Max Mehl

@mxmehl
974 Followers
164 Following
1.2K Posts
Open Sourcerer 🧙‍♂️ Free Software advocate 💪
Casting profane magic at DB Systel (Deutsche Bahn). Board member @fsfe, @openrail Team, formerly @fdroidorg board. REUSE.software evangelist.
Posts in EN & DE.
🌍 Websitehttps://mehl.mx
📨 Contacthttps://mehl.mx/contact
🎤 OpinionsMy own, not my affiliations'
⚧️ Pronounshe/him
Today at 10:00 @ #FOSSbackstage, my colleague @cschum and I are going to talk about "getting real with the supply chain". The session will be about how the #OSPO at #DeutscheBahn generates actionable insights from vast data and navigates the triangle of risk/value/people.
TIL my ΔEₒₖ JND is 0.0036 (and what that actually means). Apparently this is quite good. Can you beat it? https://www.keithcirkel.co.uk/whats-my-jnd/?r=AWwgKP__v8vD
What's My JND?

Find your Just Noticeable Difference in colour perception. How small a colour difference can you actually see?

Ist das noch kreative Guerillawerbung oder schon peinliche Anbiederung an jugendliche Kundschaft? #Wero

Open Source Foundations Consortium Announces Seven New Working Groups

https://nesbitt.io/2026/03/07/announcing-new-working-groups.html

Announcing New Working Groups

The Open Source Foundations Consortium announces seven new working groups.

Andrew Nesbitt

The second presentation overlapped slightly with the first, but emphasized the tooling aspect:

#SBOM lifecycle and blueprint
• Our modular SBOM toolchain for generation, refinement, analysis and storage
• Integration into DevOps workflows
• Our central compliance portal for teams and governance owners
• And how we delight our various users.

This is all heavily based on many great #OpenSource projects, such as those by @anchore and @homebrew.

https://mehl.mx/blog/2026/deutsche-bahns-approach-to-large-scale-sbom-collection-and-use/

[🧵 3/3]

Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use | Max Mehl

At FOSDEM 2026, I presented Deutsche Bahn’s journey from operational need to concrete implementation of large-scale SBOM collection and use. The scale is staggering: approximately 500,000 SBOMs …

Max Mehl

Actually, there were two presentations at #FOSDEM. In the first, I focused on the strategic aspects and context of the Cyber Resilience Act (#CRA).

Why does DB need transparency of its software supply chains? Why is it damn hard to achieve this? How did we come from idea to strategy to implementation? And why do we need less a technological and rather an organizational and cultural shift to succeed?

Answers to these questions in the recording and slides.

https://mehl.mx/blog/2026/software-supply-chain-strategy-at-deutsche-bahn/

[🧵 2/3]

Software Supply Chain Strategy at Deutsche Bahn | Max Mehl

At FOSDEM 2026, I presented Deutsche Bahn’s software supply chain strategy in the context of the EU Cyber Resilience Act (CRA), but made clear from the start that CRA was the context, not the …

Max Mehl

I recently presented Deutsche Bahn's ongoing efforts to make its software supply chains more transparent. For the first time, we publicly shared how we set up the internal program, the principles we follow, the overarching architectural blueprint, and the tools we use to create, store, and analyze 80,000+ SBOMs. All of this is to find out, in real time, which of the over 100,000 software components we are using are where and how. [🧵 1/3]

#DeutscheBahn #SBOM #SupplyChain #CRA #NIS2

RE: https://eupolicy.social/@finnmyrstad/116141082378515849

This video is pure gold just because it makes you laugh about something that is depressingly true.

#enshittification

The big FOSS vendors don't eat their own dogfood – they pay for proprietary groupware

https://www.theregister.com/2026/02/12/suse_runs_ms/

That's… *not* a good idea

<- by me on @theregister

#OpenSourcePolicySummit2026

The big FOSS vendors don't eat their own dogfood – they pay for proprietary groupware

Open Source Policy Summit 2026: That's not a good idea

The Register

At #FOSDEM and want to learn how a large organization such as #DeutscheBahn is getting ready for the #CRA by making its software supply chain transparent with #SBOM?

Join my talk today (15:05) on the strategy we've set up: https://fosdem.org/2026/schedule/event/ZSWH3N-deutsche-bahn-supply-chain-cra-strategy/

...and tomorrow (12:00) with an emphasis on the tooling we're using: https://fosdem.org/2026/schedule/event/7EYTRJ-deutsche-bahn-large-scale-sbom-approach/

I offer facts and diagrams. I seek questions and feedback.