Kiko Fernandez-Reyes, Ericsson

Supply chain best practices are a necessity in the current world, and even more at Ericsson, with the entry of Cyber Resillience Act (CRA) and update to the NIST CSF 2.0.
Ericsson maintains and develops Erlang/OTP, an open source project that has been alive for 40 years, which is used also by well-known companies, such as WhatsApp, Cisco, Klarna, Kivra, and Discord, among others.
In this presentation, Kiko (core member of Erlang/OTP) provides a deep dive into how the Erlang/OTP team has lead the implementation of supply-chain best practices for the BEAM community, with support from the Erlang Ecosystem Foundation.
Topics covered include:
- Creation of source SBOM for Erlang/OTP and the whole BEAM community,
- Contribution towards key compliance open source tools for the benefit of Ericsson and the BEAM community (oss-review-toolkit, reuse, scorecard, etc),
- Automated vulnerability scanning of Erlang/OTP third party dependencies applicable to any project,
- Vulnerability handling in collaboration with the Erlang Ecosystem Foundation as CNA,
- Automated generation of VEX (OpenVEX) statements for downstream consumers of Erlang/OTP, and
- Monitoring of all of these automations in Github
This presentation teaches lessons learnt and open source tooling to do compliance and vulnerability scanning, shows supply chain best practices that open source projects should exhibit, and ultimately guides programmers into what to look for before choosing an open source tool/library/programming language.
Conference partners







Organiser
