AppSec Decoded: Managing your open source risks
2023-3-2 22:0:19 Author: www.synopsys.com(查看原文) 阅读量:20 收藏

Posted by on Thursday, March 2, 2023

In this episode, we discuss the crucial elements to managing open source risks as highlighted in the 2023 OSSRA report.

If software is eating the world, as was said more than a decade ago, open source software is doing most of the eating. It is in virtually every codebase now in use and makes up the large majority—an average of 76%—of the components in those codebases.

That means it is most of the links in the massive and complicated software supply chains that enable innovation and bring dazzling features to both the online and physical worlds. But it also brings unique and dangerous risks.

And that’s why the Synopsys Cybersecurity Research Center has, for the eighth year running, produced the “Open Source Security and Risk Analysis” (OSSRA) report based on an analysis of the open source vulnerabilities and license conflicts found in more than 1,700 commercial codebases across 17 industries. The report offers recommendations on how to mitigate those risks and is available to the public for free.

Mike McGuire, senior software solutions manager with the Synopsys Software Integrity Group, played a major role in the research and analysis that supports the latest OSSRA report. In this, the second of two AppSec Decoded conversations focused on the report, McGuire and Taylor Armerding, security advocate at Synopsys, discuss two of the most important ways to manage open source risks: an automated software composition analysis (SCA) tool, and the creation and maintenance of a software Bill of Materials (SBOM).

Watch the two-part series


文章来源: https://www.synopsys.com/blogs/software-security/appsec-decoded-managing-your-open-source-risks/
如有侵权请联系:admin#unsafe.sh