Steve Springett — OWASP Dependency Track — 5 Minute AppSec episode artwork

EPISODE · Aug 25, 2019 · 4 MIN

Steve Springett — OWASP Dependency Track — 5 Minute AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. Steve also covers outdated-component detection, package ecosystems, and license analysis through SPDX. This concise introduction presents Dependency-Track as a software supply-chain component analysis platform built to turn a constantly changing inventory into actionable risk information rather than a one-time list of dependencies.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Springett:→ Steve Springett on LinkedIn→ OWASP Dependency-TrackMentioned in this episode:→ OWASP Dependency-Track→ National Vulnerability Database→ Sonatype OSS Index→ SPDX→ HeartbleedFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 What is OWASP Dependency-Track?00:16 Analyzing components and SBOMs at enterprise scale02:16 Vulnerability intelligence and outdated components03:25 APIs, webhooks, and actionable intelligence04:12 Continue with the full SCA interview

Episode metadata supplied by the publisher feed · Published Aug 25, 2019

Embed this episode

What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. S...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steve Springett — OWASP Dependency Track — 5 Minute AppSec

0:00 4:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 4 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 25, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!