Adam Berman
@adamberman_13
Ultimate Frisbee, SF sports, and sometimes security/technical leadership. Eng director @ semgrep.dev
ID: 253414612
17-02-2011 05:41:47
46 Tweet
187 Followers
413 Following
Travis McPeak Jim Manico from Manicode Security What Semgrep is doing, that I really like, is looking at if the lib is reachable. Idea is that using semgrep to scan too, as well as understanding sources, sinks and data flow, we are better armed at making the decision of if it is exploitable
We’ve saved the best for last! Don’t miss Adam Berman's “When is a vulnerability, not a vulnerability? Overcoming the inundation of noisy security alerts” in 1 hour sched.co/1JrCj
✅ The solution: Reachability Analysis This goes beyond traditional SCA to only flag when you have a dependency at a vulnerable version AND you're using the vulnerable code ➡️ Drastically reduces alerts in practice For operationalizing this approach, ping Adam Berman
My talk is live! Thanks for the shoutout Chris Krycho!