In this AppSec Decoded interview, we look at the top takeaways from the ‘DevSecOps Practices and Open Source Management in 2020’ report.
Stay on top of open source vulnerabilities and license obligations with discovery capabilities from Black Duck.
The Common Vulnerability Scoring System (CVSS) can help you navigate the constantly growing ocean of open source vulnerabilities. But it’s difficult to lend your trust and put the security of your organization and your customers into the hands of a system that you may know very little about. Let’s take a closer look at the CVSS to see what it’s all about.
Understand the three common scenarios for why unlicensed open source is found in the codebase and the implications of it being embedded in commercial apps.
Open source projects can become victims of their own success. What can developers do to secure their open source software?
Learn what OpenChain is, how it works, and how companies around the world are using it to secure their software supply chains and reduce open source risk.
Hear about the state of open source in our Red Hat partner webinar, discover our approach to threat modeling, and learn how to secure Node.js applications.
In this week’s webinars, we’ll talk about binary scanning techniques and challenges, and how to reduce your risk with software supply chain management.
Identifying open source in the target’s codebase is essential to M&A transactions involving software. Open source audits go far beyond what SCA can provide.
An open source audit digs into a codebase to see what’s inside. Find out what our audit services team unearthed in the 1,250+ codebases we reviewed in 2019.