Session

Securing your dependencies with the OWASP Dependency tools

Keeping your dependencies up to date is more important than ever. Unpatched software is an increasing problem in our industry, and in 2023 OWASP added A9-Using Components with Known Vulnerabilities onto their top 10 list for the first time. A recent study by Ponemon Institute revealed that 60% of all breaches were due to unpatched known vulnerabilities, but at the same time 62% of victims were unaware of that they were vulnerable.

Luckily OWASP has two projects that can help with this problem, Dependency-Check and Dependency-Track. Join me as we look at how Dependency-Check can be added to your build pipeline to prevent unpatched components from making it into your releases. And how to use Dependency-Track to monitor the dependencies of your deployed versions for new known vulnerabilities.

Fredrik Ljung

Lead Developer and Architect at Datema Retail

Stockholm, Sweden

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top