Talk
It's Just JSON, Right?
Whenever you run a security scan on your dependencies, you trust that the underlying vulnerability database is structured, clean, and machine-readable. After all, it's the modern era - it’s all standardised JSON, right? In this interactive "live"-coding session, we will peel back the layers of our global vulnerability databases to see what actually powers your dependency alerts. We’ll explore why decentralised open-source data is surprisingly difficult to standardise, how projects like OSV.dev solve this heavy lifting for the developer ecosystem, and what we can do to build cleaner, more resilient data pipelines across the software supply chain.




