The State of Open Source Security & Compliance: Best Practices

Logo
Presented by

Jason Hammond, Director of Solution Engineering at WhiteSource

About this talk

Open Source components have become a fundamental part of modern software applications. With the massive growth of the open source vulnerabilities over the past few years, the overall landscape of ensuring security, quality, and compliance might seem complex and challenging. There are ways to gain visibility and control over the open source components that make up the products that we release, but we must first address the risks so we can take the proper measures to avoid them. In this session you’ll discover: * How to address the needs of the entire organization, gain visibility and control, and prevent risk. * Where a vulnerable functionality is referenced within the code, so you can address and remediate the most critical issues and reduce security alerts by 85% * Learn how to automate the process of identifying all licenses that are attached to the dependencies whenever a new open source component is added to the build.
Related topics:

More from this channel

Upcoming talks (6)
On-demand talks (42)
Subscribers (16964)
Mend, formerly known as WhiteSource, effortlessly secures what developers create. Mend uniquely removes the burden of application security, allowing development teams to deliver quality, secure code, faster. With a proven track record of successfully meeting complex and large-scale application security needs, the world’s most demanding software developers rely on Mend. The company has more than 1,000 customers, including 25 percent of the Fortune 100, and manages Renovate, link here, the open-source automated dependency update project. For more information, visit www.mend.io, the Mend blog, and Mend on LinkedIn and Twitter.