Jeremy Long — It’s dependency check, not checker episode artwork

EPISODE · Feb 20, 2020 · 41 MIN

Jeremy Long — It’s dependency check, not checker

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases? Jeremy Long, founder of OWASP Dependency-Check, explains the evidence-gathering and matching behind software composition analysis. He tells the project’s origin story, discusses accuracy and false positives, and describes how Dependency-Check fits alongside other dependency tools. The conversation explores delayed upgrades, automated update services, supply-chain integrity, and the limits of treating all vulnerabilities alike. Jeremy also explains how teams can begin with a local scan and move checks into their build pipelines. Along the way, he offers a maintainer’s perspective on a widely adopted open-source project and keeps one naming detail clear: it is Dependency-Check, not Dependency-Checker.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jeremy Long:→ Jeremy Long on GitHubMentioned in this episode:→ OWASP Dependency-Check→ OWASP Dependency-Track→ National Vulnerability Database→ JenkinsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Dependency-Check with Jeremy Long02:41 Jeremy’s path into security06:38 The project’s origin story09:43 How Dependency-Check identifies components14:14 Turning component evidence into vulnerability findings16:31 Accuracy and the limits of matching19:49 Maintaining a widely used open-source project21:25 Why available patches still go unapplied26:28 Automated upgrades and the future of SCA28:35 Build integrity and supply-chain security31:17 Adoption and project reach33:08 Local scans and build-pipeline integration38:54 Dependency-Check, not Dependency-Checker40:00 Jeremy’s final advice

Episode metadata supplied by the publisher feed · Published Feb 20, 2020

Embed this episode

How do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases? Jeremy Long, founder of OWASP Dependency-Check, explains the evidence-gathering and matching behind software composition analysis. He tells the project’s origin story, discusses accuracy and false positives, and describes how Dependency-Check fits alongside other dependency tools. The conversation explores delayed upgrades, automated update services, supply-chain integrity...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Jeremy Long — It’s dependency check, not checker

0:00 41:23

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 41 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 20, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!