Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Liran Tal — The state of open source software security

34 min5 september 2019

Om avsnittet

Developers may want to own security, but what helps them turn that intention into safer software? Liran Tal joins Chris and Robert to examine Snyk's 2019 State of Open Source Security research. After sharing how running a bulletin board system sparked his curiosity, he explains the report's mix of survey responses, dependency data, and public ecosystem information. They discuss vulnerable libraries in popular container images, why updating a base image can matter, and the hesitation developers feel when dependency changes might break an application. Liran also explores how vulnerabilities can remain unnoticed for years. He closes with three priorities for improvement: make security accessible, treat it as part of product quality, and celebrate developers who find and fix problems.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Liran Tal:
LinkedIn
GitHub

Mentioned in this episode:
2019 State of Open Source Security — developer ownership findings
Docker Hub
Node.js
Libraries.io

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Introduction
01:23 BBS roots and early computing
04:38 Finding a path into application security
06:41 Curiosity and learning by building
11:00 The data behind the open-source report
12:11 Combining survey and ecosystem sources
12:40 Developers want to own security
15:13 Vulnerabilities in popular container images
17:32 Base images, trust, and practical fixes
20:13 Updating dependencies without breaking the application
23:59 Vulnerabilities that remain dormant for years
26:23 The window before discovery
27:52 Three priorities for improving open-source security
31:43 Connecting with Liran

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.