EPISODE · Feb 20, 2020 · 41 MIN
Jeremy Long — It’s dependency check, not checker
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases? Jeremy Long, founder of OWASP Dependency-Check, explains the evidence-gathering and matching behind software composition analysis. He tells the project’s origin story, discusses accuracy and false positives, and describes how Dependency-Check fits alongside other dependency tools. The conversation explores delayed upgrades, automated update services, supply-chain integrity, and the limits of treating all vulnerabilities alike. Jeremy also explains how teams can begin with a local scan and move checks into their build pipelines. Along the way, he offers a maintainer’s perspective on a widely adopted open-source project and keeps one naming detail clear: it is Dependency-Check, not Dependency-Checker.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jeremy Long:→ Jeremy Long on GitHubMentioned in this episode:→ OWASP Dependency-Check→ OWASP Dependency-Track→ National Vulnerability Database→ JenkinsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Dependency-Check with Jeremy Long02:41 Jeremy’s path into security06:38 The project’s origin story09:43 How Dependency-Check identifies components14:14 Turning component evidence into vulnerability findings16:31 Accuracy and the limits of matching19:49 Maintaining a widely used open-source project21:25 Why available patches still go unapplied26:28 Automated upgrades and the future of SCA28:35 Build integrity and supply-chain security31:17 Adoption and project reach33:08 Local scans and build-pipeline integration38:54 Dependency-Check, not Dependency-Checker40:00 Jeremy’s final advice
Embed this episode
What this episode covers
How do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases? Jeremy Long, founder of OWASP Dependency-Check, explains the evidence-gathering and matching behind software composition analysis. He tells the project’s origin story, discusses accuracy and false positives, and describes how Dependency-Check fits alongside other dependency tools. The conversation explores delayed upgrades, automated update services, supply-chain integrity...
Ready to play
Jeremy Long — It’s dependency check, not checker
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.