Since 1999

Securing the Open Source Software Supply Chain

Watch on YouTube ↗

Popular app frameworks like Docker, Node.js, React, Ruby on Rails, and Grails all pull in thousands of dependencies, and developers routinely add dependencies that may be unsafe. This talk covers how malicious actors use open source libraries to attack applications, and a proactive dependency management approach to stop it. Recorded at HellaConf 2020.

For the short version, see Third-Party Dependencies in the Software Supply Chain.