Managing Vulnerabilities in Open-Source Dependencies
Offered By: OpenSSF via YouTube
Course Description
Overview
Explore the intricacies of managing vulnerabilities in open-source dependencies in this 13-minute conference talk by Eva Sarafianou from Mattermost. Learn how to navigate the challenges of securing third-party components in software development, where products often combine in-house code with open-source dependencies. Discover key considerations for evaluating software composition analysis tools and gain insights into implementing a successful tool rollout. Delve into effective strategies for triaging findings and shifting from a reactive to a proactive security posture. Walk away with a foundational yet adaptable process to enhance the security of products relying on open-source dependencies, addressing the often overlooked aspect of safeguarding against vulnerabilities in these components.
Syllabus
Managing Vulnerabilities in Open-Source Dependencies - Eva Sarafianou, Mattermost
Taught by
OpenSSF
Related Courses
Inspecting Open Source Software Packages for Security and License CompliancePluralsight DevSecOps Fundamentals
Cybrary Effective Vulnerability Discovery with Machine Learning
Black Hat via YouTube The Devils in the Dependency - Data Driven Software Composition Analysis
Black Hat via YouTube Protect Yourself Against Supply Chain Attacks
NDC Conferences via YouTube