Перейти к содержимому

ReARM Community Edition - Black Hat USA 2026 Arsenal Demo

Reliza

0:00 / 0:00

ReARM Community Edition - Black Hat USA 2026 Arsenal Demo

29 просмотров · 13 дней назад
Reliza
26 подписчиков
29 просмотров · 13 дней назад
Most software supply-chain tooling tells you what's broken. This demo shows the whole loop: an SBOM-backed view of your component and product releases, VEX applied against it, and an AI agent fixing a live CVE end to end — with every commit it makes signed and attributed back to the release. Recorded on ReARM Community Edition, the free and open-source edition of the ReARM release governance platform by Reliza. The demo application is Mafia Card Shuffle: a Node/Express backend, a Vue frontend and a Helm chart, all built by CI and registered to ReARM on every push. The demo shows: Overview: the security dashboard in ReARM CE Components, releases and the SBOM behind each one VEX: importing contradictory vendor statements Staged vs auto-accepted statements, and why the difference matters Live remediation: an AI agent reads the findings from ReARM Signed commits, agent session attribution, CI rebuild and re-scan Posture after the fix WHAT'S IN IT The dashboard. ReARM keeps a release-level record of every build: the SBOM and other security artifacts, the deliverables, and the vulnerability posture that comes from scanning them. Because scans re-run on a schedule, the posture of a release you shipped weeks ago keeps moving as the world learns about new CVEs. VEX. Real vulnerability exchange documents disagree with each other. The document imported here deliberately carries contradictory statements from different vendors about the same components, so you can see how ReARM handles them: statements can be staged for human review rather than trusted on arrival, or auto-accepted where the source is trusted, and only then do they move the numbers. Live remediation. The agent doesn't scan anything locally, it reads the findings off ReARM, bumps the affected dependencies, and commits. The commits are signed, and carry the agent's session identity, so the resulting release shows up in ReARM with its signature verified and its authorship resolved to that agent rather than to an anonymous CI run. CI rebuilds, ReARM re-scans, and the new release's posture is the proof the fix landed. One detail worth watching for: an earlier attempt at this fix removed the package managers in a later image layer, and the numbers didn't move. ReARM via cdxgen reads every layer in the image history, so deleting a thing later doesn't unship it. The fix that worked was a two-stage build onto a distroless runtime. LINKS ReARM CE source: https://github.com/relizaio/rearm ReARM main website: https://rearmhq.com Public ReARM Demo (ReARM Pro): https://demo.rearmhq.com Demo application: https://github.com/relizaio/card-shuffle #sbom #vex #supplychainsecurity #devsecops #cyclonedx #aiagents #opensource