Loading…
Attending this event?
September 30 - October 1, 2024 | New York, New York
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source in Finance Forum New York 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Savings Time (EDT). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
Monday September 30, 2024 2:30pm - 3:00pm EDT
Improving software supply chain security starts with a secure foundation. The FINOS community has recently intensified efforts to help members enhance software supply chain security on two critical fronts:

1. Empowering maintainers to assess and improve their dependency ingestion with access to enterprise-grade software composition analysis (SCA)
2. Providing in-depth dependency consumption analysis, including a detailed review of member downloads from Maven Central

In this presentation, Brian Fox, co-founder of Sonatype, the maintainers of Maven Central, will explore the tangible risks the FINOS community is addressing through these initiatives. He’ll walk through a detailed consumption analysis report from Maven Central, sharing industry insights, what these trends reveal about software supply chain risks, and actionable steps organizations can take to enhance their security posture. Additionally, he’ll provide an overview of the SCA tools available to maintainers to reduce risk and improve delivery across FINOS projects.
Speakers
avatar for Brian Fox

Brian Fox

Cofounder & CTO, Sonatype
Co-founder and CTO, Brian Fox is a Governing Board member for the Opensource Security Foundation, a member of the Apache Software Foundation and former Chair of the Apache Maven project. As a direct contributor to the Maven ecosystem, including the maven-dependency-plugin and maven-enforcer-plugin... Read More →
Monday September 30, 2024 2:30pm - 3:00pm EDT
Royale + Plymouth

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link