
Steve Springett — OWASP Dependency Track — 5 Minute AppSec
Om avsnittet
What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. Steve also covers outdated-component detection, package ecosystems, and license analysis through SPDX. This concise introduction presents Dependency-Track as a software supply-chain component analysis platform built to turn a constantly changing inventory into actionable risk information rather than a one-time list of dependencies.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Steve Springett:
→ Steve Springett on LinkedIn
→ OWASP Dependency-Track
Mentioned in this episode:
→ OWASP Dependency-Track
→ National Vulnerability Database
→ Sonatype OSS Index
→ SPDX
→ Heartbleed
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 What is OWASP Dependency-Track?
00:16 Analyzing components and SBOMs at enterprise scale
02:16 Vulnerability intelligence and outdated components
03:25 APIs, webhooks, and actionable intelligence
04:12 Continue with the full SCA interview
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.