EPISODE · Sep 5, 2019 · 34 MIN
Liran Tal — The state of open source software security
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Developers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research. After sharing how running a bulletin board system sparked his curiosity, he explains the report's mix of survey responses, dependency data, and public ecosystem information. They discuss vulnerable libraries in popular container images, why updating a base image can matter, and the hesitation developers feel when dependency changes might break an application. Liran also explores how vulnerabilities can remain unnoticed for years. He closes with three priorities for improvement: make security accessible, treat it as part of product quality, and celebrate developers who find and fix problems.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Liran Tal:→ LinkedIn→ GitHubMentioned in this episode:→ 2019 State of Open Source Security — developer ownership findings→ Docker Hub→ Node.js→ Libraries.ioFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:23 BBS roots and early computing04:38 Finding a path into application security06:41 Curiosity and learning by building11:00 The data behind the open-source report12:11 Combining survey and ecosystem sources12:40 Developers want to own security15:13 Vulnerabilities in popular container images17:32 Base images, trust, and practical fixes20:13 Updating dependencies without breaking the application23:59 Vulnerabilities that remain dormant for years26:23 The window before discovery27:52 Three priorities for improving open-source security31:43 Connecting with Liran
Embed this episode
What this episode covers
Developers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research. After sharing how running a bulletin board system sparked his curiosity, he explains the report's mix of survey responses, dependency data, and public ecosystem information. They discuss vulnerable libraries in popular container images, why updating a base image can matter, and the hesitation developer...
Ready to play
Liran Tal — The state of open source software security
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.