Federal Tech Podcast:  for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awareness

Ep 32 Reducing Risk for Federal Software Supply Chains


Listen Later

Attacks on the software supply chain have grown by an average of 742% a year since 2019. It makes complete sense if you look at several factors.

Years ago, a software developer would write code as part of a large project. It is quite possible they had the opportunity to examine all aspects of their code for vulnerabilities. That transitioned to developers grabbing blocks of code from libraries. Even then, they had at least a chance to review code grabbed from software repositories.

Federal mandates regarding cybersecurity are forcing systems administrators to speed along work by using code from software libraries. Unfortunately, remote work and cloud transition has made projects so complex that, if they tried to examine each line of code in the project, it would never get done.

One solution is to look at options for examining open-source code before being incorporated into a project. Today's interview is with Dr. Stephen Magill from Sonatype. He gives a detailed description of how software developers can be assured code they develop is safe. He reminds the audience that, even with bespoke code, newer versions must be added along with improved code over the long haul.

Dr. Magill brings up an interesting aspect of software risk – artifacts. In this sense of the word, an "artifact" is a bit of code that can make binaries work in a system. As a result, they must be managed as carefully as traditional binaries.

If you would like to have more details about security and open-source software, consider downloading the annal report from Sonatype called the "2021 Start of the Software Supply Chain" from Sonatype.

...more
View all episodesView all episodes
Download on the App Store

Federal Tech Podcast:  for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awarenessBy John Gilroy

  • 5
  • 5
  • 5
  • 5
  • 5

5

6 ratings


More shows like Federal Tech Podcast: for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awareness

View all
Global News Podcast by BBC World Service

Global News Podcast

7,728 Listeners

Tech Talks Daily by Neil C. Hughes

Tech Talks Daily

198 Listeners

The Daily by The New York Times

The Daily

112,574 Listeners

Practical AI by Practical AI LLC

Practical AI

212 Listeners

This Day in AI Podcast by Michael Sharkey, Chris Sharkey

This Day in AI Podcast

209 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

586 Listeners