Modern Vulnerability Management | Sonatype Fireside Chat
Modern Vulnerability Management
As applications continue to rely on large and complex open source dependency chains, security teams face growing challenges in identifying, prioritizing, and addressing risks effectively. Explore why traditional approaches to vulnerability management are struggling to keep pace with the realities of modern software development. In this fireside chat, industry experts examine the underlying issues and discuss practical strategies for managing vulnerabilities in today’s fast-moving software ecosystems.
Modern Vulnerability Management
Modern Vulnerability Management
Dave Welch, Chief Software Architect • HeroDevs AND Brian Fox, CTO • Sonatype AND Christopher Robinson, Chief Security Architect • OpenSSF
Watch now
Feb 23 2026 | 49 mins
Modern vulnerability management is breaking down, not because teams aren't scanning, but because the system itself no longer supports reliable remediation.
End-of-life (EOL) dependencies are becoming a structural flaw in modern enterprise stacks. Once a release line is out of maintenance, upstream fixes stop, turning ordinary CVEs into permanent exposure. With 5–15% of components in enterprise dependency graphs already EOL, organizations face a growing blind spot where advisory coverage degrades and risks are undercounted.
In this session featuring experts from Sonatype, HeroDevs, and OpenSSF, we unpack the 2025 data behind avoidable vulnerability consumption, failing vulnerability intelligence, and the structural risks of abandoned software.
Join us to explore real-world telemetry on:
- The Persistence of Fixable Risks: Why most vulnerable components being downloaded today already have safer versions available.
- The "Forever Risk" of EOL: How end-of-life dependencies transform manageable vulnerabilities into permanent security debts.
- The AI Multiplier: Why AI-assisted development often amplifies the consumption of outdated and vulnerable components.
- Beyond "Scan and Patch": Practical strategies for when traditional remediation paths are closed.
This is a practical conversation for leaders navigating vulnerability risk that can’t simply be patched away.
Featured Speakers
Dave Welch
Chief Software Architect, Herodevs
Brian Fox
CTO, Sonatype
Christopher Robinson
Chief Security Architect, OpenSSF