Software Integrity Blog

Archive for the 'Software Composition Analysis (SCA)' Category

 

World’s top hackers meet at the first 5G Cyber Security Hackathon

Our Defensics R&D team put a couple of Synopsys tools to the test in the 5G Cyber Security Hackathon in Oulu, Finland, and placed in both of their competitions.

Continue Reading...

Posted in Fuzz Testing, Software Composition Analysis (SCA), Software Security Research | Comments Off on World’s top hackers meet at the first 5G Cyber Security Hackathon

 

SAST vs. SCA: What’s the difference? Do I need both?

Learn how to combine static application security testing (SAST) and software composition analysis (SCA) to strengthen your software security program.

Continue Reading...

Posted in Application Security, Software Composition Analysis (SCA), Static Analysis (SAST) | Comments Off on SAST vs. SCA: What’s the difference? Do I need both?

 

What is a software bill of materials?

With a software bill of materials (software BOM), you can respond quickly to the security, license, and operational risks that come with open source use.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis (SCA) | Comments Off on What is a software bill of materials?

 

JDA Software: Extending their SDLC to remediate open source issues

Smart organizations in the business of building software need to use a mix of application testing tools to ensure their code is high-quality and secure.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis (SCA) | Comments Off on JDA Software: Extending their SDLC to remediate open source issues

 

Top open source licenses and legal risk for developers

Learn about the top open source licenses used by developers, including the 20 most popular open source licenses, and their legal risk categories.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis (SCA) | Comments Off on Top open source licenses and legal risk for developers

 

Top 3 reasons to choose Black Duck

What sets Black Duck apart from other SCA solutions? Industry-leading innovation, extensive vulnerability detection, and a broad range of integrations.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis (SCA) | Comments Off on Top 3 reasons to choose Black Duck

 

How to choose application security vendors and tools

Unless you build your own AppSec tools, you need to know how to choose an application security vendor and whether to opt for individual tools or a suite.

Continue Reading...

Posted in Interactive Application Security Testing (IAST), Software Composition Analysis (SCA) | Comments Off on How to choose application security vendors and tools

 

Introducing Black Duck for Google Cloud Build

To support the launch of Binary Authorization, we’re releasing Black Duck for Google Cloud Build to help ensure your images are free of policy violations.

Continue Reading...

Posted in Container Security, News & Announcements, Open Source Security, Software Composition Analysis (SCA) | Comments Off on Introducing Black Duck for Google Cloud Build

 

Introducing the Black Duck Jira Cloud integration

The Black Duck Jira Cloud integration is based on a flexible, customizable model, backed by the same exemplary Black Duck software composition product.

Continue Reading...

Posted in News & Announcements, Open Source Security, Software Composition Analysis (SCA) | Comments Off on Introducing the Black Duck Jira Cloud integration

 

You’re using open source software, and you need to keep track of it

How should you track open source? It’s almost definitely in your codebase, so the question is not whether to track it but what could happen if you don’t.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis (SCA) | Comments Off on You’re using open source software, and you need to keep track of it