PodParley PodParley

Securing Supply Chains In C++, Java, And JavaScript With Liran Tal And Roy Ram

In episode 133 of The Secure Developer, we delve into the subject of supply chain security across various ecosystems and languages, guided by industry experts Liran Tal and Roy Ram from Snyk. Liran is the Director of Developer Advocacy at Snyk and has a background working particularly in Node.js and JavaScript. Roy is a Senior Product Manager serving as part of the product team for Snyk Code, and has a background in cybersecurity and a solid understanding of C++. With a 20-year background in Java, host Simon Maple moderates the conversation. We discuss the challenges and differences between ecosystems, such as the use of third-party libraries and issues with typosquatting and malicious packages. We also talk about the volume of dependencies that each of our ecosystems pull in, whether you should stay on the latest version or pin to a version, and the importance of software bill of materials (SBOMs). For valuable advice on securing your supply chain in different languages and ecosystems, tune in today!

Episode 133 of the The Secure Developer podcast, hosted by Roy Ram, Simon Maple, Liran Tal, titled "Securing Supply Chains In C++, Java, And JavaScript With Liran Tal And Roy Ram" was published on May 15, 2023 and runs 38 minutes.

May 15, 2023 ·38m · The Secure Developer

0:00 / 0:00

In episode 133 of The Secure Developer, we delve into the subject of supply chain security across various ecosystems and languages, guided by industry experts Liran Tal and Roy Ram from Snyk. Liran is the Director of Developer Advocacy at Snyk and has a background working particularly in Node.js and JavaScript. Roy is a Senior Product Manager serving as part of the product team for Snyk Code, and has a background in cybersecurity and a solid understanding of C++. With a 20-year background in Java, host Simon Maple moderates the conversation. We discuss the challenges and differences between ecosystems, such as the use of third-party libraries and issues with typosquatting and malicious packages. We also talk about the volume of dependencies that each of our ecosystems pull in, whether you should stay on the latest version or pin to a version, and the importance of software bill of materials (SBOMs). For valuable advice on securing your supply chain in different languages and ecosystems, tune in today!

In this episode of The Secure Developer, we delve into the subject of supply chain security across various ecosystems and languages, guided by industry experts Liran Tal and Roy Ram from Snyk. Liran is the Director of Developer Advocacy at Snyk and has a background working particularly in Node.js and JavaScript. Roy is a Senior Product Manager serving as part of the product team for Snyk Code, and has a background in cybersecurity and a solid understanding of C++. With a 20-year background in Java, host Simon Maple moderates the conversation. We discuss the challenges and differences between ecosystems, such as the use of third-party libraries and issues with typosquatting and malicious packages. We also talk about the volume of dependencies that each of our ecosystems pull in, whether you should stay on the latest version or pin to a version, and the importance of software bill of materials (SBOMs). For valuable advice on securing your supply chain in different languages and ecosystems, tune in today!

Follow Us

The Secure World Foundation Podcast Secure World Foundation This podcast features content produced by the Secure World Foundation (SWF), an endowed, private operating foundation that promotes cooperative solutions for space sustainability and the peaceful uses of outer space. The Foundation acts as a research body, convener and facilitator to promote key space security, and other related topics, and to examine their influence on governance and international development. The Secure Woman Podcast Your Lifestylist Im your Lifestylist,Welcome to the Secure Woman podcast. Where I talk about the tools to elevating your thinking, move pass past trauma and we talk about healing is a journey. Our conversations are geared towards help women master their emotions and manifest their dream life, we are moving full throttle pass the pain. This podcast is for those looking to WIN past the pain. Support this podcast: https://podcasters.spotify.com/pod/show/yourlifestylist/support Secure the Future Dave Maasland Secure the Future is een maandelijkse podcast over digitale beveiliging. Met CISO’s, voor CISO’s. Over hoe we vandaag beschermen om morgen veiliger te zijn.Ik ben Dave Maasland en in de Secure the Future podcast ga ik in gesprek met vooraanstaande securityleiders in ons land. Je leert als CISO hoe vakcollega’s naar dit vak kijken, juist in deze tijd. Hoe gaan we om met de huidige ransomwarecrisis? Hoe bereiden we ons voor op dreigingen in de toekomst? Hoe begin je in het CISO-vak? En hoe zet je een sterk securityframework neer?Kortom: het is tijd om CISO’s in Nederland met elkaar te verbinden en meer kennis uit te wisselen. Natuurlijk ga ik ook met hen in gesprek over wie ze zijn als mens en hoe ze hier zijn gekomen.Luister daarom elke maand naar de Secure the Future podcast dé podcast over digitale beveiliging met CISO’s, voor CISO’s. The Reezy London Podcast The Reezy London Podcast Diving into the mind of Reezy London on his quest to secure financial longevity, happiness, & his interests in today’s world
URL copied to clipboard!