Assessing NuGet Packages with Security Scorecards
Offered By: NDC Conferences via YouTube
Course Description
Overview
Explore the critical topic of assessing NuGet packages for security risks in this 54-minute conference talk from NDC Security in Oslo. Learn about the importance of evaluating third-party code, which often comprises up to 80% of modern applications. Discover how OpenSSF Scorecards can provide a "nutrition label" for software packages, helping developers make informed decisions about their dependencies. Examine various aspects of package security, including maintenance practices, build workflows, and the use of security tools. Delve into additional considerations specific to NuGet packages, such as reproducibility, .NET API usage, and code security reviews. Gain valuable insights to improve your ability to assess the security posture of NuGet packages and enhance your overall application security.
Syllabus
Assessing NuGet Packages more easily with Security Scorecards - Niels Tanis
Taught by
NDC Conferences
Related Courses
Security Is an Ecosystem - We Can't Be Secure in IsolationLinux Foundation via YouTube Improving the Security of a Large Open Source Project One Step at a Time
Linux Foundation via YouTube Simplifying Coordinating Vulnerabilities and Disclosures in Open Source Projects
Linux Foundation via YouTube SLSA in Action: Securing the Software Supply Chain
Linux Foundation via YouTube Implementing OpenSSF Best Practices Badges and Scorecards for Project Security
Linux Foundation via YouTube