EPISODE · Aug 25, 2019 · 4 MIN
Steve Springett — OWASP Dependency Track — 5 Minute AppSec
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. Steve also covers outdated-component detection, package ecosystems, and license analysis through SPDX. This concise introduction presents Dependency-Track as a software supply-chain component analysis platform built to turn a constantly changing inventory into actionable risk information rather than a one-time list of dependencies.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Springett:→ Steve Springett on LinkedIn→ OWASP Dependency-TrackMentioned in this episode:→ OWASP Dependency-Track→ National Vulnerability Database→ Sonatype OSS Index→ SPDX→ HeartbleedFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 What is OWASP Dependency-Track?00:16 Analyzing components and SBOMs at enterprise scale02:16 Vulnerability intelligence and outdated components03:25 APIs, webhooks, and actionable intelligence04:12 Continue with the full SCA interview
Embed this episode
What this episode covers
What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. S...
Ready to play
Steve Springett — OWASP Dependency Track — 5 Minute AppSec
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.