Главная
Study mode:
on
1
intro
2
preamble
3
about kyle
4
agenda
5
software dependencies
6
open source software oss
7
oss vulnerabilities
8
an uncomfortable prioritization exercise
9
semgrep supply chain ssc
10
software composition analysis sca
11
one of a few ways: reachability
12
now what? remediation
13
easy wins with semantic versioning semver
14
manifest file dependency versions
15
example
16
transitive vulnerabilities
17
key takeaways
18
resources
Description:
Explore the complexities of open source software risks in this 22-minute conference talk from Conf42 DevOps 2024. Delve into topics such as software dependencies, open source vulnerabilities, and prioritization strategies. Learn about tools like Semgrep Supply Chain and Software Composition Analysis for managing risks. Discover reachability analysis, remediation techniques, and the importance of semantic versioning. Gain practical insights on handling manifest files, dependency versions, and transitive vulnerabilities. Walk away with key takeaways and valuable resources to enhance your DevOps practices and mitigate open source software risks effectively.

Mapping the Minefield of Open Source Software Risks - DevOps 2024

Conf42
Add to list
0:00 / 0:00