World Congress 2024 Aug 20, 2024 Session details

Reviewing 3rd party library security easily using OpenSSF Scorecard

Niels Tanis

Nearly 80% of developers ignore library updates. This blind trust invites devastating supply chain attacks. Learn how OpenSSF Scorecard acts as an automated nutrition label for open-source repositories.

Pause
Mute Enter Fullscreen
#1 about 2 min

Understanding the security risks of third-party libraries

How modern application architectures are fundamentally vulnerable to unmaintained or malicious dependency components.

#2 about 3 min

Managing dependency vulnerabilities and transitive software risks

How stale open-source dependencies and complex transitive trees contribute to hidden application vulnerabilities.

#3 about 3 min

Combatting rogue maintainers and backdoors in open source

How threat actors gradually infiltrate open-source projects to plant malicious code and subtle backdoors.

#4 about 2 min

Addressing visibility challenges with software nutrition labels

The need for clear software composition visibility to expose hidden unmanaged libraries within compiled packages.

#5 about 8 min

Assessing repository security hygiene using OpenSSF Scorecard

An overview of automated repository checks spanning known vulnerabilities, branch protection, testing, and continuous integration practices.

#6 about 2 min

Evaluating dependencies locally and through automated scorecard APIs

How to generate and parse JSON scorecard reports for dependency trees using command-line tools and programming interfaces.

#7 about 4 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Analyzing industry data to understand how contributor counts and defined security policies correlate with project vulnerabilities.

#8 about 4 min

Exploring advanced security tooling and community dependency vetting

Improving software ecosystem safety using coverage-based fuzzing, contextual data-flow analysis, reproducible builds, and collaborative vetting.

Matching moments

2:09 min

Evaluating library intent using security scorecards

Niels Tanis Niels Tanis · World Congress 2022

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:39 min

Summarizing strategies for securing the open source ecosystem

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:00 min

Utilizing static analysis for foundational source code security

Michael Wildpaner Michael Wildpaner · World Congress 2025

1:41 min

Leveraging free tools for application security auditing

Stefania Chaplin · World Congress 2022

2:00 min

Mitigating risks from supply chain attacks and vulnerable libraries

Jasmin Azemović Jasmin Azemović · World Congress 2023

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 23, 2026 · 14:00–14:30

Stage 1

Supply Chain Security When Agents Write the Code

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Stage 6

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova