null Global Committee elections are coming up! See the election repository for more information.

B2e985117fdb9deeff71e6ed154d7f08

Abstract

Software Composition Analysis (SCA) is crucial for securing dependencies, but existing tools often have limitations in accuracy, false positives, or ecosystem support. In this talk, we explore the core components of an SCA tool and walk through the journey of building Tej, an open-source SCA scanner for Node.js, integrating OpenSSF Scorecard and CVE detection. Attendees will learn the challenges in SCA, designing efficient scanners, and improving vulnerability detection beyond traditional tooling.

Speaker

Hare Krishna Rai

Timing

Starts at Saturday March 29 2025, 11:15 AM. The sessions runs for about 1 hour.

Resources