Steve Springett — OWASP Dependency Track — 5 Minute AppSec
With Steve Springett
What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 5 chapters
About this episode
What does OWASP Dependency-Track add beyond a conventional software composition analysis scanner? Steve Springett explains how the project continuously analyzes software bills of materials across an enterprise, correlates components with multiple vulnerability-intelligence sources, and helps teams identify affected assets when a new issue emerges. Its API-first design allows CI/CD pipelines to submit inventories automatically and lets downstream systems react through REST APIs and webhooks. Steve also covers outdated-component detection, package ecosystems, and license analysis through SPDX. This concise introduction presents Dependency-Track as a software supply-chain component analysis platform built to turn a constantly changing inventory into actionable risk information rather than a one-time list of dependencies.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Steve Springett:
→ Steve Springett on LinkedIn
→ OWASP Dependency-Track
Resources
→ OWASP Dependency-Track
→ National Vulnerability Database
→ Sonatype OSS Index
→ SPDX
→ Heartbleed
Actionable
From this conversation
- 0:15
Ingest SBOMs in CI/CD
If you have tens of thousands of applications in your environment and you are producing software bill of materials in a CI/CD pipeline, DependencyTrack can automatically ingest, automatically analyze, and automatically alert you of any vulnerability or other types of risk.
- 0:15
Identify at-risk assets
You can, with DependencyTrack, identify those assets that are at risk in your environment.
- 3:25
Act on vulnerability intelligence
At the end of the day, having all this intelligence is great, but you need to do something about it.
Transcript · 5 min conversation
0:00Chris RomeoOn this episode of 5 Minute AppSec, the question is for Steve Springett, and it's in regards to software composition analysis and OWASP Dependency Track. What is OWASP Dependency Track?
0:15Steve SpringettThat's a great question. So Dependency Track is a flagship OWASP open-source project that helps organizations identify and reduce risk from the use of third-party and open-source components. It would be classified as an SCA product by the market research firms, but DependencyTrack identifies more as a software supply chain component analysis platform. And what does that mean? It means that we're— we don't necessarily care about what the components are if they're software. we can analyze them. If those components are hardware or operating systems, we can also analyze those. So it's really about identifying and reducing the risk from the use of third-party and open-source components across your entire enterprise. If you have tens of thousands of applications in your environment and you are producing software bill of materials in a CI/CD pipeline, DependencyTrack can automatically ingest, automatically analyze, and automatically alert you of any kind of vulnerability or other types of risk. You can also, with DependencyTrack, identify those assets that are at risk in your environment. So if the new Heartbleed, if the new CVE with a flashy marketing website comes up next month, you can quickly identify what assets in your environment are potentially affected. Dependency Track really is an API-first thing. So it's really designed to be embedded in a CI/CD pipeline where you are constantly feeding it software bill of materials.
2:11Robert HurlbutYou can also obviously, you know, get software bill of materials from vendors and that sort of thing as well.
2:16Steve Springettand, you know, upload those to Dependency Track where they can be processed. But it's really about analyzing all these components constantly in your environment. The platform itself integrates with multiple sources of vulnerability intelligence. Out of the box, it supports the National Vulnerability Database.
2:38Robert HurlbutIt supports Sonatype OSS Index.
2:40Steve SpringettIt supports the npm advisories.
2:44Robert HurlbutIt supports, VulnDB from Risk-Based Security, and there's more sources of vulnerability intelligence that will be supported in the near future. It also identifies whether or not your components are out of date. So it integrates with Maven, it integrates with npm, and Ruby, and Python, and all these other ecosystems to determine whether or not your components are out of date. And of course, it supports SPDX licenses. So it normalizes and identifies what your components are licensed at, has and tries to evaluate the risk based on your license as well.
3:25Steve SpringettAt the end of the day, having all this intelligence is great, but you need to do something about it. That's where the REST APIs, that's where the webhooks really come into play here. Being able to have webhooks, being able to receive webhooks when those new vulnerabilities come out, when new audit decisions are made, maybe a component is now exploitable and it wasn't previously. Having all of this dynamic intelligence delivered to you from DependencyTrack is really a game changer.
3:59Robert HurlbutSo identifying what those risks are, what those components are, identifying the risk, and trying to get organizations to actually do something because of the API integration that it facilitates.
4:12Chris RomeoWe did a longer interview with Steve where we dive deeply into all the different avenues of software composition analysis, and he specifically walks us through the different things that he looks for in a commercial software composition analysis solution. And we also got an update on DependencyTrack, so tune in to that episode for more about SCA.
596 words · transcript by assemblyai
More on OWASP Projects
View all episodes →- April 12, 2018 · 48 minSteve Springett -- Dependency Check and Dependency Track
- January 12, 2021 · 48 minJC Herz and Steve Springett — SBOMs and software supply chain assurance
- February 20, 2020 · 41 minJeremy Long — It’s dependency check, not checker