Now Playing - You Chose...Wisely: Making Informed Open Source Package Decisions - SnykCon
54420
,
on-demand
You Chose...Wisely: Making Informed Open Source Package Decisions - SnykCon
828559
MURAL
MURAL
Nationwide Building Society
Adaptavist
Nationwide Building Society
Atlassian
Atlassian
Atlassian
Peloton
Atlassian
CBA
Commonwealth Bank Australia
Atlassian
Mabl
Snyk
Atlassian
Wells Fargo
Wells Fargo
CBS
Isos Technology
Adaptavist
Sick Kids Foundation
MURAL
MURAL
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Aligned Agility
The Adaptavist Group
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Appfire Technologies
Appfire
Appfire
Forrester
Atlassian
Atlassian
MSUFCU
Isos Technology
Charter Communications
Charter Communications
Atlassian
Splunk
The Walt Disney Company *Available for a limited time only
Atlassian
Adaptavist
Adaptavist
Adaptavist
Amazon
Amazon Web Services
Appfire Technologies
Appfire
Appfire
Software development is increasingly about composition. Modern developers are able to stand on the shoulders of giants, using a wealth of open source libraries to build software quickly and delightfully. More and more open source packages are released every day on npm, PyPI, Maven Central and other central repositories. New versions of libraries are released hourly. However, attackers are finding ways of using the open source toolchain to scale attacks. How do you choose the best library when considering sustainability, security and compliance as well as functionality? In this talk we’ll understand why package health is important and how you can help make sustainable library choices and minimize future maintenance like: • Making sure you consider open source license implications as part of development • Considering the security history, maintenance history and other projects attributes • Automating dependency management to keep versions up-to-date