Find and Track the hidden vulnerabilities inside your dependencies (Julien Topçu)
4,791 views · Published 8 November 2018 · 26:34 · Indexed 5 October 2026
Channel: Devoxx · 2018 · Science & Technology
44% of applications contain critical vulnerabilities in an open source component* and this although good practices like OWASP Top 10 have become widespread. Do not let these vulnerabilities incubate warm in the belly of your app! With this talk you'll learn how those vulnerabilities are indexed (NVD, CVE) and how their severity is scored (CVSS). You'll see how to create your first Continuous Security pipeline using Jenkins and OWASP DependencyCheck which detects vulnerabilities and track them using OWASP DependencyTrack (open-source softwares) Do you first step in the DevSecOps philosophy !!! *https://www.veracode.com/products/software-composition-analysis Voxxed Days Microservices 2018: 2 days conference (+1 optional workshops day) only on Microservices. Follow us on : Website : https://voxxeddays.com/microservices (bit.ly/vxdmicro) Twitter : https://twitter.com/vxdmicroservice Linkedin : https://www.linkedin.com/in/voxxed-days-microservices-906115164 Keep in touch : https://t.co/pxf7cHZOpl #developers #conference #microservices
More from this channel
-
2:04:09
Powerful Metaprogramming Techniques With Groovy by Jeff Brown
-
2:38:32
Distributed Machine Learning 101 using Apache Spark from a Browser by Xavier Tordoir/Andy Petrella
-
59:45
Dive into Spark Streaming by Gerard Maas
-
54:28
Dockerize user stories with Mayfly by Maarten Dirkse
-
19:29
Let's have 100 phones connected to a cinema multi-player game by Ernest Micklei
-
1:01:45
Introduction to Modular Development by Mark Reinhold/Alan Bateman
-
39:41
Android and the Seven Dwarfs by Murat Yener
-
16:09
It started with a whiteboard in the kitchen by Saskia Vermeer - Ooms