3 Security Buddies

3SB-6: Dependency Hell


Listen Later

Follow up:

 - Nothing this week


Topics:

  • Automated Fuzzing Testing in Go
  • Stack Overflow Supply Chain Attacks
  • Deps.dev
  • Update on Github’s policies regarding exploits, malware, and vulnerability research

Paul Rant:

  • Pinning dependencies on Libraries 


Links:

  • https://blog.golang.com/fuzz-beta
  • https://www.wsj.com/articles/software-developer-community-stack-overflow-sold-to-tech-giant-prosus-for-1-8-billion-11622648400
  • https://deps.dev
  • https://github.blog/2021-06-04-updates-to-our-policies-regarding-exploits-malware-and-vulnerability-research/


Hosts:

Paul Kehrer @reaperhulk

Robert Clark @hyakuhei

Matías Brutti @MrBrutti


Post-Production:

Matias Brutti @MrBrutti


Disclaimer: The opinions and security statements on this podcast are our own and do not represent that of our respective past, current or future employers. 


...more
View all episodesView all episodes
Download on the App Store

3 Security BuddiesBy Paul Kehrer, Robert Clark, Matias Brutti

  • 5
  • 5
  • 5
  • 5
  • 5

5

5 ratings