The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Steve Springett -- Dependency Check and Dependency Track
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Finding a vulnerable library in one build is only the beginning: how do you find every affected application across an organization? Steve Springett explains how OWASP Dependency-Check and Dependency-Track complement each other in a software composition analysis program. He starts with the ingredients of modern applications, then distinguishes build-time analysis from maintaining a portfolio-wide inventory that can respond to newly disclosed vulnerabilities. The conversation covers language support, dependency updates, vulnerability data quality, and the differences between open-source and commercial tools. Steve offers practical guidance for integrating checks into build pipelines, triaging findings with developers, and making security part of engineering culture. He also looks beyond reactive vulnerability chasing toward software that is easier to maintain and update throughout its life.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Steve Springett:
→ Steve Springett on GitHub
Mentioned in this episode:
→ OWASP Dependency-Check
→ OWASP Dependency-Track
→ National Vulnerability Database
→ SPDX
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Dependency-Check and Dependency-Track with Steve Springett
04:29 Understanding software composition analysis
05:56 Why dependency visibility matters
08:31 Equifax and the challenge of upgrading components
11:58 The origins of Dependency-Check
15:32 Language support and build analysis
16:50 Why Dependency-Track was created
18:40 Tracking vulnerabilities across a portfolio
23:06 How the two projects work together
26:48 Open-source and commercial SCA tools
28:50 Vulnerability data quality and noise
33:08 Starting with build integration
36:01 Helping developers triage findings
38:12 Overcoming adoption objections
41:44 The future of dependency security
45:03 Toward continuously updated software
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo