EPISODE · Apr 12, 2018 · 48 MIN
Steve Springett -- Dependency Check and Dependency Track
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Finding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization? Steve Springett explains how OWASP Dependency-Check and Dependency-Track complement each other in a software composition analysis program. He starts with the ingredients of modern applications, then distinguishes build-time analysis from maintaining a portfolio-wide inventory that can respond to newly disclosed vulnerabilities. The conversation covers language support, dependency updates, vulnerability data quality, and the differences between open-source and commercial tools. Steve offers practical guidance for integrating checks into build pipelines, triaging findings with developers, and making security part of engineering culture. He also looks beyond reactive vulnerability chasing toward software that is easier to maintain and update throughout its life.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Springett:→ Steve Springett on GitHubMentioned in this episode:→ OWASP Dependency-Check→ OWASP Dependency-Track→ National Vulnerability Database→ SPDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Dependency-Check and Dependency-Track with Steve Springett04:29 Understanding software composition analysis05:56 Why dependency visibility matters08:31 Equifax and the challenge of upgrading components11:58 The origins of Dependency-Check15:32 Language support and build analysis16:50 Why Dependency-Track was created18:40 Tracking vulnerabilities across a portfolio23:06 How the two projects work together26:48 Open-source and commercial SCA tools28:50 Vulnerability data quality and noise33:08 Starting with build integration36:01 Helping developers triage findings38:12 Overcoming adoption objections41:44 The future of dependency security45:03 Toward continuously updated software
Embed this episode
What this episode covers
Finding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization? Steve Springett explains how OWASP Dependency-Check and Dependency-Track complement each other in a software composition analysis program. He starts with the ingredients of modern applications, then distinguishes build-time analysis from maintaining a portfolio-wide inventory that can respond to newly disclosed vulnerabilities. The conversation covers language su...
Ready to play
Steve Springett -- Dependency Check and Dependency Track
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.