Open Source Software Vulnerability Management with Sonatype’s Tyler Warden
As the number of cyberattacks increases due to accessible code modification and reverse engineering tools, open source software faces heightened vulnerability. Resource-limited volunteers often maintain this software, compounding the issue. To address this, Sonatype has launched an integration with ServiceNow to enhance software vulnerability detection. This integration allows Sonatype Lifecycle’s vulnerability scan results to flow directly into ServiceNow’s Application Vulnerability Response (AVR), streamlining vulnerability management. Amid relentless security threats, this integration empowers IT and security teams to identify, track, and remediate vulnerabilities efficiently, helping them stay ahead of potential attacks.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Techstrong tv.
Our next guest is Tyler Warden. Tyler is the SVP of product at Sona Type. com, security Boulevard, cloud native.
Now, sort of the types of company we've been covering for as long as I've been doing this, I had a lot of friends from Wayne Jackson, the CEO on down there. Tyler, welcome to Techstrong tv. It's great to have you on.
Thanks, I'm happy to be here. So your SVP of product over here at Soda Type. Why don't you give us maybe a little bit of your background?
Yeah, I've been in, uh, enterprise software and Tech for about 20 years and had almost every job you could have. I've been an engineer. I ran engineering teams.
I've been a product manager, product owners, sales engineer, product marketing, uh, and I really love kind of using technology to build solutions and solve problems. I started off as a, as a guy that wanted to do music and acting. Um, so I find that the same scratching the itch of creativity that I got from performing and doing music is often met with using technology to make creative, fun solutions for the customers.
And I'm a enterprise software guy, right? I'm a, I'm a B2B software guy, building, shipping, selling, supporting, and strategizing. So that's me.
And right now I've got the privilege to, uh, be the head of product over here at tit. Love it. So, binging instrument playing What, what, what, what's the music?
Becca, Uh, classically trained. My, my, my goal for a time was to be a classical music orchestra conductor. Really?
Yeah. That's what I wanted to love it to do. Went to college for music and business with the it they call it is at the time focus.
Mm-Hmm. Um, and, uh, you know, I, uh, made the switch to music from a profession to music as, as, as a hobby, and it was the right decision for me. Absolutely.
You know, it's funny, one of our good friends who was at Sonotype a long time, Mark Miller, I don't know if you're familiar with Mark, but Mark's two children are both, uh, symphony Orchestra Oh, cool. Musicians. One just graduated Rice and I think he's starting with the San Francisco.
Wow, that's great. That's Great. Good.
Forny Orchestra and his daughter sort of still in school, but she's, I, where is she playing this summer? Also very talented. Very, very, both kids.
Very talented in, uh, classical music. That's great. That's Great.
It's good stuff. So how long have you been SVP of Product over? Its Sonotype?
About a year and a half now. I was part of kind of a new technology product leadership team that, that was brought in toward the end of 2022. So a little over I think I remember when all that.
Yeah. Yeah, I remember when all that went down. Very cool.
Um, you know, I'm acting, as I mentioned, snow Type is a company we've been covering and I've been familiar with forever and ever, but there might be some people out here not familiar with Sonatype Tyler, if you wouldn't mind give them, you know, a quick elevator pitch. Yeah. At Sonatype, we are, our, our goal really is to help the world innovate with fearlessness and speed.
And we do that by making open source software, uh, easy, fun, attractive, and safe to use for organizations like most software, most of most software that's written over 90% of the actual lines of code in most software is actually open source components that are brought in. And those dependencies and managing those dependencies can be frustrating. Yeah.
Frustrating and painful and, and, and just not fun. And so what we try to do in our mission is to have them go have a go from frus, frustrating to fascinating, to awful, to accelerating, you know, really from, uh, binary artifact repository to software composition analysis to dependency management. We pride ourselves in knowing more and having the deepest data set about how the world uses open source and applying that through our software and solutions to help teams and organizations ship faster, more secure software.
Absolutely. I I think a lot of our audience probably interacts with Sonatype. It may not even be aware.
Yeah. You know, the, uh, Sonatype manages one of the largest repos right? On the internet.
We Do, we are the That's correct. We are the stewards of Maven Central. So if you have ever used Maven or, uh, worked in Java or ever worked in Java, then you have touched, uh, Sonatype, whether you know it or not.
And we're really proud of that. And, um, it's something we believe in for, you know, the good of the world, for the good of how we all can build, uh, software faster. Absolutely.
And I just also want to add, 'cause a large part of our audience is, you know, a security focused, uh, segment. Sonatype has really always been one of the leaders in securing open source software. Uh, I know most recently you guys are working a ton on sbo Correct Type of, uh, stuff.
We, There's, when what, when you're evaluating an open source com component, right? If, if you're a, if you're a, a developer, an injury leader and architect, and you're deciding what open source component am I'm going to use, there's lots of things to, to consider, right? Uh, is it being actively managed?
What are are the license implications? How popular is it? But what typically rises to the top right away is security and evaluating the security of a component, both today and, and how that changes over time.
And so we're very proud of, and a big part of our, uh, business is providing that open source security, uh, both in terms of thought leadership as well as within individual, uh, applications. And one of the newest trends in that is the software bill of material. So our new SBO manager product, uh, is, uh, help design to help people manage.
We do an SBOs and SBOs. Were, were, were cool, right? We're just recently hearing people say that, say talk about SBOs and how, how they're important.
But yeah. Um, securing the software supply chain is, uh, is one of our big pillars of belief in what we wake up every day and, um, try to help the world do Fantastic. com is, that's right.
Is the website stuff A lot of stuff out there. Tyler, if you don't mind, I want to kind of pivot a little bit Sure. And change gears too.
The topic of today's discussion, which is guys resilient, uh, announced an integration partnership with ServiceNow. IT needs, um, again, ServiceNow is a company that really doesn't need any introduction to our audience. They're a monster, right?
I mean, they're very, one of the most successful companies in tech out there today. They just done a great job of expanding and, and continually to expand and perfect their, their offering. Why don't you, if you don't mind, give us a little insight.
What's this integration? You know, there's a lot of moving parts there at ServiceNow. Where, where, where's this integration?
We find that organizations, uh, especially those that are using ServiceNow, are really trying to drive repeatable, reliable automation into how they manage their assets, uh, how they manage their software, how they manage their IT routing and ticketing and all those kind of back office functions and moving more into, uh, uh, the innovation functions. And so what our, uh, customers were asking us was really for two things. One, uh, we talked about securing the software supply chain.
When our exact identification identifies an open source component, runs that against our world class data set, it then takes it against a policy engine. So organizations can say, is this, uh, is this component violating a policy, a security policy, a a legal policy, a usage policy? And when there's a policy violation, organizations wanna fix them.
And one of the ways that they wanna fix them is to integrate that into a ServiceNow workflow, to a ServiceNow set of, of steps. So one of the grace, one of the integration points is taking those, uh, policy violation findings and automating the resolution of those through ServiceNow workflows and, and processes. So on the resolution side, there's a set of, of integrations also, uh, organizations use as, uh, many of you know, ServiceNow to kind of be that single pane of glass view for their application posture.
So what, what is, what containers are running, what servers are running, what applications are running on those? And what makes up all of those containers and applications and microservices are open source components. So what they want is that view of, of risk, that view of compliance in that single pane of glass view within ServiceNow.
And so the other part of, of the integration is tying our policy violation, uh, data sets and the findings of what we know about, uh, open source components independencies and integrating that into that view within ServiceNow. So it's, it's taking what we do and, uh, linking it in. So you get that single pane of glass and they able to automate remediation workflows, uh, for organizations that have kind of standardized and made the backbone of their IT and tech operations a ServiceNow, uh, platform.
So is, is this integration API driven, basically, or is it, We actually have Way beyond that, but Yeah, it's, it's gonna be beyond that. We actually have a, um, a plugin in there App Store. So if you go to ServiceNow, you can look search for different kind of add-ins and, and plugins and apps.
And so there's now a Sona type one in, in, in the store. So it's not just an API integration. It's been, uh, reviewed and certified by the ServiceNow now team for inclusion in there marketplace.
Um, so it goes a much higher standard of just APIs. It's actually kind, uh, they come about an app on their app store that's been certified, blessed and vetted by their, by their team. And then who's responsible for the upkeep of the app at Sonatype, I would imagine.
Yeah. Sonotype is, yeah. Correct.
Yep. So this, it's, it's, you know, we've value the trust our customers put in us both to helping them secure the software supply chain and develop faster. And with that trust comes the expectation of high quality maintained software.
And this, uh, plugin in is, uh, no exception, it's just delivered via the ServiceNow marketplace where organizations can get it. Um, any, any current, uh, lifecycle customer of ours, the Southern type lifecycle product, uh, that's also a ServiceNow customer can get it, wire it up and start to get that data and information and automation flowing. Love it.
Just still, uh, may I consider a, some may consider it a silly question. I don't What percentage of your sonotype customer base are ServiceNow customers do know It's a plurality? Probably not a majority because we have, uh, as you know, we have some of the largest customers in, in, in the world.
And then we also have, uh, as you know, our, uh, especially our, our Nexus repo offering goes down to, you know, five, uh, men and women startups. So, but if, if you were to segment the largest customers in, in the world, there's also very much often oftentimes happen to be ServiceNow's customers. So yeah, it's very large.
Uh, percentage. Yeah, That's fantastic. Where people wanna get more information, where do they go?
Tyler? com is the best, is the best place to go to, to learn more. You have the ServiceNow integration page there, and if you're, uh, you can also go to the ServiceNow, uh, uh, marketplace, marketplace search, search for sonotype, and we'll hop up to the top.
Hey man, it sounds great. ServiceNow's a great company. Yeah.
Sonatype and ServiceNow I think are better together. Agreed. So that it's a great partnership here.
Looking forward to keeping in touch with you going forward and, and hearing more about all. I know you guys have some good stuff coming down the pike. We're excited to hear about it And we're excited to share it with you, Alan.
Thank you. All right. Tyler Warden s SVP of product at Sonatype here on Tech Trunk tv.
Thanks, Tyler. Keep it up and we'll be in touch. Thank you.
We're gonna take a break. Thank you. We're gonna take a break here on Tech Trunk tv.
We'll be back in just a moment.