Loading…
Attending this event?
THE MUST ATTEND EVENT FOR CYBERSECURITY PROFESSIONALS
Friday September 27, 2024 11:00am - 11:30am PDT
OWASP dep-scan v6: The S in SCA is not an SBOM

The principle behind Software Composition Analysis (SCA) has remained the same for over a decade. It involves a single Software Bill-of-Materials (SBOM) document and a vulnerability database to identify potential vulnerabilities and advisories that might affect the given application or service. Such a technique of scanning an application with limited context creates both false positives and false negatives, a problem that is well-understood. Solving these inherent weaknesses requires some bold ideas. For OWASP dep-scan v6, we are revisiting every single word in the SCA acronym, to rethink SCA as we know it. In this mini session, we discuss the thinking behind the v6 release and offer insights into our technology and development efforts.
Speakers
avatar for Prabhu Subramanian

Prabhu Subramanian

Prabhu Subramanian is the creator of the AppThreat platform, which includes open-source tools such as atom, blint, cdxgen, and dep-scan. Many of these projects are now incubated under the OWASP Foundation, where he co-leads them along with Caroline and Tim.
Friday September 27, 2024 11:00am - 11:30am PDT
Room: Bayview A (Bay Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link