Keeping up with the Dependencies

Nov 5, 2020

Speakers

About

Open source libraries are great. Vulnerabilities that come along with them? Not so much. As a security team trying to implement a secure development lifecycle process, how do you solve this issue, not once but forever? This talk will cover behind the scenes efforts that resulted in a tangible plan for dependency management, particularly for Python, Go and Javascript, at Lyft. Further, we will walk through challenges we faced along the way during implementation of popular best practices at scale. Talk outline : 1. Open source libraries pros and cons 2. Variety of programming languages with their problematic dependency lifecycle 3. Securing supply chain at scale with developer empathy 4. Sustaining a good dependency management process 5. Measuring success and failure Audience would leave the talk with the knowledge of real challenges faced while implementing a dependency management program and an example of how to mitigate them.

Organizer

Categories

About Loco Moco Security Conference

Inclusive product security conference that attracts builders and defenders from around the world.

Store presentation

Should this presentation be stored for 1000 years?

How do we store presentations

Total of 0 viewers voted for saving the presentation to eternal vault which is 0.0%

Sharing

Recommended Videos

Presentations on similar topic, category or speaker

Interested in talks like this? Follow Loco Moco Security Conference