Liran Tal — The state of open source software security episode artwork

EPISODE · Sep 5, 2019 · 34 MIN

Liran Tal — The state of open source software security

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Developers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research. After sharing how running a bulletin board system sparked his curiosity, he explains the report's mix of survey responses, dependency data, and public ecosystem information. They discuss vulnerable libraries in popular container images, why updating a base image can matter, and the hesitation developers feel when dependency changes might break an application. Liran also explores how vulnerabilities can remain unnoticed for years. He closes with three priorities for improvement: make security accessible, treat it as part of product quality, and celebrate developers who find and fix problems.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Liran Tal:→ LinkedIn→ GitHubMentioned in this episode:→ 2019 State of Open Source Security — developer ownership findings→ Docker Hub→ Node.js→ Libraries.ioFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:23 BBS roots and early computing04:38 Finding a path into application security06:41 Curiosity and learning by building11:00 The data behind the open-source report12:11 Combining survey and ecosystem sources12:40 Developers want to own security15:13 Vulnerabilities in popular container images17:32 Base images, trust, and practical fixes20:13 Updating dependencies without breaking the application23:59 Vulnerabilities that remain dormant for years26:23 The window before discovery27:52 Three priorities for improving open-source security31:43 Connecting with Liran

Episode metadata supplied by the publisher feed · Published Sep 5, 2019

Embed this episode

Developers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research. After sharing how running a bulletin board system sparked his curiosity, he explains the report's mix of survey responses, dependency data, and public ecosystem information. They discuss vulnerable libraries in popular container images, why updating a base image can matter, and the hesitation developer...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Liran Tal — The state of open source software security

0:00 34:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 34 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 5, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!