<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1076912843267184&amp;ev=PageView&amp;noscript=1">

RL Blog

|

How to trust open source software: A conversation with OpenSSF's Naveen Srinivasan

ConversingLabs caught up with Srinivasan to discuss how OpenSSF's Security Scorecard can aid developers in assessing open source software components for their projects. 

ConversingLabs-How-Do-You-Trust-Open-Source-Software
For software engineers to keep up with the pace of software delivery in the world of continuous delivery/continuous integration (CI/CD), they rely on open source codebases to meet deadlines and create a quality product. But while open source code is essential to developers — it has also become a major problem for secure software development.

The Synopsis 2021 Open Source Security and Risk Analysis Report found that 84% of all scanned codebases have at least one software vulnerability, with an average of 158 per codebase. This makes it incredibly easy for developers to accidentally use open source components that could have potential security vulnerabilities in them, creating application security and software supply chain security risk. 

The effort to review open source code for vulnerabilities is also a tedious task, making it less likely that harried software developers will review these dependencies to assess their security risk. This is why open source software developers created an essential tool known as OpenSSF Scorecard (also known as Security Scorecard). The tool, which is part of the Open Source Security Foundation, assesses open source projects for security risks through a series of automated checks. 

[ See also: OpenSSF's npm best practices: A solid first step — but trust issues remain ]

At this year’s RSA Conference in San Francisco, one of Security Scorecard’s maintainers, Naveen Srinivasan, presented alongside Brian Russell of Google to share how Security Scorecard works and why it’s an essential tool in better securing software applications and supply chains. 

ConversingLabs host Paul Roberts caught up with Srinivasan on the sidelines of RSAC to follow up with him on his presentation. The two discussed the following:

  • What Security Scorecard is
  • How the tool fits into the application security ecosystem
  • What dangers are currently present to the development process
  • How software vulnerabilities compare to other supply chain risks

Here is their conversation, ConversingLabs: How Do You Trust Open Source Software?:


The ConversingLabs episode is also available to watch on-demand — or listen to wherever you get your podcasts. 

Keep learning

Get up to speed with our special report: CSF 2.0 and C-SCRM for Software Risk Management. Plus: See the related expert panel discussion.

Understand key trends and get expert insights with our special report package: The State of Supply Chain Security (SSCS) 2024. Plus: Download the full State of SSCS report.

Learn key factors and best practices for managing software supply chain risk with Gartner's guidance. Plus: Watch the related Webinar and get the Gartner Report courtesy of RL.

Read about why you need to upgrade your AppSec tools for the SSCS era. Plus: Download and share RL's Buyer's Guide for SSCS.


Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for advanced file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

More Blog Posts

Introducing the Unified RL Spectra Suite

Introducing the Unified RL Spectra Suite

RL announced the Spectra Advanced File Analysis and Malware Detection suite, a strategic update of our malware analysis and threat hunting solutions for advanced file analysis and threat detection. Here’s what you need to know.
Read More

    Special Reports

    Latest Blog Posts

    Chinese APT Group Exploits SOHO Routers Chinese APT Group Exploits SOHO Routers

    Conversations About Threat Hunting and Software Supply Chain Security

    Reproducible Builds: Graduate Your Software Supply Chain Security Reproducible Builds: Graduate Your Software Supply Chain Security

    Glassboard conversations with ReversingLabs Field CISO Matt Rose

    Software Package Deconstruction: Video Conferencing Software Software Package Deconstruction: Video Conferencing Software

    Analyzing Risks To Your Software Supply Chain