Everything there is to find on tag: supply chain security.
Top story
Vulnerabilities go unnoticed by users of open-source software far too often
Every year, Sonatype takes a good look at the software supply chain. In this year's State of the Software Sup...
Tidelift shields organizations from the risks of open source
Tidelift has added new capabilities to its Tidelift Subscription. The newly expanded package allows organizat...
CNCF’s Notary and Notation get first full release
The Cloud Native Computing Foundation's (CNCF) Notary Project and Notation Project standardization projects f...
EU will expand its cooperation with Japan on chip supply
The European Union is seeking to reduce its reliance on China for semiconductors. It hopes to find a suitable...
OpenSSF strengthens supply chain security with SLSA 1.0
SLSA 1.0 is intended to provide a standard language for software supply chain security. The project is at an ...
Nearly all companies have misconfigurations in cloud environments
Nearly all organizations (98.6 percent) are experiencing worrisome misconfigurations that pose significant ri...
Sigstore launches free software signing service
The open-source technology allows users to verify the reliability of software components. Sigstore is used by...
‘SSO credentials of the world’s largest organizations are for sale’
The login credentials of 25 percent of the 500 largest US organizations are for sale on the dark web, accordi...
SentinelOne detects Rust-based supply chain attack
SentinelOne recently discovered a supply chain attack that uses components of the Rust programming language. ...
GitHub imposes 2FA on all contributors
GitHub wants to arm itself against supply chain attacks. Two-factor authentication (2FA) will be mandatory fo...