Modern Vulnerability Management | Sonatype Fireside Chat

Modern Vulnerability Management

Watch Now

As applications continue to rely on large and complex open source dependency chains, security teams face growing challenges in identifying, prioritizing, and addressing risks effectively. Explore why traditional approaches to vulnerability management are struggling to keep pace with the realities of modern software development. In this fireside chat, industry experts examine the underlying issues and discuss practical strategies for managing vulnerabilities in today’s fast-moving software ecosystems.

Modern Vulnerability Management

Modern Vulnerability Management

Dave Welch, Chief Software Architect • HeroDevs AND Brian Fox, CTO • Sonatype AND Christopher Robinson, Chief Security Architect • OpenSSF

Watch now

Feb 23 2026 | 49 mins

Modern vulnerability management is breaking down, not because teams aren't scanning, but because the system itself no longer supports reliable remediation.

End-of-life (EOL) dependencies are becoming a structural flaw in modern enterprise stacks. Once a release line is out of maintenance, upstream fixes stop, turning ordinary CVEs into permanent exposure. With 5–15% of components in enterprise dependency graphs already EOL, organizations face a growing blind spot where advisory coverage degrades and risks are undercounted.

In this session featuring experts from Sonatype, HeroDevs, and OpenSSF, we unpack the 2025 data behind avoidable vulnerability consumption, failing vulnerability intelligence, and the structural risks of abandoned software.

Join us to explore real-world telemetry on:

This is a practical conversation for leaders navigating vulnerability risk that can’t simply be patched away.

Featured Speakers

Dave Welch

Chief Software Architect, Herodevs

Brian Fox

CTO, Sonatype

Christopher Robinson

Chief Security Architect, OpenSSF