RomHack Camp 2026

SBOM SBAM: Who Put This in My Code? Enterprise-Grade Supply Chain Security on a Zero Budget
2026-10-03 , STAGE 2 (Ghost in the Shellcode)
Language: Italiano

Modern software is assembled, not just written: nearly 90% of a typical application consists of third-party libraries. If a critical vulnerability like Log4Shell were disclosed tomorrow, how long would it take your team to identify every affected microservice? While large enterprises rely on expensive "Ultimate" licenses, SMEs and independent teams often face a dangerous security gap.
In this session, we will explore how to democratize Software Supply Chain Security (SSCS) by building an automated defense perimeter at zero licensing cost. Through a Live Demo featuring a Docker-based prototype, we will walk through a real-world architecture integrating:
• GitLab Community Edition for pipeline orchestration.
• Trivy and cdxgen for automated SBOM (Software Bill of Materials) generation in CycloneDX format.
• OWASP Dependency-Track for continuous, proactive vulnerability monitoring.
We will go beyond basic scanning by demonstrating how to leverage Artificial Intelligence for code reachability analysis, generating VEX (Vulnerability Exploitability eXchange) files to silence false positives and focus only on actionable risks. We will also discuss how this stack prepares organizations for the upcoming EU Cyber Resilience Act (CRA) requirements.

AWS HERO | Senior Engineering Manager | IT Strategy & AI Governance | Infrastructure Architect | Bridging Tech & Business Goals

Trasformo la visione di business in infrastrutture tecnologiche scalabili e performanti. Con oltre 15 anni di esperienza, di cui 10+ focalizzati su architetture Cloud-native e governance di programmi complessi, guido la digitalizzazione della Pubblica Amministrazione e delle imprese con un approccio "hands-on" che garantisce concretezza e velocità di delivery.

Perché collaborare con me:

  • Governance su larga scala: Ho gestito portafogli progetti >4M€, coordinando team multi-vendor di 50+ persone con piena responsabilità su budget e KPI.
  • Efficienza operativa: Ho ridotto i cicli di release del 60% attraverso l'adozione di pratiche DevOps, CI/CD e Infrastructure as Code (Terraform).
  • Visione Architetturale: Guido migrazioni cloud end-to-end (AWS) e modernizzazione di sistemi legacy tramite API-first design e microservizi.
  • Leadership & Community: Founder di GDG e AWS User Group Basilicata, credo nel valore dell'evangelismo tecnologico e della formazione come motori di crescita aziendale.

Specializzato nel "bridging" tra stakeholder C-level e team di sviluppo, garantisco che ogni scelta tecnologica sia un investimento orientato al valore.