Liran Tal on NPM Package Security – 2022-05-19

Опубликовано: 07 Октябрь 2024
на канале: VSHN The DevOps Company
269
11

Recording of a special Cloud Native Computing Switzerland event with Liran Tal, Director Developer Advocacy at Snyk, on Thursday May 19th 2022, 18h CEST at VSHN.

Open-source software is ubiquitous and no one is short of npm modules, but that also makes them a prime target for attackers and a genuine risk to developers and governments alike. Whether the mission is espionage, cryptocurrency heist, or protesting against capitalism and war, open-source software is being actively weaponized and we’re all potential targets. In this session, Liran shares details on recent headline incidents such as node-ipc, colors, faker, and the impact on supply chain security, as well as what you can do to minimize the risk. After the talk there's a short Q&A session.

Liran Tal is a software developer, and a GitHub Star, world-recognized for his activism in open source communities and advancing web and Node.js security. He engages in security research through his work in the OpenJS Foundation and the Node.js ecosystem security working group and further promotes open-source supply chain security as an OWASP project lead. Liran is also a published author of Essential Node.js Security and O'Reilly's Serverless Security. At Snyk, he is leading the developer advocacy team and on a mission to empower developers with better dev-first security.