Find and Track the Hidden Vulnerabilities Inside Your Dependencies
Offered By: Devoxx via YouTube
Course Description
Overview
Discover how to identify and monitor hidden vulnerabilities in your application dependencies in this 27-minute conference talk from Devoxx. Learn about vulnerability indexing systems like NVD and CVE, as well as severity scoring using CVSS. Explore the creation of a Continuous Security pipeline using Jenkins and open-source tools such as OWASP DependencyCheck and DependencyTrack. Gain insights into the DevSecOps philosophy and see practical demonstrations of vulnerability detection, tracking, and mitigation. Cover topics including the National Phenology Database, Heartbleed, common vulnerability scoring, and specific vulnerabilities in popular frameworks like Spring and Jackson. Walk through the process of fixing vulnerabilities, checking base code and dependencies, and implementing security measures using Jenkins plugins, Docker images, and API keys.
Syllabus
Intro
Risk
Introduction
National Phenology Database
Heartbleed
Common Vulnerability Scoring System
Dependency Check
Demo
Dependency Track
Springwood vulnerability
Jackson vulnerability
Fixing the vulnerability
Checking the base code
Checking the dependencies
Jenkins plugin
Jenkins report
Docker image
API Key
Flag Security Vulnerability
Taught by
Devoxx
Related Courses
Play by Play: Developing Microservices and Mobile Apps with JHipsterPluralsight Software Archaeology - Learning from the Landing on the Moon
Devoxx via YouTube Create an Eco-Friendly World with Green Software Engineering
Devoxx via YouTube Platform Building for Data Mesh - Show Me How It Is Done
Devoxx via YouTube The Hitchhiker's Guide to Software Architecture and Design
Devoxx via YouTube