YoVDO

Keep Your Dependencies in Check

Offered By: GOTO Conferences via YouTube

Tags

GOTO Conferences Courses IntelliJ IDEA Courses Gradle Courses Log4j Courses Software Composition Analysis Courses Dependabot Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore strategies for managing and updating software dependencies in this 38-minute conference talk from GOTO Copenhagen 2023. Learn about the importance of keeping dependencies up-to-date, referencing recent vulnerabilities like Log4Shell and Spring4Shell. Discover tools and techniques for selecting, maintaining, and analyzing dependencies, including package managers, IDEs, and automated bots. Examine the pros and cons of various approaches, from Maven and Gradle to Dependabot and Renovate. Gain insights into software composition analysis, migration tools like Error Prone and OpenRewrite, and best practices for balancing dependency management with delivering business value. Equip yourself with the knowledge to make informed decisions about dependency management in your software projects.

Syllabus

Intro
Open source software
Log4j
Spring4Shell
Do we need this dependency?
Selecting dependencies
Dependency information
Maintain dependencies
Maven
Gradle
Demo
IntelliJ IDEA
Pros & cons
Software composition analysis
Dependabot
Renovate
Snyk open source
Bots: Pros & cons
Migration tools
Error Prone
OpenRewrite
Conclusion
Outro


Taught by

GOTO Conferences

Related Courses

DevSecOps Fundamentals
Cybrary
DevSecOps: Adding Security Testing Tools to Pipelines
Pluralsight
Inspecting Open Source Software Packages for Security and License Compliance
Pluralsight
Security Instrumentation - The Future of Software Security
LASCON via YouTube
5 Open Source Security Tools All Developers Should Know About
All Things Open via YouTube