Steve Springett — An insiders checklist for Software Composition Analysis episode artwork

EPISODE · Aug 27, 2019 · 50 MIN

Steve Springett — An insiders checklist for Software Composition Analysis

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

An SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered. Steve Springett, creator of Dependency-Track and CycloneDX, shares the detailed criteria he used to evaluate commercial and open-source tools. He starts with accurate component inventories, then examines package management, licenses, maintenance status, provenance, policy enforcement, and integration with real development environments. Steve cautions against treating an unconfirmed exploit path as proof that a dependency is safe and explains why project health belongs in risk decisions. The conversation also introduces software bills of materials and compares binary, manifest, and SBOM analysis. This archive discussion provides a concrete way to define requirements and test competing tools against the software an organization actually builds.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Springett:→ Steve Springett on GitHubMentioned in this episode:→ OWASP Dependency-Track→ CycloneDX→ SPDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 An insider’s SCA checklist with Steve Springett03:02 Understanding software supply-chain risk06:16 What software composition analysis should provide08:13 Risk intelligence beyond known vulnerabilities09:33 Evaluating the SCA market at the time13:57 Defining requirements for a tool comparison14:50 Start with an accurate component inventory15:41 Ecosystems, package management, provenance, and SBOM support24:07 Testing tools against your organization’s needs28:43 Policy enforcement and exploitability caveats30:29 Onboarding, integration, and component age33:08 Project health and limiting dependency sprawl34:49 Reviewing the complete evaluation checklist38:27 Software bills of materials explained43:22 Using SBOMs to improve inventory accuracy45:24 Combining binary, manifest, and SBOM analysis47:45 Dependency-Track project update

Episode metadata supplied by the publisher feed · Published Aug 27, 2019

Embed this episode

An SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered. Steve Springett, creator of Dependency-Track and CycloneDX, shares the detailed criteria he used to evaluate commercial and open-source tools. He starts with accurate component inventories, then examines package management, licenses, maintenance status, provenance, policy enforcement, and integration with real development environments. Steve cautions against treating an unconfirmed ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steve Springett — An insiders checklist for Software Composition Analysis

0:00 50:49

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 50 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 27, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!