SlideShare a Scribd company logo
The Devops Challenge: Open Source Security Throughout the DevOps Pipline- A WhiteSource Webinar
Hello!
Shiri Arad Ivtsan
Product Manager @WhiteSource
Shiri.ivtsan@WhiteSourceSoftware.com
Continuous Delivery
Continuous Delivery
Open Source
96.8%of the developers rely on
open source components
Security in Open Source
Some Basic Statistics
* Based on a survey conducted in more than 650 companies
OSS Security Vulnerabilities Are On The Rise
51%
The observed YoY rise
of reported vulnerabilities in 2017
Open Source Challenges
Onechallenging area in particular
is pronounced
Companies Do Not Prioritize Their Fixes Efficiently
Criticality of the project that might be impacted by the vulnerability
Availability of the suggested fix
Perceived impact of the vulnerability on projects
Number of software libraries containing the vulnerability
Vulnerability severity
Creation date of the vulnerability alert
prioritize based on the real business
impact
~56%
Just
Recent News
Integrity Availability Security-Protection
The Devops Challenge: Open Source Security Throughout the DevOps Pipline- A WhiteSource Webinar
Security Throughout The
SDLC Pipeline
Scan
CI/CD Pipeline
Code Build Package Deploy
Code
Code Build Package Deploy
β€’ Choose the right component from the earliest
stages
β€’ Automatically open pull requests for patches
β€’ Restrict merges if vulnerabilities exist
Build
Code Build Package Deploy
β€’ Scan on any build
β€’ Fail builds based on policies (i.e high severity
vulnerabilities)
Package
Code Build Package Deploy
β€’ Scan Docker images – in private and public image
registries
Deploy
Code Build Package Deploy
β€’ Scan upon deployment to your production
platform
β€’ Monitor running applications in production for
newly published vulnerabilities
Key Takeaways
Know your code
Monitor it frequently
Make it simple & faster: Automate
β€’ Automate the scanning
β€’ Automate the prioritization
β€’ Automate your remediation

More Related Content

PPTX
Automating Open Source Security: A SANS Review of WhiteSource
PDF
From Zero To Hero: Continuous Container Security in 4 Simple Steps- A WhiteSo...
PDF
CI/CD pipeline security from start to finish with WhiteSource & CircleCI
PPTX
WhiteSource Webinar What's New With WhiteSource in December 2018
PPTX
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
PPTX
The State of Open Source Vulnerabilities - A WhiteSource Webinar
PDF
Open Source Security at Scale- The DevOps ChallengeΒ 
PPTX
WhiteSource Webinar-New Research Reveals Key Strategy to Manage Open Source S...
Automating Open Source Security: A SANS Review of WhiteSource
From Zero To Hero: Continuous Container Security in 4 Simple Steps- A WhiteSo...
CI/CD pipeline security from start to finish with WhiteSource & CircleCI
WhiteSource Webinar What's New With WhiteSource in December 2018
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
The State of Open Source Vulnerabilities - A WhiteSource Webinar
Open Source Security at Scale- The DevOps ChallengeΒ 
WhiteSource Webinar-New Research Reveals Key Strategy to Manage Open Source S...

What's hot (20)

PPTX
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
PPTX
Find Out What's New With WhiteSource May 2018- A WhiteSource Webinar
PPTX
Managing Open Source in Application Security and Software Development Lifecycle
PDF
8 Patterns For Continuous Code Security by Veracode CTO Chris Wysopal
PPTX
Empowering Application Security Protection in the World of DevOps
PPTX
7 Reasons Your Applications are Attractive to Adversaries
PPTX
September 13, 2016: Security in the Age of Open Source:
PDF
PIACERE - DevSecOps Automated
PPTX
Open Source and Cyber Security: Open Source Software's Role in Government Cyb...
PDF
Myths and Misperceptions of Open Source Security
PDF
How to automate your DevSecOps successfully
PPTX
Open Source Security
PDF
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
PPTX
DevSecOps outline
PDF
Dev week cloud world conf2021
PPTX
Security in the Age of Open Source
PDF
Devops security-An Insight into Secure-SDLC
PPTX
Secure application deployment in Apache CloudStack
PPTX
DevSecOps Days SF at RSA Conference 2018
PDF
Open Source in Application Security
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
Find Out What's New With WhiteSource May 2018- A WhiteSource Webinar
Managing Open Source in Application Security and Software Development Lifecycle
8 Patterns For Continuous Code Security by Veracode CTO Chris Wysopal
Empowering Application Security Protection in the World of DevOps
7 Reasons Your Applications are Attractive to Adversaries
September 13, 2016: Security in the Age of Open Source:
PIACERE - DevSecOps Automated
Open Source and Cyber Security: Open Source Software's Role in Government Cyb...
Myths and Misperceptions of Open Source Security
How to automate your DevSecOps successfully
Open Source Security
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
DevSecOps outline
Dev week cloud world conf2021
Security in the Age of Open Source
Devops security-An Insight into Secure-SDLC
Secure application deployment in Apache CloudStack
DevSecOps Days SF at RSA Conference 2018
Open Source in Application Security
Ad

Similar to The Devops Challenge: Open Source Security Throughout the DevOps Pipline- A WhiteSource Webinar (20)

PDF
The DevOps Challenge: Open Source Security at Scale
PDF
Winning open source vulnerabilities without loosing your deveopers - Azure De...
PPTX
Welcome & The State of Open Source Security
PDF
All Things Open 2022 - State of OSS Security & Support
PDF
The State of Open Source Vulnerabilities Management
PDF
The State of Open Source Vulnerabilities Management
PDF
Synopsys Security Event Israel Presentation: New AppSec Paradigms with Open S...
PPTX
All You need to Know about Secure Coding with Open Source Software
PPTX
A question of trust - understanding Open Source risks
PPTX
Secure application deployment in the age of continuous delivery
PDF
(In)security in Open Source
PDF
Webinar–2019 Open Source Risk Analysis Report
PPTX
Security in the age of open source - Myths and misperceptions
PPTX
Secure application deployment in the age of continuous delivery
PPTX
Secure application deployment in the age of continuous delivery
PDF
Donu’t Let Vulnerabilities Create a Hole in Your Organization
PPTX
Open Source Insight: NotPetya Strikes, Patching Is Vital for Risk Management
PDF
2016 Future of Open Source Survey Results
PPTX
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
PPTX
Black Duck & IBM Present: Application Security in the Age of Open Source
The DevOps Challenge: Open Source Security at Scale
Winning open source vulnerabilities without loosing your deveopers - Azure De...
Welcome & The State of Open Source Security
All Things Open 2022 - State of OSS Security & Support
The State of Open Source Vulnerabilities Management
The State of Open Source Vulnerabilities Management
Synopsys Security Event Israel Presentation: New AppSec Paradigms with Open S...
All You need to Know about Secure Coding with Open Source Software
A question of trust - understanding Open Source risks
Secure application deployment in the age of continuous delivery
(In)security in Open Source
Webinar–2019 Open Source Risk Analysis Report
Security in the age of open source - Myths and misperceptions
Secure application deployment in the age of continuous delivery
Secure application deployment in the age of continuous delivery
Donu’t Let Vulnerabilities Create a Hole in Your Organization
Open Source Insight: NotPetya Strikes, Patching Is Vital for Risk Management
2016 Future of Open Source Survey Results
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
Black Duck & IBM Present: Application Security in the Age of Open Source
Ad

More from WhiteSource (17)

PPTX
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
PDF
Innocent Vulnerabilities vs. Malicious Backdoors: How to Manage Your Risk
PDF
Empowering Financial Institutions to Use Open Source With Confidence
PDF
Tackling the Container Iceberg:How to approach security when most of your sof...
PDF
Taking Open Source Security to the Next Level
PDF
Securing Container-Based Applications at the Speed of DevOps
PDF
The Challenges of Scaling DevSecOps
PDF
Tackling the Risks of Open Source Security: 5 Things You Need to Know
PDF
Open Source Security: How to Lay the Groundwork for a Secure Culture
PDF
Deep Dive into Container Security
PDF
Fire alarms vs. Fire hoses: Keeping up with Dependencies
PDF
DevSecOps: Closing the Loop from Detection to Remediation
PDF
Barriers to Container Security and How to Overcome Them
PDF
SAST (Static Application Security Testing) vs. SCA (Software Composition Anal...
PDF
Top Open Source Licenses Explained
PPTX
Strategies for Improving Enterprise Application Security - a WhiteSource Webinar
PPTX
How temenos manages open source use, the easy way combined
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
Innocent Vulnerabilities vs. Malicious Backdoors: How to Manage Your Risk
Empowering Financial Institutions to Use Open Source With Confidence
Tackling the Container Iceberg:How to approach security when most of your sof...
Taking Open Source Security to the Next Level
Securing Container-Based Applications at the Speed of DevOps
The Challenges of Scaling DevSecOps
Tackling the Risks of Open Source Security: 5 Things You Need to Know
Open Source Security: How to Lay the Groundwork for a Secure Culture
Deep Dive into Container Security
Fire alarms vs. Fire hoses: Keeping up with Dependencies
DevSecOps: Closing the Loop from Detection to Remediation
Barriers to Container Security and How to Overcome Them
SAST (Static Application Security Testing) vs. SCA (Software Composition Anal...
Top Open Source Licenses Explained
Strategies for Improving Enterprise Application Security - a WhiteSource Webinar
How temenos manages open source use, the easy way combined

Recently uploaded (20)

PPTX
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PDF
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PDF
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PPTX
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
Β 
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
PDF
Exploring VPS Hosting Trends for SMBs in 2025
PDF
Sims 4 Historia para lo sims 4 para jugar
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPTX
E -tech empowerment technologies PowerPoint
PPTX
SAP Ariba Sourcing PPT for learning material
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PPTX
artificialintelligenceai1-copy-210604123353.pptx
Β 
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
June-4-Sermon-Powerpoint.pptx USE THIS FOR YOUR MOTIVATION
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
πŸ’° π”πŠπ“πˆ πŠπ„πŒπ„ππ€ππ†π€π πŠπˆππ„π‘πŸ’πƒ π‡π€π‘πˆ 𝐈𝐍𝐈 πŸπŸŽπŸπŸ“ πŸ’°
Β 
Design_with_Watersergyerge45hrbgre4top (1).ppt
Decoding a Decade: 10 Years of Applied CTI Discipline
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
Power Point - Lesson 3_2.pptx grad school presentation
Β 
PptxGenJS_Demo_Chart_20250317130215833.pptx
international classification of diseases ICD-10 review PPT.pptx
Exploring VPS Hosting Trends for SMBs in 2025
Sims 4 Historia para lo sims 4 para jugar
Introuction about ICD -10 and ICD-11 PPT.pptx
INTERNET------BASICS-------UPDATED PPT PRESENTATION
E -tech empowerment technologies PowerPoint
SAP Ariba Sourcing PPT for learning material
WebRTC in SignalWire - troubleshooting media negotiation
artificialintelligenceai1-copy-210604123353.pptx
Β 
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt

The Devops Challenge: Open Source Security Throughout the DevOps Pipline- A WhiteSource Webinar

Editor's Notes

  • #12: Recent news – general vulnerability or open source?
  • #13: What’s this about? Apache struts in a docker environment (in