Event

CSA San Francisco July Chapter Meetup

Date
July 23, 2024
Time
5:30 - 7:30 PM PT
Event Type
In person
Location
North America
Event Overview

The SCA Balancing Act: Understanding Tradeoffs, What to Do and Avoid

Software Composition Analysis (SCA) is among the most foundational approaches to product security. Understanding the known vulnerabilities (CVE) and leading and lagging indicators of risk are among the most widely leveraged security controls in industry. There are three major types of SCA: Runtime SCA, Manifest scanning SCA and Build/Install-time SCA with and without program analysis. This session will explore not only the hidden costs & pros/cons, but explain why they exist. With any approach to vulnerability management there are a spectrum of trade offs that exista and often complementary approaches are seen as competitive because of a lack of understanding.

Join us for the CSA - San Francisco Chapter Meetup.

Want to stay in the loop?

Sign up for our newsletter.

Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
Average results with 59.8% on functional solves and just 19.0% on security solves
Read more
Recall, not reasoning: how AI coding agents cheat security benchmarks
Recall, not reasoning: how AI coding agents cheat security benchmarks
Read more
Endor Labs + Cursor: Building the security foundation for agentic coding
Endor Labs + Cursor: Building the security foundation for agentic coding
Read more
Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise
Cut container vulnerability noise by up to 90% with full-stack reachability analysis spanning application and container image OS layers.
Read more
Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
MCP servers inherit classical vulnerabilities like command injection, path traversal, and SSRF. Here's why LLMs and MCP deserve the same security practices as traditional applications.
Read more
How Fake Font Packages Abused npm as a CDN
101 packages disguised as font files distributed 34 TiB of data via npm's infrastructure—with a total of 4.3 PiB transferred via downloads.
Read more