Тёмный

DevSecOps Talks - Mitigating the Risks of 3rd Party Code 

Code Intelligence
Подписаться 844
Просмотров 112
50% 1

In today's fast-paced software environment, third-party code has become irreplaceable. With 96% of codebases containing open-source dependencies, the image is clear: open-source is ubiquitous in the development landscape.
However, this can come with great risk. Supply Chain Breaches were the no. 1 Attack Vector in 2022. This comes at no surprise given that 84% of open-source code contained at least one vulnerability in 2022. Additionally, 89% of software tested contained open-source code more than four years out of date, adding further risk. Vulnerabilities such as log4Shell or Heartbleed have shown the devastating effect these security gaps can have on software supply chains.
It is clear that a more comprehensive, less labor-intensive approach to open-source security is vital to better accompany the rapid growth we see in development. In this third installment of the DevSecOps Talk Series, Jonathan Metzman, a software engineer on the Google Open-Source Security Team, will delve into how our collaboration enabled them to uncover severe security issues in popular open-source libraries.
He will cover:
-How Google’s collaboration with Code Intelligence has helped to secure Java/JavaScript ecosystems.
-The importance of genetic algorithms in continuous testing of open-source libraries.
-Critical CVEs that were unearthed through this collaboration, including an Expression DoS in Spring and a Prototype Pollution in protobuf.js.

Опубликовано:

 

18 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии    
Далее
С чего всё началось?
00:42
Просмотров 116 тыс.
API Gateway explained
22:30
Просмотров 132 тыс.
Clean Code - Uncle Bob / Lesson 1
1:48:42
Просмотров 1,9 млн
Introduction to Programming
32:46
Просмотров 2,3 млн
Facebook and memcached - Tech Talk
27:56
Просмотров 233 тыс.
Hashing vs Encryption Differences
19:38
Просмотров 168 тыс.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17