{"id":62492,"date":"2021-10-05T05:52:04","date_gmt":"2021-10-05T13:52:04","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/devops\/?p=62492"},"modified":"2021-10-05T05:52:04","modified_gmt":"2021-10-05T13:52:04","slug":"azurefunbytes-episode-58-improve-your-open-source-security-with-whitesourcesoft","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/devops\/azurefunbytes-episode-58-improve-your-open-source-security-with-whitesourcesoft\/","title":{"rendered":"AzureFunBytes Episode 58 &#8211; Improve your Open Source Security with @WhiteSourceSoft"},"content":{"rendered":"<p>AzureFunBytes is a weekly opportunity to learn more about the fundamentals and foundations that make up Azure. It&#8217;s a chance for me to understand more about what people across the Azure organization do and how they do it. Every week we get together at 11 AM Pacific on <a href=\"https:\/\/cda.ms\/226\">Microsoft LearnTV<\/a> and learn more about Azure.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/practicaldev\/image\/fetch\/s--Z7BxBMz1--\/c_limit%2Cf_auto%2Cfl_progressive%2Cq_66%2Cw_880\/https:\/\/dev-to-uploads.s3.amazonaws.com\/uploads\/articles\/j2xzw2g664tj31jij13t.gif\" alt=\"AzureFunBytes animation\" \/><\/p>\n<p>One of my favorite parts of doing this show is meeting people across the world who want to help others have a safe and secure experience on Azure.  I&#8217;ve done my best to find guests in the last few weeks that really drill down the importance of &#8220;shifting left&#8221; while developing software.  This is an effort that should start at your planning process and involve everyone from your developers, product managers, and ops.<\/p>\n<p>This week is no different as we talk about securing open source management workflows.  As developers progress along the software delivery lifecycle there&#8217;s a need to ensure that security scans can be automated.  By implementing products like <a href=\"https:\/\/www.whitesourcesoftware.com\/\">WhiteSource<\/a> you can automatically detect, prioritize, and remediate your open source security vulnerabilities.<\/p>\n<p>On this episode of AzureFunBytes, <a href=\"https:\/\/twitter.com\/rarkins\">Rhys Arkins<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/lena-kleyner-1a74935\">Lena Kleyner<\/a> of <a href=\"https:\/\/www.whitesourcesoftware.com\/\">WhiteSource Software<\/a> are here to introduce us to WhiteSource&#8217;s security and licensing capabilities for Azure DevOps!<\/p>\n<p><iframe title=\"AzureFunBytes Episode 58 - Improve your Open Source Security with @WhiteSourceSoft\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/dIxL1zDi-jI?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p><a href=\"https:\/\/youtu.be\/qhKWAeenqXQ\">00:00:00 &#8211; Opening<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=389\">00:06:29 &#8211; Let&#8217;s meet Lena and Rhys<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=1110\">00:18:30 &#8211; Detection, Prioritization, Remediation<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=1605\">00:26:45 &#8211; Open source Security<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=2082\">00:34:42 &#8211; Demoing WhiteSource and Azure DevOps<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=2532\">00:42:12 &#8211; Open source risk report<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=3020\">00:50:20 &#8211; Free plugin<\/a><br>\n<a href=\"https:\/\/youtu.be\/qhKWAeenqXQ?t=3183\">00:53:03 &#8211; Diffend<\/a><\/p>\n<p>Our agenda includes:<\/p>\n<ul>\n<li>Rhys &amp; Lena&#8217;s roles at WhiteSource<\/li>\n<li>Software Composition Analysis (SCA) importance<\/li>\n<li>SCA in the SDLC, including AZDO<\/li>\n<li>Pipeline plugin for scanning<\/li>\n<li>UI for security and compliance reports<\/li>\n<li>Renovate tool for Dependency automation<\/li>\n<li>Diffend service for Supply Chain security<\/li>\n<li>Future Azure repos integrations<\/li>\n<\/ul>\n<p><strong>About Rhys Arkins:<\/strong><\/p>\n<p><em>Rhys Arkins is the Director of Product Management at WhiteSource responsible for developer tooling and supply chain security. He joined WhiteSource in 2019 through the acquisition of his startup &#8220;Renovate Bot&#8221;, which he continues to take a leading role on. Rhys is a big believer in automation in the SDLC as a way to produce better, quicker, more consistent outcomes.<\/em><\/p>\n<p><strong>About Lena Kleyner:<\/strong><\/p>\n<p><em>Lena Kleyner is a Product Manager at WhiteSource with a vast technical background. With more than 10 years as a software developer, she is leading WhiteSource&#8217;s integrations and scanning agents. Lena specifically enjoys connecting between customers&#8217; needs and the proper technical solutions.<\/em><\/p>\n<hr \/>\n<p>Learn about Azure fundamentals with me!<\/p>\n<p>Live stream is normally found on Twitch, YouTube, and <a href=\"https:\/\/cda.ms\/226\">LearnTV<\/a> at 11 AM PT \/ 2 PM ET Thursday. You can also find the recordings here as well:<\/p>\n<p><a href=\"https:\/\/twitch.tv\/azurefunbytes\">AzureFunBytes on Twitch<\/a><br>\n<a href=\"https:\/\/aka.ms\/jaygordononyoutube\">AzureFunBytes on YouTube<\/a><br>\n<a href=\"https:\/\/www.youtube.com\/channel\/UC-ikyViYMM69joIAv7dlMsA\">Azure DevOps YouTube Channel<\/a><br>\n<a href=\"https:\/\/twitter.com\/azurefunbytes\">Follow AzureFunBytes on Twitter<\/a><br><\/p>\n<p>Useful Docs:<\/p>\n<p><a href=\"https:\/\/cda.ms\/219\">Get $200 in free Azure Credit<\/a><br>\n<a href=\"https:\/\/cda.ms\/243\">Microsoft Learn: Introduction to Azure fundamentals<\/a><br>\n<a href=\"https:\/\/www.whitesourcesoftware.com\/\">WhiteSource Software<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Ld\">WhiteSource for Azure DevOps Services<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Lf\">WhiteSource Bolt<\/a><br>\n<a href=\"https:\/\/github.com\/renovatebot\/renovate\">Renovate Bot open source<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Lg\">Renovate Me community pipeline<\/a><br>\n<a href=\"https:\/\/www.whitesourcesoftware.com\/whitesource-diffend\/\">WhiteSource Diffend<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Lk\">WhiteSource Essentials<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Lm\">WhiteSource streamlines application delivery and development with Microsoft Azure and Azure Kubernetes Service<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Ln\">Microsoft Security Engineer certification path<\/a><br>\n<a href=\"https:\/\/cda.ms\/2Lp\">Enable DevSecOps with Azure and GitHub<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As developers progress along the software delivery lifecycle there&#8217;s a need to ensure that security scans can be automated. By implementing products like WhiteSource you can automatically detect, prioritize, and remediate your open source security vulnerabilities.<\/p>\n","protected":false},"author":39313,"featured_media":62493,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[249,251],"tags":[],"class_list":["post-62492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-open-source","category-security"],"acf":[],"blog_post_summary":"<p>As developers progress along the software delivery lifecycle there&#8217;s a need to ensure that security scans can be automated. By implementing products like WhiteSource you can automatically detect, prioritize, and remediate your open source security vulnerabilities.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/62492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/users\/39313"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/comments?post=62492"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/62492\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media\/62493"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media?parent=62492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/categories?post=62492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/tags?post=62492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}