Jan. 24, 2024, 3:04 a.m. | OWASP Foundation

OWASP Foundation www.youtube.com

Slides: https://static.sched.com/hosted_files/owasp2023globalappsecwashin/93/OWASP%20DC%20Malicious%20Dependencies.pptx

Incidents of malicious dependencies in open source package managers continue to grow in number every year. However, we are not defenseless. Techniques to identify and neutralize malicious packages are also improving, and we add our own static analysis techniques to the mix.

Static analysis has become more accessible in recent years, making it a great tool for inspecting source code with speed and accuracy. By studying the code in malicious packages, combined with our own experience, we developed …

analysis code continue dependencies great identify incidents making malicious malicious packages managers open source own package package managers packages source code static analysis techniques tool

Financial Crimes Compliance - Senior - Consulting - Location Open

@ EY | New York City, US, 10001-8604

Software Engineer - Cloud Security

@ Neo4j | Malmö

Security Consultant

@ LRQA | Singapore, Singapore, SG, 119963

Identity Governance Consultant

@ Allianz | Sydney, NSW, AU, 2000

Educator, Cybersecurity

@ Brain Station | Toronto

Principal Security Engineer

@ Hippocratic AI | Palo Alto