Loading…
May 21, 2026 | Minneapolis, Minnesota, USA
Learn More and Register To Attend
Schedule is subject to change.

The Sched app allows you to build your schedule, but it is not a substitute for event registration. To participate in the sessions, you must be registered for OpenSSF Community Day NA 2026. If you have not registered but would like to join us, please visit the event registration page to purchase a ticket.












Thursday May 21, 2026 12:05pm - 12:20pm CDT
Software supply chain risk assessments increasingly rely on Software Bill of Materials (SBOMs), yet their practical value is often tested under severe time constraints. In Mergers and Acquisitions (M&A) due diligence, Application Security (AppSec) teams are frequently required to assess large codebases and their third-party dependencies within days or weeks, where the goal is informed risk visibility rather than exhaustive remediation.

This talk presents a practitioner’s perspective on using SBOMs to prioritize software supply chain risk under tight M&A timelines. Drawing from real-world due-diligence engagements, it explores how AppSec teams analyze SBOMs to identify high-impact dependencies, assess transitive risk, and correlate vulnerability intelligence with open-source license obligations that may influence post-acquisition risk.

The session also addresses common challenges such as incomplete SBOMs, noisy vulnerability data, unclear license declarations, and limited exploit or usage context. The emphasis is on practical, risk-based prioritization techniques and legal-safe framing of findings.

Attendees will leave with practical guidance on using SBOMs as a decision-support mechanism, rather than just as compliance artifacts.
Speakers
avatar for Prashanth Chandrasekar

Prashanth Chandrasekar

Principal Consultant, Bitsea
Prashanth Chandrasekar is an Application Security practitioner and Open Source Consultant at Bitsea, focused on software supply chain risk and SBOM-driven analysis for stakeholders. He brings hands-on experience from time-bound due-diligence engagements, helping teams prioritize vulnerability... Read More →
Thursday May 21, 2026 12:05pm - 12:20pm CDT
101E

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link