Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free TrialFor software engineers to keep up with the pace of software delivery in the world of continuous delivery/continuous integration (CI/CD), they rely on open source codebases to meet deadlines and create a quality product. But while open source code is essential to developers — it has also become a major problem for secure software development.
The Synopsis 2021 Open Source Security and Risk Analysis Report found that 84% of all scanned codebases have at least one software vulnerability, with an average of 158 per codebase. This makes it incredibly easy for developers to accidentally use open source components that could have potential security vulnerabilities in them, creating application security and software supply chain security risk.
The effort to review open source code for vulnerabilities is also a tedious task, making it less likely that harried software developers will review these dependencies to assess their security risk. This is why open source software developers created an essential tool known as OpenSSF Scorecard (also known as Security Scorecard). The tool, which is part of the Open Source Security Foundation, assesses open source projects for security risks through a series of automated checks.
See also: OpenSSF's npm best practices: A solid first step — but trust issues remain
At this year’s RSA Conference in San Francisco, one of Security Scorecard’s maintainers, Naveen Srinivasan, presented alongside Brian Russell of Google to share how Security Scorecard works and why it’s an essential tool in better securing software applications and supply chains.
ConversingLabs host Paul Roberts caught up with Srinivasan on the sidelines of RSAC to follow up with him on his presentation. The two discussed the following:
Here is their conversation, ConversingLabs: How Do You Trust Open Source Software?:
The ConversingLabs episode is also available to watch on-demand — or listen to wherever you get your podcasts.
Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial