Software Developer for 15+ years, my favorite topics are containerization (Docker and Kubernetes), building tools, Continuous Integration and, of course, core Java development.
Having recently joined HeroDevs, I work on patching and releasing EOL OSS Java and Spring projects.
I'm also a maintainer of the Paketo Java buildpacks.
In my spare time, I work on various open source projects : from Mastodon bots written in NodeJS or Go, to Android apps!
English session - Intermediate
This session demystifies the vulnerability lifecycle for Java devs: how flaws are found, scored (CVSS), and disclosed.
Learn the key databases (NVD, GitHub Advisory, OSS Index) and the tools that use them.
Get hands-on with discovery (SBOM), remediation (VEX files) and their associated tools. Also learn how handle framework End-of-Life.
Turn security from burden to advantage in your Java projects.