Open Source
Open Source | News, how-tos, features, reviews, and videos
At least one open source vulnerability found in 84% of code bases: Report
Almost all applications contain at least some open source code, and 48% of all code bases examined by Synopsys researchers contained high-risk vulnerabilities.
Privacera connects to Dremio’s data lakehouse to aid data governance
The integration of open-source based Privacera into Dremio’s data lakehouse is designed to allow joint customer enterprises to manage and organize secure data access.
GitHub releases new SDLC security features including private vulnerability reporting
GitHub also announces CodeQL support for Ruby programming language and coverage/risk overviews to help users secure the software development lifecycle.
Rezilion expands SBOM to support Windows environments
Organizations can now apply Rezilion’s SBOM to Windows environments to manage software vulnerabilities and meet regulatory standards.
The OSPO – the front line for secure open-source software supply chain governance
An open-source program office (OSPO) can act as both gatekeeper and evangelist in an organization’s struggle to ensure ubiquitous open-source components – incredibly useful but vulnerable to bad actors and misuse – are deployed safely...
Supply chain attacks increased over 600% this year and companies are falling behind
Most companies believe they are using no open-source software libraries with known vulnerabilities, but new research finds them in 68% of selected enterprise applications.
U.S. government issues guidance for developers to secure the software supply chain: Key takeaways
The U.S. NSA, CISA and ODNI created the Securing the Software Supply Chain guide to focus on the software development lifecycle.
8 notable open-source security initiatives of 2022
Vendors, collectives and governments are contributing to improve the security of open-source code, software, and development amid organizations’ increasing use of open-source resources.
The Heartbleed bug: How a flaw in OpenSSL caused a security crisis
Heartbleed is a vulnerability in OpenSSL that came to light in April of 2014; it can be traced to a single line of code.
OpenSSF releases npm best practices to help developers tackle open-source dependency risks
The npm Best Practices Guide aims to help JavaScript and TypeScript developers reduce the security risks of using open-source dependencies.
Vulnerability eXploitability Exchange explained: How VEX makes SBOMs actionable
VEX adds context to software vulnerabilities to better inform risk assessment decisions.
SBOM formats SPDX and CycloneDX compared
Understanding the differences between these widely used software bill of materials format standards is important, but your tools will likely need to support both.
How OpenSSF Scorecards can help to evaluate open-source software risks
Scorecards automatically generates a score for open-source projects based on potential vulnerabilities and dependencies.
GitGuardian launches ggcanary project to help detect open-source software risks
GitGuardian says its new open-source canary tokens project helps businesses detect breaches as they unfold.
8 top SBOM tools to consider
These commercial and open-source tools will scan code and create software bills of materials automatically.
What is an SBOM? Software bill of materials explained
An SBOM is a detailed guide to what's inside your software. It helps vendors and buyers alike keep track of software components for better software supply chain security.
Auth0’s OpenFGA explained: Open source universal authorization
Authorization is an essential and non-trivial need in application development. Modern requirements have only increased the complexity of delivering adequate authorization. Auth0 aims to make authorization more standard and...
Open-source software risks persist, according to new reports
Companies are still struggling to gain confidence in the security of their open-source projects, but shifting security earlier in the development process shows promise.