ SPDX
→ Docker
→ JC Herz and Steve Springett -- SBOMs and software supply chain assurance
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Patrick Dwyer: CycloneDX and SBOMs
05:07 Awesome. So I want to, I want to transition into talking
07:36 I guess what was the need when this project was started
10:01 So, so they have kind of different functions then. So I
12:12 Cool. So let's back up for a second. I probably got
14:10 Yeah, I'm also seeing the value then of retrieving SBOMs in
18:41 How'd you get involved with this then, with the CycloneDX project
19:52 Very cool. Very cool. So I mentioned kind of at the—
23:21 Yeah, that's, that's great to hear. What do you see as
25:11 Yeah, I guess as the tooling continues to improve and the
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo