Events2Join

Securing the open source supply chain


Securing the Software Supply Chain: Recommended Practices for ...

This issue spans both commercial and open-source software and impacts private and government enterprises. Accordingly, there is an increased ...

Securing the open source supply chain: The essential role of CVEs

Tackling data overload with automation · Providing transparency about the dependencies used by your repository. · Allowing vulnerabilities to be ...

Open Source Supply Chain Security | FINOS

In this article we are going to look at the growing issue of software supply chain attacks via some examples and then look at the emerging field of open source ...

Understanding the software supply chain is key to improving security

For decades, the public and private sectors have steadily increased their use of open source software (OSS), representing a significant evolution in ...

Beyond Vulnerabilities, Towards a Holistic Approach to Securing the ...

Hidden risks in open source libraries · Best practices to reduce open source risks · Automate risk reduction in your software supply chain with ...

The big, gaping hole in software supply chain security - CIO

Securing the software supply chain would be easy — if not for the fact that tools to manage this risk often focus exclusively on open source ...

Open Source Software Supply Chain Security - Linux Foundation

Open Source Software Supply Chain Security. Download Report. As cybersecurity incidents have continued to grow in magnitude, frequency, and consequences, both ...

Securing the Supply Chain | Managing the Risk of Open Source ...

This post provides guidelines on how organizations choosing to use these tools can do so both effectively and safely.

The Complete Guide to Software Supply Chain Security - FOSSA

The links in the software supply chain extend from development to deployment and include open source dependencies, build tools, package managers, testing tools, ...

Study highlights secure software supply chain best practices

Security trends report from open source firm shows the approaches IT leaders take to secure their software supply chain.

Top 12 Open Source Software Security Best Practices

Top Open Source Supply Chain Security Risks & Tips to Prevent · 1. Vet Sources for Lookalikes · 2. Establish Rules for Developers Using Open- ...

NSA and ESF Partners Release Recommended Practices for ...

However, organizations that do not follow a consistent and secure-by-design management practice for the open source software they utilize are ...

Safeguarding Your Software Supply Chain: Strategies For Securing ...

Yet, from a software supply chain risk management perspective, open source packages pose a major challenge: If they contain malicious code or vulnerabilities, ...

Overcoming Open Source Vulnerabilities in the Software Supply Chain

Ultimately, a secure software supply chain requires numerous safety measures to prevent threat groups from infiltrating the supply chain and ...

The Dark Side of Open Source: Securing the Software Supply Chain

In this post, we'll delve into the dark side of open-source, exploring the hidden vulnerabilities, supply chain attacks, and the challenges of ensuring the ...

Protecting against software supply chain attacks - InfoWorld

Open source software is ubiquitous, and supply chain attacks are on the rise. Companies should consider these three strategies to secure their software.

Software supply chain security | Google Cloud

Assured Open Source Software provides open source packages that Google has verified and tested. These packages are built using Google's secure ...

Open Source Supply, Demand, and Security - Sonatype

A troubling trend has emerged in the software supply chain over the past few years of tailor-made packages designed to run a malicious payload on download — ...

US addresses securing software supply chain for managing open ...

The memo focuses on strengthening the security of the software supply chain, including open-source software (OSS) and software bills of ...

Open Source Supply Chain Security at Google - research!rsc

My talk was titled “Open Source Supply Chain Security at Google” and was 45 minutes long. I spent a while at the start defining open source ...