For software engineers to keep up with the pace of software delivery in the world of continuous delivery/continuous integration (CI/CD), they rely on open source codebases to meet deadlines and create a quality product. But while open source code is essential to developers — it has also become a major problem for secure software development.
The Synopsis 2021 Open Source Security and Risk Analysis Report found that 84% of all scanned codebases have at least one software vulnerability, with an average of 158 per codebase. This makes it incredibly easy for developers to accidentally use open source components that could have potential security vulnerabilities in them, creating application security and software supply chain security risk.
The effort to review open source code for vulnerabilities is also a tedious task, making it less likely that harried software developers will review these dependencies to assess their security risk. This is why open source software developers created an essential tool known as OpenSSF Scorecard (also known as Security Scorecard). The tool, which is part of the Open Source Security Foundation, assesses open source projects for security risks through a series of automated checks.
[ See also: OpenSSF's npm best practices: A solid first step — but trust issues remain ]
At this year’s RSA Conference in San Francisco, one of Security Scorecard’s maintainers, Naveen Srinivasan, presented alongside Brian Russell of Google to share how Security Scorecard works and why it’s an essential tool in better securing software applications and supply chains.
ConversingLabs host Paul Roberts caught up with Srinivasan on the sidelines of RSAC to follow up with him on his presentation. The two discussed the following:
- What Security Scorecard is
- How the tool fits into the application security ecosystem
- What dangers are currently present to the development process
- How software vulnerabilities compare to other supply chain risks
Here is their conversation, ConversingLabs: How Do You Trust Open Source Software?:
The ConversingLabs episode is also available to watch on-demand — or listen to wherever you get your podcasts.
Keep learning
- Get up to speed on securing AI/ML systems and software with our Special Report. Plus: See the Webinar: The MLephant in the Room.
- Learn how you can go beyond the SBOM with deep visibility and new controls for the software you build or buy. Learn more in our Special Report — and take a deep dive with our white paper.
- Upgrade your software security posture with RL's new guide, Software Supply Chain Security for Dummies.
- Commercial software risk is under-addressed. Get key insights with our Special Report, download the related white paper — and see our related Webinar for more insights.
Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.