EPISODE · Mar 4, 2025 · 38 MIN
Henrik Plate -- OWASP Top 10 Open Source Risks
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Our discussion also includes the need for a dedicated open-source risk list, and the importance of addressing known vulnerabilities, unmaintained projects, immature software, and more. Henrik Plate is the principal security researcher at Endor Labs. He formerly worked for SAP Security Research, where he led the focus topic open source security starting in 2014.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Henrik Plate:→ The OWASP Top 10 Open Source Risks→ Endor LabsMentioned in this episode:→ The OWASP Top 10 Open Source Risks→ Endor Labs→ OpenSSFFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Henrik Plate: OWASP Top 10 Open Source Risks01:42 We're back on the world of OWASP. We've, we've been away04:39 Yeah, Henrik, uh, just curious. So, uh, we're talking about the08:17 The order in this list mean something, or are these all10:29 Yeah. So if I'm a developer, what, how do I use12:47 I wonder if we could start to walk through the list19:43 This, XZ was a more modern example of this, right22:13 Yeah. And that's, and that's a common problem in the open24:28 All right, so what is 428:28 Okay. So Robert, why don't you, uh, pick one between 831:57 All right, Henrik, we have 3 questions that we typically ask35:01 Uh, the 3rd question is, what's your top book recommendation and
Embed this episode
What this episode covers
Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Ou...
Ready to play
Henrik Plate -- OWASP Top 10 Open Source Risks
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.