Here is another post on my favorite quotes from the Security at the Speed of Development webinar with Wendy Nather, Research Director, Security for 451 Research and Ryan Berg, Sonatype CSO. Wendy was talking about how inertia makes it difficult to justify fixing security flaws later in the development lifecycle:
Wendy also noted the need to protect the entire supply chain including assets that are sourced from third parties. Her Twitter reference implied that some suppliers will not address security flaws until negative publicity forces them to act.
There are multiple reasons flaws are not fixed: lack of budget, poor project planning, shifting resources, etc. Another factor is that today's security tools are focused on discovery, they don't help you fix problems. Ryan went on to say:
We took this challenge into account when we designed the Sonatype CLM. Not only does the CLM help you identify security, licensing and quality flaws, it helps you prioritize and fix the problems, directly in the IDE.
To see how you can fix flaws with the Sonatype CLM, check out the "Quickly identify your exposure and remediate flaws" section of the product tour.
Make sure you read Wendy's research Mission Impossible: securing the open source software supply chain with Sonatype.