The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Steve Springett — An insiders checklist for Software Composition Analysis
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
An SCA tool can find vulnerable libraries and still leave important software supply-chain questions unanswered. Steve Springett, creator of Dependency-Track and CycloneDX, shares the detailed criteria he used to evaluate commercial and open-source tools. He starts with accurate component inventories, then examines package management, licenses, maintenance status, provenance, policy enforcement, and integration with real development environments. Steve cautions against treating an unconfirmed exploit path as proof that a dependency is safe and explains why project health belongs in risk decisions. The conversation also introduces software bills of materials and compares binary, manifest, and SBOM analysis. This archive discussion provides a concrete way to define requirements and test competing tools against the software an organization actually builds.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Steve Springett:
→ Steve Springett on GitHub
Mentioned in this episode:
→ OWASP Dependency-Track
→ CycloneDX
→ SPDX
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 An insider’s SCA checklist with Steve Springett
03:02 Understanding software supply-chain risk
06:16 What software composition analysis should provide
08:13 Risk intelligence beyond known vulnerabilities
09:33 Evaluating the SCA market at the time
13:57 Defining requirements for a tool comparison
14:50 Start with an accurate component inventory
15:41 Ecosystems, package management, provenance, and SBOM support
24:07 Testing tools against your organization’s needs
28:43 Policy enforcement and exploitability caveats
30:29 Onboarding, integration, and component age
33:08 Project health and limiting dependency sprawl
34:49 Reviewing the complete evaluation checklist
38:27 Software bills of materials explained
43:22 Using SBOMs to improve inventory accuracy
45:24 Combining binary, manifest, and SBOM analysis
47:45 Dependency-Track project update
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo