Erlend Oftedal  -- What You Require, You Must Also Retire episode artwork

EPISODE · Oct 30, 2018 · 30 MIN

Erlend Oftedal -- What You Require, You Must Also Retire

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A JavaScript library can keep working long after its security problems become public. Retire.js project leader Erlend Oftedal explains how developers can discover vulnerable dependencies and make that information part of everyday development. He describes the project’s origins, command line scanning, browser-based detection, and options for integrating checks into a build pipeline. Chris probes what happens after a finding, how exceptions can undermine the process, and how externally loaded libraries fit into the picture. They also discuss Retire.js alongside npm auditing, OWASP Dependency-Check, and Dependency-Track. Erlend’s experience leading an OWASP chapter adds a community perspective to the technical discussion. The practical message is to know which libraries you ship and make upgrading them a continuing engineering responsibility.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Erlend Oftedal:→ Erlend Oftedal on LinkedIn→ Retire.jsMentioned in this episode:→ Retire.js source code→ OWASP Dependency-Check→ OWASP Dependency-Track→ OWASP Proactive ControlsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Finding vulnerable JavaScript with Erlend Oftedal01:54 A developer’s path into security07:07 Running an OWASP chapter10:27 Why Retire.js was created12:34 Scanning locally and in a pipeline14:16 The danger of ignoring every finding15:29 Reading scan results and the role of npm audit17:45 Upgrading vulnerable libraries19:05 Detecting libraries loaded from other sites20:32 Passive discovery in the browser22:05 Working with Dependency-Check and Dependency-Track24:27 Open-source and commercial dependency tools28:21 The limits of automated coverage

Episode metadata supplied by the publisher feed · Published Oct 30, 2018

Embed this episode

A JavaScript library can keep working long after its security problems become public. Retire.js project leader Erlend Oftedal explains how developers can discover vulnerable dependencies and make that information part of everyday development. He describes the project’s origins, command line scanning, browser-based detection, and options for integrating checks into a build pipeline. Chris probes what happens after a finding, how exceptions can undermine the process, and how externally loaded l...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Erlend Oftedal -- What You Require, You Must Also Retire

0:00 30:41

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 30 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 30, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!