
Dennis, Principal Security Consultant (Veracode) asked a question.
Hello Community!
@Boy, Security Consultant (Veracode) and @Dennis, Principal Security Consultant (Veracode) , the Application Security Consultants again! Hope everyone is having a great summer!
This week we’ll be looking at flaws in 3rd-party software. When security flaws are found in your own code it can be difficult enough to remediate those vulnerabilities. But what about when the code was created by someone else, like another team in your organization, another company altogether, or even an open source repository with questionable ownership? We want to hear from you about what you do in these cases.
- What are your experiences and best practices when working with third parties to make your software more secure?
- Feel free to brag a little - how have you made the world more secure by securing 3rd-party components?
🔖 Related Reads
"How 3rd-Party Content is Our Responsibility" by @Dennis, Principal Security Consultant (Veracode)
Takeaways: The engineering and security best practices for securing 3rd party code
"How to Fix a Veracode Static Analysis Flaw in 3rd-Party Software" by @Boy, Security Consultant (Veracode)
Takeaways: Guidance on handling 3rd party risks with Static Analysis (with examples)
.png)
In our shop we really relish being able to use the SCA scanning component in Veracode. It helps teams understand where they stand for the version of 3rd party components in use today, and a lot of the time its a very old version. We are encouraging them to look at the SCA section but sometimes its not as apparent to them to look there- however when they do it helps them understand the versions above that they can look to upgrade to.
We advise they try to find a next minor version which has no or less known security flaws so its less daunting to upgrade to the newest version which may take a lot more work to do.