No items found.
Event

CSA San Francisco July Chapter Meetup

Date
July 23, 2024
Time
5:30 - 7:30 PM PT
Event Type
In person
Location
North America
Event Overview

The SCA Balancing Act: Understanding Tradeoffs, What to Do and Avoid

Software Composition Analysis (SCA) is among the most foundational approaches to product security. Understanding the known vulnerabilities (CVE) and leading and lagging indicators of risk are among the most widely leveraged security controls in industry. There are three major types of SCA: Runtime SCA, Manifest scanning SCA and Build/Install-time SCA with and without program analysis. This session will explore not only the hidden costs & pros/cons, but explain why they exist. With any approach to vulnerability management there are a spectrum of trade offs that exista and often complementary approaches are seen as competitive because of a lack of understanding.

Join us for the CSA - San Francisco Chapter Meetup.

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
Read more
CISO's Guide: Build vs Buy AI Code Security
CISO's Guide: Build vs Buy AI Code Security
Read more
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Read more
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
Read more
CISO's Guide: Build vs Buy AI Code Security
CISO's Guide: Build vs Buy AI Code Security
Read more
NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages
Read more

Want to stay in the loop?

Sign up for our newsletter.