Andy Lewis - A Fun Story About A Software Supply Chain Calamity: the UA-Parser Saga
Description:
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Grab it
Explore a lighthearted 51-minute conference talk from LASCON examining the significant security compromise of the widely-used UA-Parser javascript library, which impacts over 4.2 million users and 2000+ downstream NPM projects. Learn about the discovery of the security breach, the community's response to the crisis, and gain practical insights on detecting compromised dependencies in your applications. Discover methods to identify whether your projects are affected by contaminated libraries, using the UA-Parser incident as a compelling case study for understanding software supply chain vulnerabilities.
Software Supply Chain Security: The UA-Parser Compromise and Detection