Artwork

Content provided by ink8r. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ink8r or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode #29 - Tackling the biggest problem affecting code … dependency lifecycle management

27:20
 
Share
 

Manage episode 362646903 series 3298179
Content provided by ink8r. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ink8r or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

As it turns out, managing Open Source Software (OSS) dependencies is extremely difficult. Not all vulnerabilities are in runtime and/or reachable, not all exploits focus on high/critical CVSS, there is a time delay with patches when they are made available, and Semantic Versioning (SerVer) can make prioritization challenging when thinking through backward compatibility, upgrade paths, version pinning in supply chain, etc.
Though estimates vary based on source, some 80% of deployed code is now OSS with 95% of vulnerabilities taking place in transitive dependencies. What’s more, when looking at the Census II report () approximately 50% of all packages tracked did NOT have a release in 2022. This is an intractable problem and a reason why Endor Labs started development back in 2021.
As they so eloquently state, “Software ages like milk, not like wine”.
In this podcast episode, Satbir and Darren explore the Software Composition Analysis (SCA) domain with Varun Badhwar, CEO/Founder of Endor Labs, regarding how to focus teams on the most relevant vulnerabilities associated with their OSS code and how many AppSec programs are starting to focus efforts in this area.

  continue reading

45 episodes

Artwork
iconShare
 
Manage episode 362646903 series 3298179
Content provided by ink8r. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ink8r or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

As it turns out, managing Open Source Software (OSS) dependencies is extremely difficult. Not all vulnerabilities are in runtime and/or reachable, not all exploits focus on high/critical CVSS, there is a time delay with patches when they are made available, and Semantic Versioning (SerVer) can make prioritization challenging when thinking through backward compatibility, upgrade paths, version pinning in supply chain, etc.
Though estimates vary based on source, some 80% of deployed code is now OSS with 95% of vulnerabilities taking place in transitive dependencies. What’s more, when looking at the Census II report () approximately 50% of all packages tracked did NOT have a release in 2022. This is an intractable problem and a reason why Endor Labs started development back in 2021.
As they so eloquently state, “Software ages like milk, not like wine”.
In this podcast episode, Satbir and Darren explore the Software Composition Analysis (SCA) domain with Varun Badhwar, CEO/Founder of Endor Labs, regarding how to focus teams on the most relevant vulnerabilities associated with their OSS code and how many AppSec programs are starting to focus efforts in this area.

  continue reading

45 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide