41 mintranscript
Jeremy Long — It’s dependency check, not checker
How do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases?
Listen to the episodeGuest
Jeremy Long is a principal engineer specializing in securing the SDLC. He is the founder and project lead for OWASP Dependency-Check, a software composition analysis tool that identifies known vulnerabilities in third-party libraries.
How do you discover vulnerable libraries when the names developers use do not match the names in vulnerability databases?
Listen to the episode