Steve Springett  -- Dependency Check and Dependency Track episode artwork

EPISODE · Apr 12, 2018 · 48 MIN

Steve Springett -- Dependency Check and Dependency Track

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Finding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization? Steve Springett explains how OWASP Dependency-Check and Dependency-Track complement each other in a software composition analysis program. He starts with the ingredients of modern applications, then distinguishes build-time analysis from maintaining a portfolio-wide inventory that can respond to newly disclosed vulnerabilities. The conversation covers language support, dependency updates, vulnerability data quality, and the differences between open-source and commercial tools. Steve offers practical guidance for integrating checks into build pipelines, triaging findings with developers, and making security part of engineering culture. He also looks beyond reactive vulnerability chasing toward software that is easier to maintain and update throughout its life.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Springett:→ Steve Springett on GitHubMentioned in this episode:→ OWASP Dependency-Check→ OWASP Dependency-Track→ National Vulnerability Database→ SPDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Dependency-Check and Dependency-Track with Steve Springett04:29 Understanding software composition analysis05:56 Why dependency visibility matters08:31 Equifax and the challenge of upgrading components11:58 The origins of Dependency-Check15:32 Language support and build analysis16:50 Why Dependency-Track was created18:40 Tracking vulnerabilities across a portfolio23:06 How the two projects work together26:48 Open-source and commercial SCA tools28:50 Vulnerability data quality and noise33:08 Starting with build integration36:01 Helping developers triage findings38:12 Overcoming adoption objections41:44 The future of dependency security45:03 Toward continuously updated software

Episode metadata supplied by the publisher feed · Published Apr 12, 2018

Embed this episode

Finding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization? Steve Springett explains how OWASP Dependency-Check and Dependency-Track complement each other in a software composition analysis program. He starts with the ingredients of modern applications, then distinguishes build-time analysis from maintaining a portfolio-wide inventory that can respond to newly disclosed vulnerabilities. The conversation covers language su...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steve Springett -- Dependency Check and Dependency Track

0:00 48:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 48 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 12, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!