#dependencytrack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dependencytrack, aggregated by home.social.
-
OWASP Dependency-Track v5.0.3 released
https://secburg.com/posts/dependency-track-v503-released/
#DependencyTrack #OWASP #SBOM #SupplyChainSecurity #DevSecOps
-
«РБПО для бедных»: настраиваем сервисы безопасной разработки
В прошлой статье цикла мы закончили разворачивать инфраструктуру будущего РБПО: установили GitLab, Nexus, HashiCorp Vault, Dependency-Track и DefectDojo, подготовили отдельную виртуальную машину с инструментами безопасности и убедились, что все сервисы успешно запускаются. Но установить сервисы — это только половина дела. Теперь их нужно настроить и подготовить к совместной работе. Без этого GitLab останется просто GitLab, Vault — просто хранилищем секретов, а DefectDojo и Dependency-Track — красивыми веб-интерфейсами без практической пользы. В этой статье займемся базовой конфигурацией. Настроим GitLab и GitLab Runner, подготовим Nexus к приему артефактов, научим Vault доверять GitLab через JWT-аутентификацию и создадим необходимые сущности в DefectDojo и Dependency-Track. Документация открыта, терминал запущен, банка кваса на месте. Начинаем настройку инструментов.
https://habr.com/ru/companies/bastion/articles/1041704/
#vault #devsecops #рбпо #безопасная_разработка #gitlab #Nexus #hashicorp_vault #DefectDojo #DependencyTrack #настройка
-
«РБПО для бедных»: разворачиваем сервисы безопасной разработки
В прошлой части цикла мы подготовили фундамент будущего РБПО: развернули виртуальные машины, настроили Ubuntu Server, сеть, брандмауэр и Docker. Другими словами, построили площадку, на которой теперь можно начинать возводить сам конвейер безопасной разработки. Теперь пора наполнять наши виртуальные машины полезным содержимым. Если продолжать сказочную аналогию — заселим наше царство безопасной разработки первыми жителями: хранителем секретов, смотрителем артефактов, летописцем уязвимостей и прочими полезными персонажами. То есть установим и настроим GitLab, Nexus, HashiCorp Vault, DefectDojo и Dependency-Track, а также подготовим отдельную виртуальную машину с набором CLI-инструментов для анализа безопасности. Большая часть сервисов будет работать в Docker-контейнерах, поэтому заодно разберемся с настройкой постоянного хранения данных, Docker Compose и некоторыми особенностями конфигурации отдельных компонентов. Что ж, глаза боятся, а руки команды в терминале набирают. Начнем с GitLab.
https://habr.com/ru/companies/bastion/articles/1038710/
#рбпо #безопасная_разработка #стартапы #DevSecOps #развертывание_GitLab #управление_секретами #HashiCorp_Vault #конвейер_безопасной_разработки #defectdojo #DependencyTrack
-
Modern supply chain security can't rely on periodic scans. When the next CVE drops, you need fleet-wide visibility immediately.
Our Managed #DependencyTrack provides continuous #SBOM monitoring with multi-source vulnerability intelligence, smart triage (#VEX + #EPSS), and complete data sovereignty, all without the operational overhead of DIY deployment.
#OpenSource at the core. Managed where it matters.
Read our 2026 guide to continuous supply chain security:
https://www.amazee.io/blog/post/dependency-track-software-supply-chain-security -
Modern apps ship fast. Dependencies change faster. Without continuous monitoring, new vulnerabilities can remain unnoticed for weeks.
Managed #DependencyTrack automates #SBOM analysis and vulnerability monitoring. Powered by #OWASP, hosted on our infrastructure, you get the platform without the operational overhead.
-
Today is the day!
Join us at 3 PM CDT for a live deep-dive into #DependencyTrack.
We're showing you how to move from point-in-time scans to continuous, real-time SBOM analysis.
Learn how to use EPSS to prioritize what’s actually being exploited and ignore the noise. Grab your spot now!
🔗 https://www.amazee.io/blog/post/live-uncover-hidden-vulnerabilities-with-dependency-track/
-
Is your security team drowning in "critical" alerts that aren't actually exploitable? 🌊
Most teams treat dependency risk as a manual chore, but our webinar on April 8 shows you how to make it continuous and automated.
We have a few seats left to show you how #DependencyTrack uses EPSS and VEX to filter out the noise and prioritize real threats. Grab one of the final spots while they’re still available!
💺 https://www.amazee.io/blog/post/live-uncover-hidden-vulnerabilities-with-dependency-track/
P.S. Can't make it? Register anyway & you'll get the recording
-
Is your security team drowning in "critical" alerts that aren't actually exploitable?
🌊🧘♂️ Most teams treat dependency risk as a periodic task, but our webinar on April 8 shows you how to make it continuous.
We'll explore how #DependencyTrack uses #EPSS and #VEX to filter out the noise and prioritize the 10% of vulnerabilities that actually pose a threat to your production environment.
🔗 https://www.amazee.io/blog/post/live-uncover-hidden-vulnerabilities-with-dependency-track
-
@andrewnez cool concept, I think it would be a big help when triaging reports from the #DependencyTrack from #OWASP. While I would want to identify critical #CVEs I also need to know the likelihood that a less serious CVE has a higher possibility to be targeted.
-
I've got a questions about working with the tools provided by #OWASP.
When working within the #Java and #Maven build environments to use both the dependency-check plugin as well as the DependencyTrack application? I do know that the #DependencyTrack uses the #CycloneDX plugin to generate the BOM. What I'm trying to prevent is extra build time used up to perform similar operations.
-
CVEs reported without version, and/or never updated to limit their CPEs to exclude versions where the vulnerability is fixed;
and now I get false positives every single time I update that dependency 😭
(in this case, specifically, Keycloak's CVE-2020-1717, CVE-2022-1438 and CVE-2023-0105, both still reported on version 22.0.4 by Dependency Track; the GitHub Advisories have the accurate information, but not the NVD 😡)
-
Google Publishes a Tutorial on How To Deploy #OWASP #DependencyTrack Platform to Google Cloud:
#SupplyChainSecurity
#OpenSource
#SBOMhttps://cloud.google.com/community/tutorials/deploy-dependency-track