The SCA Balancing Act @OWASPGLOBAL
The SCA Balancing Act  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
Software Composition Analysis (SCA) is among the most foundational approaches to application security. Understanding the known vulnerabilities, leading and lagging indicators of risk are among the most widely leveraged security controls in industry. There are three major types of SCA: Runtime SCA, Manifest scanning SCA and Build/Install-time SCA with and without program analysis. Each approach comes with hidden costs and pros and cons along the way. This session will explore not only the hidden costs, pros and cons but explain why they exist. We will round out with effective practices, classes of vulnerabilities that are covered and things to avoid with each approach. Everyone has heard that there is a panacea for managing risk in software composition analysis. You see this in marketing every day. This nirvana is a lie. But there could be a nirvana for you in your context. This talk explores the spectrum of trade offs that exist.

Jamie Scott
Endor Labs
Product Manager
Santa Clara, CA

https://x.com/iamateapot418
linkedin.com/in/james-m-scott-iii

Jamie Scott, CISSP, CCSP is a recovering cybersecurity practitioner turned product manager building the next generation of dependency management solutions at Endor Labs. Previously Jamie was Product Manager at Redis and StackRox (Acquired by Red Hat in Feb 2021) where he was an open source contributor and leader for both projects. Jamie remains an active contributor to the cybersecurity community as co-author and contributor to several benchmarks as a volunteer consultant for the Center for Internet Security.

Managed by the OWASP® Foundation
owasp.org
The SCA Balancing ActHow Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent BouchardThe Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin LehrLeaking Secrets in the Age of AI: How AI Adoption is Creating New Attack VectorsBuilding Security Into Developer Velocity: How We Made Entra Identity Compliance Invisible track 1Keynote by Adam Shostack: Stop Trying to Manage RiskOWASP Board of Directors - July 2026 Public Board MeetingNo Fate But What We Make: Doing Intrusion PredictionCycloneDX 2.0 Preview: Evolving BOM Architecture for Broader ApplicabilityGuardrails First: Building AI Agents That Won’t Leak Your Secrets - Track 2Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third PartySecure Financial Analytics with Homomorphic Encryption and GAN Driven Data Track 2
OWASP Foundation |

The SCA Balancing Act

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER