SCA Is Dead
SCA is dead. SCA does not provide proactive discovery and analysis....
SCA is dead. SCA does not provide proactive discovery and analysis....
What happens to an author after a malicious package is discovered and...
In this blog post, I explore a controversy that surrounds a prominent...
With the explosion of new software over the past decade,...
By using open source software, you expose yourself to the influence...
While SolarWinds made headlines within the last few months for the...
Despite attracting major media attention in the wake of the recent...
Dependency confusion allows bad actors to emulate internal software...
Repo jacking is an insidious software supply chain issue. Attackers...
What does the upstream for major packages really look like? Over the...