Learn

Learn about software supply chain security and Endor Labs.

Featured resources

Blog
Aug 7, 2024

Introducing Upgrades & Remediation: Give Developers the Confidence to Fix

Blog
Jul 29, 2024

33 Most Popular Open Source Tools for Maven Applications, Scored

Questions to Ask Your Software Composition Analysis Vendor
Blog
Jun 27, 2024

Questions to Ask Your Software Composition Analysis Vendor

Container Scanning + SCA = Better Together
Blog
Jun 11, 2024

Container Scanning + SCA = Better Together

Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
SCA
Developer Productivity
Blog
Aug 21, 2024

Give Devs the Confidence to Fix: Making Remediation Less Painful

Security
SCA
Blog
Aug 21, 2024

Endor Labs partners with Microsoft to strengthen software supply chains

No items found.
Blog
Aug 19, 2024

Prioritize Open Source Risks with Endor Labs

SCA
Security
Blog
Aug 14, 2024

Discover Open Source Risks with Endor Labs

Open Source
SCA
Blog
Aug 9, 2024

48 most popular open source tools for npm applications, scored

SCA
Security
Tech
Developer Productivity
Compare Endor Labs and Snyk GitHub Apps.
Blog
Aug 8, 2024

Benchmarking Endor Labs vs. Snyk’s GitHub Apps

CI/CD
Security
Compliance & SBOM
Blog
Aug 8, 2024

Using Artifact Signing to Establish Provenance for SLSA

Developer Productivity
SCA
Video
Aug 7, 2024

How to Fix Vulnerabilities Without Breaking Changes

SCA
Security
News
Developer Productivity
Blog
Aug 7, 2024

Introducing Upgrades & Remediation: Give Developers the Confidence to Fix

Open Source
Blog
Jul 29, 2024

33 Most Popular Open Source Tools for Maven Applications, Scored

SCA
Security
Customer Story
Jul 24, 2024

Jellyfish Enables Data-Driven AppSec with Endor Labs

Security
SCA
Blog
Jul 24, 2024

Jellyfish’s Data-Driven Security Program

News
Blog
Jul 15, 2024

Endor Labs Receives Strategic Investment from Citi Ventures

News
We made the Inc. Best Workplaces List for 2024!
Blog
Jul 8, 2024

We made the Inc. Best Workplaces List for 2024!

Security
Open Source
Blog
Jul 3, 2024

New CocoaPods CVEs: Swift and Objective-C Supply Chains Are Fragile

SCA
Security
Questions to Ask Your Software Composition Analysis Vendor
Blog
Jun 27, 2024

Questions to Ask Your Software Composition Analysis Vendor

Security
Developer Productivity
SCA
Backstage and Endor Labs: AppSec in a Dev’s Dream Workspace
Blog
Jun 18, 2024

Backstage and Endor Labs: AppSec in a Dev’s Dream Workspace

Security
What's a Security Pipeline? - On-Demand Webinar
Video
Jul 17, 2024

What's a Security Pipeline? - On-Demand Webinar

News
Blog
Jun 4, 2024

Endor Labs Named to Rising in Cyber by CISOs and Venture Capital Investors

SCA
Open Source
Security
Blog
Jun 4, 2024

Evaluating and Scoring OSS Packages

SCA
Compliance & SBOM
Open Source
Security
Demystifying Transitive Dependency Vulnerabilities
Blog
May 31, 2024

Demystifying Transitive Dependency Vulnerabilities

SCA
Open Source
Security
Compliance & SBOM
Container Scanning + SCA = Better Together
Blog
Jun 11, 2024

Container Scanning + SCA = Better Together

CI/CD
Security
Open Source
Surprise! Your GitHub Actions Are Dependencies Too
Blog
May 28, 2024

Surprise! Your GitHub Actions Are Dependencies, Too

Compliance & SBOM
SCA
Security
OSS Vulnerabilities and the Digital Operational Resilience Act (DORA)
Blog
May 21, 2024

OSS Vulnerabilities and the Digital Operational Resilience Act (DORA)

SCA
Security
Protect Mobile Apps with Kotlin and Swift SCA
Blog
May 21, 2024

Protect Mobile Apps with Kotlin and Swift SCA

Compliance & SBOM
SCA
Managing Open Source Vulnerabilities for PCI DSS Compliance- On-Demand Webinar
Video
Jun 18, 2024

Managing Open Source Vulnerabilities for PCI DSS Compliance - On-Demand Webinar

SCA
Open Source
Security
 OWASP OSS Risk 1: Known Vulnerabilities, by Camila Odlund and Jenn Gile
Blog
May 14, 2024

OWASP OSS Risk 1: Known Vulnerabilities

Compliance & SBOM
Open Source
SCA
An Auditor’s Perspective on Addressing OSS Vulnerabilities for PCI DSS v4 by Jenn Gile
Blog
May 2, 2024

An Auditor’s Perspective on Addressing OSS Vulnerabilities for PCI DSS v4

CI/CD
Security
Low-Code/No Code Artifact Signing by Diamantis Kourkouzelis
Blog
May 7, 2024

Low-Code/No Code Artifact Signing

CI/CD
Compliance & SBOM
Security
Your Git Repo is a Supply Chain Risk by Darren Meyer
Blog
Apr 30, 2024

Your Git Repo is a Supply Chain Risk

Security
SCA
CI/CD
Compliance & SBOM
Open Source
Guide to Implementing Software Supply Chain Security, What to Consider When Designing a Program
Ebook/Report
Apr 30, 2024

Guide to Implementing Software Supply Chain Security

CI/CD
Security
Improve Kubernetes Security with Signed Artifacts and Admission Controllers by David Archer
Blog
Apr 23, 2024

Improve Kubernetes Security with Signed Artifacts and Admission Controllers

CI/CD
Compliance & SBOM
SCA
Intro to Endor Labs- On-Demand Webinar
Video
May 15, 2024

Intro to Endor Labs - On-Demand Webinar

Developer Productivity
Open Source
Opinion
Security
Tech
AppSec Goes to Devnexus: Lessons from a Thriving, Modern Java Community by Darren Meyer
Blog
Apr 16, 2024

AppSec Goes to Devnexus: Lessons from a Thriving, Modern Java Community

Security
Open Source
Compliance & SBOM
SCA
XZ Backdoor: How to Prepare for the Next One by Jamie Scott
Blog
Apr 3, 2024

XZ Backdoor: How to Prepare for the Next One

News
Blog
May 21, 2024

Endor Labs Partners with GuidePoint Security to Secure The Software Supply Chain

Security
Open Source
Opinion
XZ is A Wake Up Call For Software Security: Here's Why by Dimitri Stiliadis
Blog
Apr 1, 2024

XZ is A Wake Up Call For Software Security: Here's Why

Compliance & SBOM
SSDF Compliance and Attestation by Chris Hughes
Blog
Mar 26, 2024

SSDF Compliance and Attestation

CI/CD
Security
You Have a Shadow Pipeline Problem by Darren Meyer
Blog
Mar 19, 2024

You Have a Shadow Pipeline Problem

CI/CD
Security
Compliance & SBOM
Artifact Signing 101 - On-Demand Webinar
Video
Apr 10, 2024

Artifact Signing 101 - On-Demand Webinar

SCA
Security
Prioritizing SCA Findings with Reachability Analysis - On-Demand Webinar
Video
Mar 6, 2024

Prioritizing SCA Findings with Reachability Analysis - On-Demand Webinar

CI/CD
Compliance & SBOM
Security
Signing Your Artifacts For Security, Quality, and Compliance
Blog
Mar 5, 2024

Signing Your Artifacts For Security, Quality, and Compliance

SCA
Open Source
Security
Remediating Vulnerabilities vs. Maintaining Current Dependencies
Blog
Mar 13, 2024

Remediating Vulnerabilities vs. Maintaining Current Dependencies

Open Source
SCA
Security
Detecting Malicious Packages in Open Source Dependencies by Henrik Plate
Blog
Feb 28, 2024

Detect Malicious Packages Among Your Open Source Dependencies

Security
Open Source
SCA
Compliance & SBOM
How to Ingest and Manage SBOMs
Video
Jan 30, 2024

How to Ingest and Manage SBOMs - Tutorial

Security
Open Source
SCA
How to Improve SCA in GitHub Advanced Security
Video
Feb 5, 2024

How to Improve SCA in GitHub Advanced Security - Tutorial

Security
Open Source
SCA
Compliance & SBOM
How to Generate SBOM and VEX
Video
Jan 23, 2024

How to Generate SBOM and VEX - Tutorial

Security
AI/ML
Open Source
How to Use AI for Open Source Selection
Video
Jan 9, 2024

How to Use AI for Open Source Selection - Tutorial

Secret Detection
Security
How to Scan and Prioritize Valid Secrets
Video
Dec 6, 2023

How to Scan and Prioritize Valid Secrets - Tutorial

News
Tom Gleason Joins Endor Labs as VP of Customer Solutions
Blog
Feb 20, 2024

Tom Gleason Joins Endor Labs as VP of Customer Solutions

CI/CD
Compliance & SBOM
Security
Introducing CI/CD Security with Endor Labs
Blog
Feb 14, 2024

Introducing CI/CD Security with Endor Labs

SCA
Open Source
Highlights from State of Dependency Management 2022
Video
Jun 23, 2023

Highlights from State of Dependency Management 2022 - Webinar

SCA
Open Source
Reachability Analysis for Python, Go, C#
Video
Sep 5, 2023

Reachability Analysis for Python, Go, C# - Webinar

SCA
Open Source
How Security and Engineering Can Scale Open Source Security
Video
Jun 23, 2023

How Security and Engineering Can Scale Open Source Security - Webinar

SCA
Open Source
Introduction to Open Source Security
Video
Feb 3, 2023

Introduction to Open Source Security - Webinar

SCA
Open Source
Comparing SBOMs Generated at Different Lifecycle Stages
Video
Feb 3, 2023

Comparing SBOMs Generated at Different Lifecycle Stages - Webinar

SCA
Open Source
Why We Need Static Analysis When Prioritizing Vulnerabilities
Video
Dec 6, 2022

Why We Need Static Analysis When Prioritizing Vulnerabilities - Webinar

SCA
Security
Open Source
State of Dependency Management 2022
Ebook/Report
Dec 8, 2022

State of Dependency Management 2022

SCA
Security
Open Source
OWASP Top 10 Risks for Open Source
Ebook/Report
Mar 1, 2023

OWASP Top 10 Risks for Open Source

SCA
Open Source
How to Prioritize Reachable Open Source Software (OSS) Vulnerabilities
Video
Nov 9, 2023

How to Prioritize Reachable Open Source Software (OSS) Vulnerabilities - Tutorial

Security
What you need to know about Apache Struts and CVE-2023-50164
Blog
Dec 18, 2023

What You Need to Know About Apache Struts and CVE-2023-50164

Security
SCA
You found vulnerabilities in your dependencies, now what?
Blog
Oct 6, 2023

You Found Vulnerabilities in Your Dependencies, Now What?

Security
SCA
Why SCA tools can't agree if something is a CVE
Blog
Oct 20, 2023

Why SCA Tools Can't Agree if Something is a CVE

News
Chris Hughes Joins Endor Labs as Chief Security Advisor
Blog
Sep 26, 2023

Chris Hughes Joins Endor Labs as Chief Security Advisor

Security
Tech
What’s in a Name? A Look at the Software Identification Ecosystem
Blog
Dec 20, 2023

What’s in a Name? A Look at the Software Identification Ecosystem

Security
SCA
Why Different SCA Tools Produce Different Results
Blog
Jun 29, 2023

Why Different SCA Tools Produce Different Results

SCA
Why Your SCA is Always Wrong
Blog
Sep 12, 2023

Why Your SCA is Always Wrong

Security
Open Source
Whatfuscator, malicious open source packages, and other beasts
Blog
Jan 9, 2023

Whatfuscator, Malicious Open Source Packages, and Other Beasts

Security
Tech
What security teams need to know about software development
Blog
Jul 14, 2022

What Security Teams Need to Know about Software Development

Developer Productivity
Security
What breaking changes teach us about security
Blog
Jan 31, 2023

What Breaking Changes Teach Us about Security

Security
Compliance & SBOM
What is VEX and why should I care?
Blog
Jan 18, 2023

What is VEX and Why Should I Care?

Security
What are Maven dependency scopes and their related security risks?
Blog
Nov 29, 2022

What are Maven Dependency Scopes and Their Related Security Risks?

SCA
Security
What is reachability-based dependency analysis?
Blog
Dec 21, 2022

What is Reachability-Based Dependency Analysis?

No items found.
VMware achieves SBOM compliance for over 100 services with Endor Labs
Customer Story
Jan 29, 2024

VMware Achieves SBOM Compliance for Over 100 Services with Endor Labs

Developer Productivity
SCA
Understanding Python Manifest Files: Part 1
Blog
Sep 20, 2023

Understanding Python Manifest Files

Opinion
Security
CSRB Log4j Report - The Response is as Dangerous as the Vulnerability
Blog
Jul 14, 2022

CSRB Log4j Report - The Response is as Dangerous as the Vulnerability

Security
SCA
Strengthening Security in .NET Development with packages.lock.json
Blog
Jun 28, 2023

Strengthening Security in .NET Development with packages.lock.json

News
SCA
Endor Labs raises $70M in series A funding to reform application security
Blog
Aug 3, 2023

Endor Labs Raises $70M in Series A Funding to Reform Application Security

Security
Compliance & SBOM
Open Source
The Government's Role in Maintaining Open-Source Security
Blog
Nov 21, 2022

The Government's Role in Maintaining Open Source Security

Security
SCA
Static SCA vs. Dynamic SCA: Which is Better and Why
Blog
Aug 1, 2024

Static SCA vs. Dynamic SCA: Which is Better (and Why It's Neither)

News
SCA
From cloud security to code security: why we've raised $25M to take on OSS dependency sprawl
Blog
Oct 11, 2022

From Cloud Security to Code Security: Why We've Raised $25M to Take on OSS Dependency Sprawl

Security
SCA
Open Source
Visualizing the Impact of Call Graphs on Open Source Security
Blog
Jun 30, 2023

Visualizing the Impact of Call Graphs on Open Source Security

Security
Compliance & SBOM
SBOM vs. SBOM: Comparing SBOMs from different tools and lifecycle stages
Blog
Feb 2, 2023

SBOM vs. SBOM: Comparing SBOMs from Different Tools and Lifecycle Stages

News
Open Source
Endor Labs Launches with $25M Seed Financing to Tackle Massive Sprawl of Open Source Software (OSS)
Blog
Oct 10, 2022

Endor Labs Launches with $25M Seed Financing to Tackle Massive Sprawl of Open Source Software (OSS)

Security
Compliance & SBOM
Key questions for your SBOM program
Blog
Aug 7, 2023

Key Questions for Your SBOM Program

Security
Compliance & SBOM
SBOMs are just a means to an end
Blog
Sep 13, 2022

SBOMs are Just a Means to an End

Security
SCA
Open Source
Reviewing Malware with LLMs: OpenAI vs. Vertex AI
Blog
Jun 5, 2023

Reviewing Malware with LLMs: OpenAI vs. Vertex AI

Security
Compliance & SBOM
SBOM Requirements for Medical Devices
Blog
Dec 5, 2023

SBOM Requirements for Medical Devices

Security
Developer Productivity
Opinion
Polyrepo vs. Monorepo - How does it impact dependency management?
Blog
Jul 12, 2022

Polyrepo vs. Monorepo - How Does it Impact Dependency Management?

Security
Open Source
Open Source Security 101: How to Evaluate Your Open Source Security Posture
Blog
Nov 16, 2023

Open Source Security 101: How to Evaluate Your Open Source Security Posture

News
Endor Labs Announces 100% Channel Commitment, Launches Global Hyperdrive Program to Arm Resellers and Solution Providers with Unprecedented Software Supply Chain Security
Blog
Mar 16, 2023

Announcing the Endor Labs Hyperdrive Program for Resellers and Solution Providers

Security
Open Source
The Open Source Security Index Top 5
Blog
Aug 29, 2023

The Open Source Security Index Top 5

Security
SCA
MileIQ securely reimagines a decade old product with Endor Labs
Customer Story
Dec 11, 2023

MileIQ Securely Reimagines a Decade Old Product with Endor Labs

Security
LLM-assisted Malware Review: AI and Humans Join Forces to Combat Malware
Blog
Apr 17, 2023

LLM-assisted Malware Review: AI and Humans Join Forces to Combat Malware

Compliance & SBOM
Open Source Licensing Simplified: A Comparative Overview of Popular Licenses
Blog
Jan 24, 2023

Open Source Licensing Simplified: A Comparative Overview of Popular Licenses

Security
Developer Productivity
SCA
Make Developers' Lives Easier with Endor Labs & GitHub Advanced Security
Blog
May 3, 2023

Make Developers' Lives Easier with Endor Labs & GitHub Advanced Security

no-results
Sorry, no results matching your search.

Want to stay in the loop?

Sign up for our newsletter.

Welcome to the resistance
Oops! Something went wrong while submitting the form.