Now Playing - You Chose...Wisely: Making Informed Open Source Package Decisions - SnykCon
54420
,
on-demand
You Chose...Wisely: Making Informed Open Source Package Decisions - SnykCon
828559
MURAL
MURAL
MURAL
MURAL
Amadeus
Amadeus
The Adaptavist Group
Sick Kids Foundation
CBS
Isos Technology
Nationwide Building Society
Adaptavist
Nationwide Building Society
Atlassian
Mabl
Snyk
Atlassian
Splunk
Atlassian
CBA
Commonwealth Bank Australia
Peloton
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Atlassian
Forrester
Atlassian
Atlassian
Atlassian
Splunk
Charter Communications
Charter Communications
MSUFCU
Isos Technology
Atlassian
Atlassian
Atlassian
Atlassian
Appfire
Appfire
Appfire
The Walt Disney Company *Available for a limited time only
Atlassian
Adaptavist
Adaptavist
Adaptavist
Amazon
Amazon Web Services
Contegix, LLC
Ascend Integrated, a Contegix Company
Appfire
Appfire
Appfire
Software development is increasingly about composition. Modern developers are able to stand on the shoulders of giants, using a wealth of open source libraries to build software quickly and delightfully. More and more open source packages are released every day on npm, PyPI, Maven Central and other central repositories. New versions of libraries are released hourly. However, attackers are finding ways of using the open source toolchain to scale attacks. How do you choose the best library when considering sustainability, security and compliance as well as functionality? In this talk we’ll understand why package health is important and how you can help make sustainable library choices and minimize future maintenance like: • Making sure you consider open source license implications as part of development • Considering the security history, maintenance history and other projects attributes • Automating dependency management to keep versions up-to-date