Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Erlend Oftedal -- What You Require, You Must Also Retire

31 min30 oktober 2018

Om avsnittet

A JavaScript library can keep working long after its security problems become public. Retire.js project leader Erlend Oftedal explains how developers can discover vulnerable dependencies and make that information part of everyday development. He describes the project’s origins, command line scanning, browser-based detection, and options for integrating checks into a build pipeline. Chris probes what happens after a finding, how exceptions can undermine the process, and how externally loaded libraries fit into the picture. They also discuss Retire.js alongside npm auditing, OWASP Dependency-Check, and Dependency-Track. Erlend’s experience leading an OWASP chapter adds a community perspective to the technical discussion. The practical message is to know which libraries you ship and make upgrading them a continuing engineering responsibility.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Erlend Oftedal:
Erlend Oftedal on LinkedIn
Retire.js

Mentioned in this episode:
Retire.js source code
OWASP Dependency-Check
OWASP Dependency-Track
OWASP Proactive Controls

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Finding vulnerable JavaScript with Erlend Oftedal
01:54 A developer’s path into security
07:07 Running an OWASP chapter
10:27 Why Retire.js was created
12:34 Scanning locally and in a pipeline
14:16 The danger of ignoring every finding
15:29 Reading scan results and the role of npm audit
17:45 Upgrading vulnerable libraries
19:05 Detecting libraries loaded from other sites
20:32 Passive discovery in the browser
22:05 Working with Dependency-Check and Dependency-Track
24:27 Open-source and commercial dependency tools
28:21 The limits of automated coverage

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.