EPISODE · Aug 27, 2019 · 50 MIN
Steve Springett — An insiders checklist for Software Composition Analysis
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
An SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered. Steve Springett, creator of Dependency-Track and CycloneDX, shares the detailed criteria he used to evaluate commercial and open-source tools. He starts with accurate component inventories, then examines package management, licenses, maintenance status, provenance, policy enforcement, and integration with real development environments. Steve cautions against treating an unconfirmed exploit path as proof that a dependency is safe and explains why project health belongs in risk decisions. The conversation also introduces software bills of materials and compares binary, manifest, and SBOM analysis. This archive discussion provides a concrete way to define requirements and test competing tools against the software an organization actually builds.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Springett:→ Steve Springett on GitHubMentioned in this episode:→ OWASP Dependency-Track→ CycloneDX→ SPDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 An insider’s SCA checklist with Steve Springett03:02 Understanding software supply-chain risk06:16 What software composition analysis should provide08:13 Risk intelligence beyond known vulnerabilities09:33 Evaluating the SCA market at the time13:57 Defining requirements for a tool comparison14:50 Start with an accurate component inventory15:41 Ecosystems, package management, provenance, and SBOM support24:07 Testing tools against your organization’s needs28:43 Policy enforcement and exploitability caveats30:29 Onboarding, integration, and component age33:08 Project health and limiting dependency sprawl34:49 Reviewing the complete evaluation checklist38:27 Software bills of materials explained43:22 Using SBOMs to improve inventory accuracy45:24 Combining binary, manifest, and SBOM analysis47:45 Dependency-Track project update
Embed this episode
What this episode covers
An SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered. Steve Springett, creator of Dependency-Track and CycloneDX, shares the detailed criteria he used to evaluate commercial and open-source tools. He starts with accurate component inventories, then examines package management, licenses, maintenance status, provenance, policy enforcement, and integration with real development environments. Steve cautions against treating an unconfirmed ...
Ready to play
Steve Springett — An insiders checklist for Software Composition Analysis
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.