The Application Security Podcast

Steve Springett -- Dependency Check and Dependency Track

Chris Romeo and Robert Hurlbut

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 48:03

Finding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization? Steve Springett explains how OWASP Dependency-Check and Dependency-Track complement each other in a software composition analysis program. He starts with the ingredients of modern applications, then distinguishes build-time analysis from maintaining a portfolio-wide inventory that can respond to newly disclosed vulnerabilities. The conversation covers language support, dependency updates, vulnerability data quality, and the differences between open-source and commercial tools. Steve offers practical guidance for integrating checks into build pipelines, triaging findings with developers, and making security part of engineering culture. He also looks beyond reactive vulnerability chasing toward software that is easier to maintain and update throughout its life.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Steve Springett:
Steve Springett on GitHub

Mentioned in this episode:
OWASP Dependency-Check
OWASP Dependency-Track
National Vulnerability Database
SPDX

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Dependency-Check and Dependency-Track with Steve Springett
04:29 Understanding software composition analysis
05:56 Why dependency visibility matters
08:31 Equifax and the challenge of upgrading components
11:58 The origins of Dependency-Check
15:32 Language support and build analysis
16:50 Why Dependency-Track was created
18:40 Tracking vulnerabilities across a portfolio
23:06 How the two projects work together
26:48 Open-source and commercial SCA tools
28:50 Vulnerability data quality and noise
33:08 Starting with build integration
36:01 Helping developers triage findings
38:12 Overcoming adoption objections
41:44 The future of dependency security
45:03 Toward continuously updated software

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo