Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Steve Springett — OWASP Dependency Track — 5 Minute AppSec

5 min25 augusti 2019

Om avsnittet

What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. Steve also covers outdated-component detection, package ecosystems, and license analysis through SPDX. This concise introduction presents Dependency-Track as a software supply-chain component analysis platform built to turn a constantly changing inventory into actionable risk information rather than a one-time list of dependencies.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Steve Springett:
Steve Springett on LinkedIn
OWASP Dependency-Track

Mentioned in this episode:
OWASP Dependency-Track
National Vulnerability Database
Sonatype OSS Index
SPDX
Heartbleed

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 What is OWASP Dependency-Track?
00:16 Analyzing components and SBOMs at enterprise scale
02:16 Vulnerability intelligence and outdated components
03:25 APIs, webhooks, and actionable intelligence
04:12 Continue with the full SCA interview

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.