Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Henrik Plate -- OWASP Top 10 Open Source Risks

38 min4 mars 2025

Om avsnittet

Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Our discussion also includes the need for a dedicated open-source risk list, and the importance of addressing known vulnerabilities, unmaintained projects, immature software, and more. Henrik Plate is the principal security researcher at Endor Labs. He formerly worked for SAP Security Research, where he led the focus topic open source security starting in 2014.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.
Learn more about Security Journey

Connect with Henrik Plate:
The OWASP Top 10 Open Source Risks
Endor Labs

Mentioned in this episode:
The OWASP Top 10 Open Source Risks
Endor Labs
OpenSSF

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Henrik Plate: OWASP Top 10 Open Source Risks
01:42 We're back on the world of OWASP. We've, we've been away
04:39 Yeah, Henrik, uh, just curious. So, uh, we're talking about the
08:17 The order in this list mean something, or are these all
10:29 Yeah. So if I'm a developer, what, how do I use
12:47 I wonder if we could start to walk through the list
19:43 This, XZ was a more modern example of this, right
22:13 Yeah. And that's, and that's a common problem in the open
24:28 All right, so what is 4
28:28 Okay. So Robert, why don't you, uh, pick one between 8
31:57 All right, Henrik, we have 3 questions that we typically ask
35:01 Uh, the 3rd question is, what's your top book recommendation and

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.