The Application Security Podcast

Steve Springett — An insiders checklist for Software Composition Analysis

Chris Romeo and Robert Hurlbut

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 50:49

An SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered. Steve Springett, creator of Dependency-Track and CycloneDX, shares the detailed criteria he used to evaluate commercial and open-source tools. He starts with accurate component inventories, then examines package management, licenses, maintenance status, provenance, policy enforcement, and integration with real development environments. Steve cautions against treating an unconfirmed exploit path as proof that a dependency is safe and explains why project health belongs in risk decisions. The conversation also introduces software bills of materials and compares binary, manifest, and SBOM analysis. This archive discussion provides a concrete way to define requirements and test competing tools against the software an organization actually builds.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Steve Springett:
Steve Springett on GitHub

Mentioned in this episode:
OWASP Dependency-Track
CycloneDX
SPDX

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 An insider’s SCA checklist with Steve Springett
03:02 Understanding software supply-chain risk
06:16 What software composition analysis should provide
08:13 Risk intelligence beyond known vulnerabilities
09:33 Evaluating the SCA market at the time
13:57 Defining requirements for a tool comparison
14:50 Start with an accurate component inventory
15:41 Ecosystems, package management, provenance, and SBOM support
24:07 Testing tools against your organization’s needs
28:43 Policy enforcement and exploitability caveats
30:29 Onboarding, integration, and component age
33:08 Project health and limiting dependency sprawl
34:49 Reviewing the complete evaluation checklist
38:27 Software bills of materials explained
43:22 Using SBOMs to improve inventory accuracy
45:24 Combining binary, manifest, and SBOM analysis
47:45 Dependency-Track project update

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo