
Henrik Plate -- OWASP Top 10 Open Source Risks
Om avsnittet
Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Our discussion also includes the need for a dedicated open-source risk list, and the importance of addressing known vulnerabilities, unmaintained projects, immature software, and more. Henrik Plate is the principal security researcher at Endor Labs. He formerly worked for SAP Security Research, where he led the focus topic open source security starting in 2014.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.
→ Learn more about Security Journey
Connect with Henrik Plate:
→ The OWASP Top 10 Open Source Risks
→ Endor Labs
Mentioned in this episode:
→ The OWASP Top 10 Open Source Risks
→ Endor Labs
→ OpenSSF
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Henrik Plate: OWASP Top 10 Open Source Risks
01:42 We're back on the world of OWASP. We've, we've been away
04:39 Yeah, Henrik, uh, just curious. So, uh, we're talking about the
08:17 The order in this list mean something, or are these all
10:29 Yeah. So if I'm a developer, what, how do I use
12:47 I wonder if we could start to walk through the list
19:43 This, XZ was a more modern example of this, right
22:13 Yeah. And that's, and that's a common problem in the open
24:28 All right, so what is 4
28:28 Okay. So Robert, why don't you, uh, pick one between 8
31:57 All right, Henrik, we have 3 questions that we typically ask
35:01 Uh, the 3rd question is, what's your top book recommendation and
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.