
The
Transparency Exchange API (TEA) is designed to make software transparency interoperable. It defines a secure, standardized way for systems to request and retrieve supply chain artifacts — like SBOMs, CBOMs, and attestations — across organizational boundaries.
As software supply chains grow more interconnected, TEA provides the missing link: a common language for exchanging trust. This hackathon is where we test that language in practice — validating the first beta of the TEA specification with real implementations and real feedback.
HOW WE'LL WORKThis is a working session, not a competition. We're bringing together open source leaders, commercial vendors, and transparency advocates to test-drive Beta 1 of the TEA specification. You’ll collaborate, test, break, and refine — together.
We'll validate:
- Can the API be implemented as designed?
- Do use cases hold up under real-world conditions?
- Are we enabling meaningful, actionable transparency?
CycloneDX is already standardized through Ecma. TEA is next. Your insights at this event will directly shape its trajectory.
WHAT TO EXPECT- Deep-dive on TEA Beta 1 and CycloneDX ecosystem
- Hands-on working sessions with other engineers and architects
- Opportunities to test cross-implementation interoperability
- Transparent feedback loops to improve the specification
Whether you’re building tools, integrating SBOM workflows, or supporting standards adoption — this is your opportunity to contribute directly to the future of software transparency infrastructure.
Registration for the hackathon is free, thanks to the generous support of the
OWASP Foundation and
Ecma International. Separate registration is required for those interested in attending the OWASP Global AppSec conference, but registration for the conference is not required to attend the hackathon.
https://cyclonedx.org/events/hackathon-barcelona-2025/