Sisyphus and the CVE Feed: Vulnerability Management at Scale

2 · Airbnb · Aug. 10, 2022, 5:31 p.m.
AuthorsKeziah Perez Sonder Plattner, Senior Software EngineerKadia Mashal, Engineering ManagerIntroductionEvery engineer knows that security is a never-ending problem. Until we delete all our code and move into a cottage in the woods, we have to accept that there is no such thing as 100% secure software. You could be doing everything perfectly, and a publicly known vulnerability (CVE) could emerge for the most updated version of a third party library in your infrastructure. Things are secure unt...