Modern software projects typically import functionality from third-party sources by including them as software dependencies. Hence, these dependencies introduce a huge chunk of code, that needs to be considered, when we are talking about bugs and security vulnerabilities of a software project. During the talk we will discuss how to automatically manage software dependencies, so there is no unpleasant gifts of a vulnerable dependency. We start with an overview of the existing options, such as the Github’s software dependency initiative. Then, we will leverage on this approach and present you the methodology for managing vulnerable dependencies developed in the Security Research Lab of the University of Trento (Italy) in collaboration with SAP Security Research (France).

Say No to the Dependency Hell / Pashchenko, Ivan. - (2019).

Say No to the Dependency Hell

Pashchenko, Ivan
2019-01-01

Abstract

Modern software projects typically import functionality from third-party sources by including them as software dependencies. Hence, these dependencies introduce a huge chunk of code, that needs to be considered, when we are talking about bugs and security vulnerabilities of a software project. During the talk we will discuss how to automatically manage software dependencies, so there is no unpleasant gifts of a vulnerable dependency. We start with an overview of the existing options, such as the Github’s software dependency initiative. Then, we will leverage on this approach and present you the methodology for managing vulnerable dependencies developed in the Security Research Lab of the University of Trento (Italy) in collaboration with SAP Security Research (France).
2019
Online
SFScon
Say No to the Dependency Hell / Pashchenko, Ivan. - (2019).
Pashchenko, Ivan
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/285412
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact