World Congress 2024 • Aug 20, 2024 • Session details

Reviewing 3rd party library security easily using OpenSSF Scorecard

Niels Tanis

Nearly 80% of developers ignore library updates. This blind trust invites devastating supply chain attacks. Learn how OpenSSF Scorecard acts as an automated nutrition label for open-source repositories.

Pause
Mute Enter Fullscreen
#1 about 2 min

Understanding the security risks of third-party libraries

How modern application architectures are fundamentally vulnerable to unmaintained or malicious dependency components.

#2 about 3 min

Managing dependency vulnerabilities and transitive software risks

How stale open-source dependencies and complex transitive trees contribute to hidden application vulnerabilities.

#3 about 3 min

Combatting rogue maintainers and backdoors in open source

How threat actors gradually infiltrate open-source projects to plant malicious code and subtle backdoors.

#4 about 2 min

Addressing visibility challenges with software nutrition labels

The need for clear software composition visibility to expose hidden unmanaged libraries within compiled packages.

#5 about 8 min

Assessing repository security hygiene using OpenSSF Scorecard

An overview of automated repository checks spanning known vulnerabilities, branch protection, testing, and continuous integration practices.

#6 about 2 min

Evaluating dependencies locally and through automated scorecard APIs

How to generate and parse JSON scorecard reports for dependency trees using command-line tools and programming interfaces.

#7 about 4 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Analyzing industry data to understand how contributor counts and defined security policies correlate with project vulnerabilities.

#8 about 4 min

Exploring advanced security tooling and community dependency vetting

Improving software ecosystem safety using coverage-based fuzzing, contextual data-flow analysis, reproducible builds, and collaborative vetting.

Matching moments

2:09 min

Evaluating library intent using security scorecards

Niels Tanis Niels Tanis · World Congress 2022

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:09 min

Prioritizing vulnerabilities with automated security tools

Desmond Lamptey Desmond Lamptey · World Congress 2026 North America

1:39 min

Summarizing strategies for securing the open source ecosystem

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:00 min

Utilizing static analysis for foundational source code security

Michael Wildpaner Michael Wildpaner · World Congress 2025

1:41 min

Leveraging free tools for application security auditing

Stefania Chaplin · World Congress 2022

Upcoming sessions on this topic

Open session

Supply Chain Security for the Everyday Engineer

  • Pradumna Saraf

    Kestra Technologies

    Quality Assurance Engineer

Open session

Beware of Strangers Bearing Code: Open Source Trust in the Agent Era

  • Vikram Vaswani

    Consultant

Open session

How We Cut Our API's p99 Latency from Minutes to Under a Second

  • Deepak Agrawal

    Atlassian

    Principal Software Engineer

Open session

From Profiler to Production: Measuring What Actually Matters in React & React Native

  • Andrei Tazetdinov

    Dynatrace

    React Native Developer

Open session

How Google built a Consistent, Global Authorization System with Zanzibar (and you can too!)

  • Sohan Maheshwar

    AuthZed

    Lead Developer Advocate

Open session

Beyond File Dumps: Context Engineering for Coding Agents

  • Animesh Dutta

    Arm

    Senior Software Engineer