Conf42: DevSecOps 2022


Open-source vulnerability management? Use the source, Luke!

Henrik Plate
Security Research @ Endor Labs

Henrik Plate's LinkedIn account

Log4Shell taught developers to check whether their project dependencies are subject to known vulnerabilities. At the example of Eclipse Steady, this talk will introduce code-centric vulnerability identification, assessment and mitigation (opportunities in terms of reducing FP/FNs and limitations).

