Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Securing Dependencies: Version Pinning & Cooldowns

Fortra
08/11/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


writing code, it would take forever to get to product. So we have dependencies, we have libraries for all these different reasons that are to make our lives easier. But now we have to draw a line between making our life easier and keeping our users of our product secure. And I think that's the the interesting thing to me where we get into those two things that I talked about at the top of the show that make a really big difference. And to me, those are version pinning and dependency cooldowns. And I think those two things are king when it comes to how are you going to deal with and protect against this.

TL;DR

  • Modern development relies heavily on third-party libraries and dependencies to accelerate product delivery, but this convenience introduces significant security risks that must be actively managed.
  • Version pinning locks dependencies to specific versions, preventing automatic updates that could introduce vulnerabilities or breaking changes into production environments.
  • Dependency cooldowns involve waiting periods before adopting new dependency versions, allowing time for the security community to identify and disclose potential vulnerabilities before they reach your codebase.

Summary

This brief segment addresses the security challenges inherent in modern software development's reliance on third-party dependencies and libraries. While these components accelerate development by eliminating the need to build everything from scratch, they introduce security risks that must be actively managed. The speaker emphasizes the critical balance between developer productivity and user security, advocating for two specific practices: version pinning (locking dependencies to specific versions rather than accepting automatic updates) and dependency cooldowns (waiting periods before adopting new dependency versions to allow vulnerabilities to surface). These strategies represent a pragmatic approach to supply chain security, acknowledging that convenience cannot come at the expense of protecting end users from potential vulnerabilities introduced through the software supply chain.

Chapters

0:00 - The Dependency Dilemma
0:14 - Balancing Productivity and Security
0:30 - Version Pinning and Cooldowns

Key Quotes

0:14 "But now we have to draw a line between making our life easier and keeping our users of our product secure."
0:30 "And to me, those are version pinning and dependency cooldowns."

FAQ

What is version pinning and why does it matter for security?

Version pinning is the practice of locking your project's dependencies to specific versions rather than allowing automatic updates to the latest versions. This matters for security because it gives you control over when and how dependencies change, preventing malicious or vulnerable code from automatically entering your application through dependency updates. It allows you to evaluate new versions before adoption rather than accepting them blindly.

Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • DevSecOps
  • Best Practices
  • Technical Deep Dive
  • Software Supply Chain Security
  • Dependency Management
  • Version Pinning
  • Dependency Cooldowns
  • Secure Development Practices
  • Third-Party Libraries
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Securing Dependencies: Version Pinning & Cooldowns

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  The Automation Escalation: Discovering the AI-Driven Underground Revolution

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Invisible Data: Understanding What You Can't Safeguard

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      The Automation Escalation: Discovering the AI-Driven Underground Revolution
                      https://www.truthinit.com/index.php/channel/2108/the-automation-escalation-discovering-the-ai-driven-underground-revolution/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: Understanding What You Can't Safeguard
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-you-cant-safeguard/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhancing Visibility and Control in Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhancing-visibility-and-control-in-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version