Skip to content

Details

Managing vulnerabilities in third party software has become an important application security activity. Vulnerabilities like Log4Shell and various supply chain attacks such as SolarWinds or CodeCov and numerous others have given many of us haunting nightmares resulting us sleeping with one eye open. Fortunately, Software Composition Analysis (SCA) tools coupled with Software Bill of Materials (SBOMs) have done so much to relieve that anxiety. Or not. This talk explores the vulnerability management process through the eyes of a FOSS security library provider and examines what we can do as AppSec engineers and developers to make the whole process a bit less painful.

Related topics

Events in Columbus, OH
Application Security
Computer Security
OWASP
Web Security
Information Security

Sponsors

OWASP Global Strategic Group

OWASP Global Strategic Group

International membership.

O'Reilly

O'Reilly

40% off of print and 50% off of ebook orders

You may also like