Software Supply Chain Security

March 20, 2023

Software supply chain security practices are maturing — but it's a work in progress

Experts weigh in on a new OpenSSF SLSA framework survey — and the overall state of supply chain security practices.
March 15, 2023

GitHub enforces 2FA — it’s about time (given the state of supply chain security)

GitHub is a weak link in the software supply chain. Finally, Microsoft is doing something about it — by forcing users into two-factor authentication (2FA).
March 14, 2023

Secrets Exposed: How hackers are gaining access to software secrets

Here’s how attackers are finding software development secrets buried in code repositories — and exploiting them. 
March 14, 2023

Introducing New Secrets Management Capabilities For Mitigating Software Supply Chain Risk

Development secrets are critical for complex software to work, but hard to manage. That's why we're unveiling features to spot secrets leaks and exposures.
March 13, 2023

Software supply chain security and financial services: Mind the gaps in app sec testing

Here's what you need to know about the limits of app sec testing, and why comprehensive software supply chain security is critical to mitigating risk.
March 13, 2023

Plugging secrets leaks requires holistic software and technology stack protection

CircleCI and other recent hacks show how vulnerable secrets are on the software supply chain. Here's why an end-to-end security approach is essential.
March 9, 2023

PyPI repo poisoned with "Colour-Blind" RAT

Here are the key takeaways from the Colour-Blind remote access trojan, with insights from supply chain security experts.
March 8, 2023

Why software transparency is critical: Understanding supply chain security in a software-driven society

Chris Hughes shares an overview of his co-authored upcoming book, “Software Transparency: Supply Chain Security in an Era of a Software-Driven Society.”