Let Vulnerabilities Close Themselves: Building a DevSecOps Closed-Loop with a Pure Open Source Toolchain
- Time
- 2026-08-08 10:00 ~ 10:40
- Speaker
- David Su
- Room
- TR313
- Co-write
Abstract
Scanners run but vulnerabilities pile up — who tracks them, fixes them, and confirms they're closed?
This talk presents an open source DevSecOps closed-loop across the full SSDLC: Threagile for threat modeling, OpenGrep for SAST, Trivy for SBOM generation, DefectDojo for aggregation and deduplication, and Dependency-Track for supply chain monitoring — all auto-ticketed to Jira/GitHub so engineers never need to log into a security platform.
We go beyond tool introductions to share each tool's real limitations, and solutions to three adoption barriers: developer resistance, SLA overload, and cross-team pushback. SBOM automation also turns CRA compliance into a B2B competitive advantage.
This is a real-world project implementation. All tools are OSI-licensed open source.
Speaker
David Su
David Su is a Security Engineer focused on DevSecOps architecture, SSDLC implementation, and security compliance — dedicated to embedding security into enterprise development workflows and organizational culture. He previously worked as a security consultant, building hands-on experience across penetration testing, GRC auditing, and cloud security. Since 2018, he has been an active member of the HITCON community, contributing to the Events team and driving technical exchange within the security community.