Loading…
Tuesday October 6, 2026 15:45 - 16:03 CEST
Modern software supply chains have evolved into vast, heterogeneous networks where transparency — the granular understanding of all software components — is now a critical security requirement. While Software Bills of Materials (SBOMs) have emerged as the primary mechanism for this transparency, current industry practices rely on a metadata-centric paradigm that assumes an artifact is defined solely by its package manager declarations. We posit that this assumption is fundamentally flawed, creating a systemic visibility gap we define as Software Dark Matter (SDM). SDM is the set of files present in an artifact's filesystem that are unaccounted for by its associated metadata. We implement a reference tool, DARKFILES, and use it to analyze four ecosystems of disjoint nature: DockerHub, bundling-prone Maven Central artifacts, extension marketplaces (Jenkins plugins and OpenVSX), and a real-world enterprise environment.
Speakers
DR

Dennis Roellke

Security Architect, Office of the CTO, Bloomberg
Dennis Roellke is a Security Architect in the Office of the CTO at Bloomberg, where he provides strategic advice to the company's software supply chain security program. His influence spans multiple departments within the firm, orchestrating a secure software development lifecycle... Read More →
AR

Abhishek Reddypalle

PhD Researcher, Trustworthy Software Ecosystems Lab, Purdue University
Abhishek Reddypalle is a PhD researcher at Purdue University's Trustworthy Software Ecosystems Lab, where he works on software supply-chain security. His research includes work on reproducible builds and SBOM completeness, with a focus on build-time techniques for producing SBOMs... Read More →
Tuesday October 6, 2026 15:45 - 16:03 CEST
South Hall 3A

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link