Henrik Plate -- OWASP Top 10 Open Source Risks episode artwork

EPISODE · Mar 4, 2025 · 38 MIN

Henrik Plate -- OWASP Top 10 Open Source Risks

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Our discussion also includes the need for a dedicated open-source risk list, and the importance of addressing known vulnerabilities, unmaintained projects, immature software, and more. Henrik Plate is the principal security researcher at Endor Labs. He formerly worked for SAP Security Research, where he led the focus topic open source security starting in 2014.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.→ Learn more about Security JourneyConnect with Henrik Plate:→ The OWASP Top 10 Open Source Risks→ Endor LabsMentioned in this episode:→ The OWASP Top 10 Open Source Risks→ Endor Labs→ OpenSSFFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Henrik Plate: OWASP Top 10 Open Source Risks01:42 We're back on the world of OWASP. We've, we've been away04:39 Yeah, Henrik, uh, just curious. So, uh, we're talking about the08:17 The order in this list mean something, or are these all10:29 Yeah. So if I'm a developer, what, how do I use12:47 I wonder if we could start to walk through the list19:43 This, XZ was a more modern example of this, right22:13 Yeah. And that's, and that's a common problem in the open24:28 All right, so what is 428:28 Okay. So Robert, why don't you, uh, pick one between 831:57 All right, Henrik, we have 3 questions that we typically ask35:01 Uh, the 3rd question is, what's your top book recommendation and

Episode metadata supplied by the publisher feed · Published Mar 4, 2025

Embed this episode

Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Ou...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Henrik Plate -- OWASP Top 10 Open Source Risks

0:00 38:26

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 38 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on March 4, 2025.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!