DevOps.com

  • Latest
    • Articles
    • Features
    • Most Read
    • News
    • News Releases
  • Topics
    • AI
    • Continuous Delivery
    • Continuous Testing
    • Cloud
    • Culture
    • DataOps
    • DevSecOps
    • Enterprise DevOps
    • Leadership Suite
    • DevOps Practice
    • ROELBOB
    • DevOps Toolbox
    • IT as Code
  • Videos/Podcasts
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • DevOps Unbound
  • Webinars
    • Upcoming
    • On-Demand Webinars
  • Library
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Related Sites
    • Techstrong Group
    • Container Journal
    • Security Boulevard
    • Techstrong Research
    • DevOps Chat
    • DevOps Dozen
    • DevOps TV
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
  • Media Kit
  • About
  • Sponsor
  • AI
  • Cloud
  • Continuous Delivery
  • Continuous Testing
  • DataOps
  • DevSecOps
  • DevOps Onramp
  • Platform Engineering
  • Low-Code/No-Code
  • IT as Code
  • More
    • Application Performance Management/Monitoring
    • Culture
    • Enterprise DevOps
    • ROELBOB
Hot Topics
  • HPE to Acquire OpsRamp to Gain AIOps Platform
  • Oracle Makes Java 20 Platform Generally Available
  • How to Maximize Telemetry Data Value With Observability Pipelines
  • Awareness of Software Supply Chain Security Issues Improves
  • Why Observability is Important for Development Teams

Home » Blogs » DevSecOps » DevOpsSec: Survival is Not Mandatory

DevOpsSec: Survival is Not Mandatory

By: Derek E. Weeks on December 8, 2015 1 Comment

Deming, the patron saint of DevOps once advised, “It is not necessary to change.  Survival is not mandatory.”

Recent Posts By Derek E. Weeks
  • State of the Software Supply Chain: Secure Coding Takes Spotlight
  • Reducing Risk in Applications Using Docker Containers
  • 200 Billion Downloads Can’t Be Wrong
More from Derek E. Weeks
Related Posts
  • DevOpsSec: Survival is Not Mandatory
  • DevOpsSec – Creating the Full Triangle
  • The devOpsSec Dilemma: Effective Strategies for Social Networking
    Related Categories
  • Blogs
  • DevSecOps
    Related Topics
  • application security
  • Archiva
  • Artifactory
  • continuous delivery
  • DevOpsSec
  • Nexus
  • OSS Goverance
  • Repository Manager
  • rugged devops
Show more
Show less

To survive, application development teams are constantly pressured to deliver software even faster.  But fast is not enough.  The best organizations realize that security, quality and integrity at velocity are mandatory for survival. Hence, DevOpsSec

My aim here is to leave you uncomfortably amazed.  While the pace of development has changed significantly, our processes to secure our applications has not changed enough.  It is as if a wildfire has raged uncontained for years now but we have failed to take notice.

Maybe that sounds a bit crazy, but once I share a little background on what is happening, you’ll understand why innovation in this arena is critical for survival (when it comes to your applications).  If you are aiming to ramp up your own Rugged DevOps or DevOpsSec practices, this is critical reading material.

Skyrocketing Usage, Plummeting Visibility

Open source component use in development is skyrocketing, and for good reason.  Over 17 billion open source and third-party components — across the major development languages — were downloaded last year helping development teams accelerate release timelines and deliver more innovative solutions to market.  To better imagine the impact of this download volume, you need to understand that there are an estimated 11 million developers responsible for the billions of downloads.

While the magnitude of usage is amazing it has obscured a vast majority of the risks.  Of the billions of downloads recorded last year, 1 in 16 components downloaded had known security vulnerabilities.

Screen Shot 2015-11-30 at 1.23.55 PM

While we have seen 30x growth of download requests over the past seven years, we have also witnessed huge growth in the number of organizations improving the speed of consumption and efficiency of their downloads using repository managers.

In the past 18 months since I joined Sonatype, we have seen active instances of repository managers like Nexus, Artifactory, and Archiva grow from 40,000 to over 70,000 installations, with users in the millions — also for good reason.  Development teams want to ensure faster, more reliable builds.  They also need a private and safe place to house and share their own proprietary components as well as assembled applications, images and other binary outputs.  The repository manager has established itself as a parts warehouse for software development.

All is Not Moonlight and Roses

1 in 16 may not sound like a lot until you recognize that many organizations are downloading over 250,000 components every year…some of the largest organizations consume millions of them.  If you have not calculated this in your head yet: 250,000 / 16 = 15,625.

Screen Shot 2015-11-30 at 1.24.07 PM

Couple this fact with the remarks in the 2015 Verizon Data Breach and Investigations Report stating that applications were the most often exploited attack vector by hackers.  As a developer community we are electively sourcing known vulnerable components for use in our applications and those applications are now more vulnerable to attack.  

Your Repository Manager Should Serve and Protect

If bad components are getting in, why not just stop them at the front door?

Easier said than done.   Current approaches to preventing such behavior are ineffective.  For some, “golden repositories” are used to house approved components — but components approved once are rarely vetted again for newly discovered vulnerabilities.  For other organizations, OSS Review Boards mandate reviews and approval for all new components — but these organizations are poorly staffed to match the volume and velocity of consumption leading to workarounds by development teams.  And while developers themselves would much prefer to use the best quality, highest integrity components when designing an applications, they are never allocated sufficient time to investigate the vulnerability status of every component required for their latest build.

Sparking Innovation

When current approaches fail, inspiration often sparks innovation.  

Enter, a new invention: a repository firewall.  Think of it as a repository manager with a guard at the front door.  Every component that gets downloaded by a proxy repository is automatically evaluated against the parameters development, governance and security teams establish.  Does it have an AGPL license, include a known security vulnerability, or is it incredibly outdated?  The repository firewall allows organizations to download “good” components while it blocks and quarantines “bad” component downloads.  Using a repository firewall can keep your repository manager and development lifecycle safe and secure – in an instant, automatically.

The first repository firewall of its kind is called Nexus Firewall.  It couples software supply chain intelligence about component quality, security, and risks with automatic evaluations against personalized policies for approving or rejecting new downloads.  Evaluations can also be applied later in the development lifecycle where staging repositories are in use.

Screen Shot 2015-11-30 at 1.12.58 PM

Imagine the result: 16 out of 16 downloads, or 250,000 out of 250,000 downloads are now of the best quality.  Everything flowing into your application development lifecycle contains the highest quality components.  You are instantly compliant with established policies.  Your applications are less vulnerable to attacks.  You are automatically reducing risk.

Next up in this series, I will share insights about Repository Health Check reports (free to use).  Used by over 15,000 organizations, they can offer organizations the first clue as to whether or not your team could benefit from a repository firewall.  

 

Filed Under: Blogs, DevSecOps Tagged With: application security, Archiva, Artifactory, continuous delivery, DevOpsSec, Nexus, OSS Goverance, Repository Manager, rugged devops

« How do you identify gaps in your testing?
Win – Win »

Techstrong TV – Live

Click full-screen to enable volume control
Watch latest episodes and shows

Upcoming Webinars

The Testing Diaries: Confessions of an Application Tester
Wednesday, March 22, 2023 - 11:00 am EDT
The Importance of Adopting Modern AppSec Practices
Wednesday, March 22, 2023 - 1:00 pm EDT
Cache Reserve: Eliminating the Creeping Costs of Egress Fees
Thursday, March 23, 2023 - 1:00 pm EDT

Sponsored Content

The Google Cloud DevOps Awards: Apply Now!

January 10, 2023 | Brenna Washington

Codenotary Extends Dynamic SBOM Reach to Serverless Computing Platforms

December 9, 2022 | Mike Vizard

Why a Low-Code Platform Should Have Pro-Code Capabilities

March 24, 2021 | Andrew Manby

AWS Well-Architected Framework Elevates Agility

December 17, 2020 | JT Giri

Practical Approaches to Long-Term Cloud-Native Security

December 5, 2019 | Chris Tozzi

Latest from DevOps.com

HPE to Acquire OpsRamp to Gain AIOps Platform
March 21, 2023 | Mike Vizard
Oracle Makes Java 20 Platform Generally Available
March 21, 2023 | Mike Vizard
How to Maximize Telemetry Data Value With Observability Pipelines
March 21, 2023 | Tucker Callaway
Awareness of Software Supply Chain Security Issues Improves
March 21, 2023 | Mike Vizard
Why Observability is Important for Development Teams
March 21, 2023 | John Bristowe

TSTV Podcast

On-Demand Webinars

DevOps.com Webinar ReplaysDevOps.com Webinar Replays

GET THE TOP STORIES OF THE WEEK

Most Read on DevOps.com

Large Organizations Are Embracing AIOps
March 16, 2023 | Mike Vizard
Addressing Software Supply Chain Security
March 15, 2023 | Tomislav Pericin
Modern DevOps is a Chance to Make Security Part of the Process
March 15, 2023 | Don Macvittie
What NetOps Teams Should Know Before Starting Automation Journeys
March 16, 2023 | Yousuf Khan
DevOps Adoption in Salesforce Environments is Advancing
March 16, 2023 | Mike Vizard
  • Home
  • About DevOps.com
  • Meet our Authors
  • Write for DevOps.com
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • Privacy Policy

Powered by Techstrong Group, Inc.

© 2023 ·Techstrong Group, Inc.All rights reserved.