Learn

Learn about software supply chain security and Endor Labs.

Featured resources

Endor Patches whitepaper
Ebook/Report

Endor Patches Whitepaper

Dec 16, 2024
Blog

Microsoft Defender for Cloud Natively Integrates with Endor Labs

Nov 19, 2024
Start Clean With AI: Select Safer LLM Models with Endor Labs
Blog

Start Clean With AI: Select Safer LLM Models with Endor Labs

Oct 16, 2024
Ebook/Report

2024 Dependency Management Report

Sep 12, 2024
Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
SCA
Security
Developer Productivity
How to Get Developers to Accept Security PRs Faster
Blog

How to Get Developers to Accept Security PRs Faster

Feb 4, 2025
AI/ML
Open Source
Security
deepseek-r1-what-security-teams-need-to-know
Blog

DeepSeek R1: What Security Teams Need to Know

Jan 29, 2025
AI/ML
SCA
Open Source
How to Discover Open Source AI Models in Your Code
Blog

How to Discover Open Source AI Models in Your Code

Jan 28, 2025
SCA
Open Source
Security
Remote Code Execution Vulnerabilities in Apache Struts
Blog

Remote Code Execution Vulnerabilities in Apache Struts

Jan 24, 2025
Open Source
First Party Code
Everything You Need to Know About Opengrep
Blog

Everything You Need to Know About Opengrep

Jan 23, 2025
SCA
Security
Blog

Uncover Trends and Show AppSec Value with the Endor Labs Dashboard

Jan 21, 2025
Compliance & SBOM
SCA
Security
Blog

Identifying and Tracking FedRAMP False Positives

Jan 14, 2025
Developer Productivity
Open Source
SCA
Security
Blog

How Endor Labs Prioritizes Open Source Security Patches

Jan 7, 2025
Open Source
SCA
Security
Why Reachability Analysis for JavaScript Is Hard (and How We Fixed It)
Blog

Why Reachability Analysis for JavaScript Is Hard (and How We Fixed It)

Dec 17, 2024
Security
Developer Productivity
Compliance & SBOM
Open Source
SCA
Endor Patches whitepaper
Ebook/Report

Endor Patches Whitepaper

Dec 16, 2024
Developer Productivity
Open Source
SCA
Grip Security Reduces Noise by 99%
Customer Story

Grip Security Reduces Noise by 99%

Dec 11, 2024
Developer Productivity
Open Source
Security
SCA
Grip Security Builds Customer Trust with AppSec
Blog

Grip Security Builds Customer Trust with AppSec

Dec 11, 2024
SCA
Developer Productivity
Open Source
The Uncomfortable Truth of Vulnerable and Outdated Software Components
Blog

The Uncomfortable Truth of Vulnerable and Outdated Software Components

Dec 9, 2024
SCA
Open Source
Compliance & SBOM
Reduce FedRAMP Compliance Costs
Solution Brief

Reduce FedRAMP Compliance Costs

Dec 4, 2024
SCA
Security
Blog

Why OVAL Feeds Outperform NVD for Linux Vulnerability Management

Dec 3, 2024
SCA
Compliance & SBOM
Security
Blog

Achieving FedRAMP’s Container Scanning Requirements

Nov 27, 2024
Developer Productivity
Open Source
SCA
Blog

Breaking Changes, Breaking Trust

Nov 26, 2024
SCA
Open Source
Compliance & SBOM
Security
Reducing FedRAMP Compliance Costs with Endor Labs
Blog

Reducing FedRAMP Compliance Costs with Endor Labs

Nov 22, 2024
SCA
News
Security
Blog

Microsoft Defender for Cloud Natively Integrates with Endor Labs

Nov 19, 2024
AI/ML
Hugging Face Model Score Curation at Endor Labs
Blog

Hugging Face Model Score Curation at Endor Labs

Nov 11, 2024
First Party Code
SCA
Open Source
Security
Endor Labs Announces Integrated SAST Offerings
Blog

Endor Labs Announces Integrated SAST Offerings

Nov 5, 2024
Security
Compliance & SBOM
SCA
Open Source
Understanding the Cyber Resilience Act
Blog

Understanding the Cyber Resilience Act

Oct 23, 2024
AI/ML
Open Source
Security
Start Clean With AI: Select Safer LLM Models with Endor Labs
Blog

Start Clean With AI: Select Safer LLM Models with Endor Labs

Oct 16, 2024
Open Source
The U.S. Government Prioritizes Open Source Governance and Security
Blog

The U.S. Government Prioritizes Open Source Governance and Security

Oct 10, 2024
AI/ML
Security
Understanding the Basics of Large Language Models (LLMs)
Blog

Understanding the Basics of Large Language Models (LLMs)

Oct 8, 2024
Open Source
SCA
Security
Blog

Container Layer Analysis: Clarity in Remediation

Oct 2, 2024
Developer Productivity
SCA
Endor Labs Achieves 92% Reduction in SCA Alerts
Blog

Endor Labs Achieves 92% Reduction in SCA Alerts

Sep 30, 2024
News
Karl Mattson Joins Endor Labs as Chief Information Security Officer
Blog

Karl Mattson Joins Endor Labs as Chief Information Security Officer

Sep 24, 2024
Open Source
Highlights from Our 2024 Dependency Management Webinar
Blog

Highlights from Our 2024 Dependency Management Webinar

Sep 24, 2024
Developer Productivity
SCA
Security
Customer Story

Relativity Blocks Risks with Endor Labs

Sep 24, 2024
Security
SCA
Developer Productivity
Blocking with Confidence: Relativity's Dev[eloper] Experience Journey
Blog

Blocking with Confidence: Relativity's Dev Experience Journey

Sep 24, 2024
Open Source
Blog

48 most popular open source tools for Python applications, scored

Sep 23, 2024
SCA
Compliance & SBOM
FedRAMP Requirements for Vulnerability Management and Dependency Upgrades
Blog

FedRAMP Requirements for Vulnerability Management and Dependency Upgrades

Sep 20, 2024
Developer Productivity
SCA
Security
Fix Vulnerabilities Faster with Auto Patching and Endor Patches
Blog

Fix Vulnerabilities Faster with Auto Patching and Endor Patches

Sep 18, 2024
No items found.
Ebook/Report

2024 Dependency Management Report

Sep 12, 2024
Open Source
SCA
News
Security
Announcing the 2024 Dependency Management Report
Blog

Announcing the 2024 Dependency Management Report

Sep 12, 2024
SCA
Security
Developer Productivity
Starburst Gets 98.3% Noise Reduction with Endor Labs
Customer Story

Starburst Gets 98.3% Noise Reduction with Endor Labs

Sep 9, 2024
Security
SCA
Developer Productivity
Building a DevSecOps Practice at Starburst
Blog

Building a DevSecOps Practice at Starburst

Sep 9, 2024
CI/CD
Security
What is CI/CD Security and What Tools Do You Need to Do it?
Blog

What is CI/CD Security and What Tools Do You Need to Do it?

Sep 5, 2024
CI/CD
Security
Blog

PWN Request Threat: A Hidden Danger in GitHub Actions

Sep 3, 2024
SCA
Security
Blog

Address Open Source Risks with Endor Labs

Aug 27, 2024
SCA
Developer Productivity
Blog

Give Devs the Confidence to Fix: Making Remediation Less Painful

Aug 21, 2024
Security
SCA
Blog

Endor Labs Partners with Microsoft to Strengthen Software Supply Chains

Aug 21, 2024
No items found.
Blog

Prioritize Open Source Risks with Endor Labs

Aug 19, 2024
SCA
Security
Blog

Discover Open Source Risks with Endor Labs

Aug 14, 2024
Open Source
SCA
Blog

48 most popular open source tools for npm applications, scored

Aug 9, 2024
SCA
Security
Tech
Developer Productivity
Compare Endor Labs and Snyk GitHub Apps.
Blog

Benchmarking Endor Labs vs. Snyk’s GitHub Apps

Aug 8, 2024
CI/CD
Security
Compliance & SBOM
Blog

Using Artifact Signing to Establish Provenance for SLSA

Aug 8, 2024
SCA
Open Source
Developer Productivity
Fixed is Better than Found | Upgrades & Remediation with Endor Labs
Solution Brief

Fixed is Better than Found | Upgrades & Remediation with Endor Labs

Aug 7, 2024
Developer Productivity
SCA
Video

How to Fix Vulnerabilities Without Breaking Changes

Aug 7, 2024
SCA
Security
News
Developer Productivity
Blog

Introducing Upgrades & Remediation: Give Developers the Confidence to Fix

Aug 7, 2024
Security
SCA
Static SCA vs. Dynamic SCA: Which is Better and Why
Blog

Static SCA vs. Dynamic SCA: Which is Better (and Why It's Neither)

Aug 1, 2024
Open Source
Blog

33 Most Popular Open Source Tools for Maven Applications, Scored

Jul 29, 2024
SCA
Security
Customer Story

Jellyfish Enables Data-Driven AppSec with Endor Labs

Jul 24, 2024
Security
SCA
Blog

Jellyfish’s Data-Driven Security Program

Jul 24, 2024
Security
What's a Security Pipeline? - On-Demand Webinar
Video

What's a Security Pipeline? - On-Demand Webinar

Jul 17, 2024
SCA
Open Source
Developer Productivity
CI/CD
Compliance & SBOM
Secure Everything Your Code Depends On | Endor Labs
Solution Brief

Secure Everything Your Code Depends On With Endor Labs

Jul 16, 2024
News
Blog

Endor Labs Receives Strategic Investment from Citi Ventures

Jul 15, 2024
News
We made the Inc. Best Workplaces List for 2024!
Blog

We made the Inc. Best Workplaces List for 2024!

Jul 8, 2024
Security
Open Source
Blog

New CocoaPods CVEs: Swift and Objective-C Supply Chains Are Fragile

Jul 3, 2024
SCA
Security
Questions to Ask Your Software Composition Analysis Vendor
Blog

Questions to Ask Your Software Composition Analysis Vendor

Jun 27, 2024
Security
Developer Productivity
SCA
Backstage and Endor Labs: AppSec in a Dev’s Dream Workspace
Blog

Backstage and Endor Labs: AppSec in a Dev’s Dream Workspace

Jun 18, 2024
Compliance & SBOM
SCA
Managing Open Source Vulnerabilities for PCI DSS Compliance- On-Demand Webinar
Video

Managing Open Source Vulnerabilities for PCI DSS Compliance - On-Demand Webinar

Jun 18, 2024
SCA
Open Source
Security
Compliance & SBOM
Container Scanning + SCA = Better Together
Blog

Container Scanning + SCA = Better Together

Jun 11, 2024
News
Blog

Endor Labs Named to Rising in Cyber by CISOs and Venture Capital Investors

Jun 4, 2024
SCA
Open Source
Security
Blog

Evaluating and Scoring OSS Packages

Jun 4, 2024
SCA
Compliance & SBOM
Open Source
Security
Demystifying Transitive Dependency Vulnerabilities
Blog

Demystifying Transitive Dependency Vulnerabilities

May 31, 2024
CI/CD
Security
Open Source
Surprise! Your GitHub Actions Are Dependencies Too
Blog

Surprise! Your GitHub Actions Are Dependencies, Too

May 28, 2024
Compliance & SBOM
SCA
Security
OSS Vulnerabilities and the Digital Operational Resilience Act (DORA)
Blog

OSS Vulnerabilities and the Digital Operational Resilience Act (DORA)

May 21, 2024
SCA
Security
Protect Mobile Apps with Kotlin and Swift SCA
Blog

Protect Mobile Apps with Kotlin and Swift SCA

May 21, 2024
News
Blog

Endor Labs Partners with GuidePoint Security to Secure The Software Supply Chain

May 21, 2024
CI/CD
Compliance & SBOM
SCA
Intro to Endor Labs- On-Demand Webinar
Video

Intro to Endor Labs - On-Demand Webinar

May 15, 2024
SCA
Open Source
Security
 OWASP OSS Risk 1: Known Vulnerabilities, by Camila Odlund and Jenn Gile
Blog

OWASP OSS Risk 1: Known Vulnerabilities

May 14, 2024
CI/CD
Security
Low-Code/No Code Artifact Signing by Diamantis Kourkouzelis
Blog

Low-Code/No Code Artifact Signing

May 7, 2024
Compliance & SBOM
Open Source
SCA
An Auditor’s Perspective on Addressing OSS Vulnerabilities for PCI DSS v4 by Jenn Gile
Blog

An Auditor’s Perspective on Addressing OSS Vulnerabilities for PCI DSS v4

May 2, 2024
CI/CD
Compliance & SBOM
Security
Your Git Repo is a Supply Chain Risk by Darren Meyer
Blog

Your Git Repo is a Supply Chain Risk

Apr 30, 2024
Security
SCA
CI/CD
Compliance & SBOM
Open Source
Guide to Implementing Software Supply Chain Security, What to Consider When Designing a Program
Ebook/Report

Guide to Implementing Software Supply Chain Security

Apr 30, 2024
CI/CD
Security
Improve Kubernetes Security with Signed Artifacts and Admission Controllers by David Archer
Blog

Improve Kubernetes Security with Signed Artifacts and Admission Controllers

Apr 23, 2024
Developer Productivity
Open Source
Opinion
Security
Tech
AppSec Goes to Devnexus: Lessons from a Thriving, Modern Java Community by Darren Meyer
Blog

AppSec Goes to Devnexus: Lessons from a Thriving, Modern Java Community

Apr 16, 2024
CI/CD
Security
Compliance & SBOM
Artifact Signing 101 - On-Demand Webinar
Video

Artifact Signing 101 - On-Demand Webinar

Apr 10, 2024
Security
Open Source
Compliance & SBOM
SCA
XZ Backdoor: How to Prepare for the Next One by Jamie Scott
Blog

XZ Backdoor: How to Prepare for the Next One

Apr 3, 2024
Security
Open Source
Opinion
XZ is A Wake Up Call For Software Security: Here's Why by Dimitri Stiliadis
Blog

XZ is A Wake Up Call For Software Security: Here's Why

Apr 1, 2024
Compliance & SBOM
SSDF Compliance and Attestation by Chris Hughes
Blog

SSDF Compliance and Attestation

Mar 26, 2024
CI/CD
Security
You Have a Shadow Pipeline Problem by Darren Meyer
Blog

You Have a Shadow Pipeline Problem

Mar 19, 2024
SCA
Open Source
Security
Remediating Vulnerabilities vs. Maintaining Current Dependencies
Blog

Remediating Vulnerabilities vs. Maintaining Current Dependencies

Mar 13, 2024
SCA
Security
Prioritizing SCA Findings with Reachability Analysis - On-Demand Webinar
Video

Prioritizing SCA Findings with Reachability Analysis - On-Demand Webinar

Mar 6, 2024
CI/CD
Compliance & SBOM
Security
Signing Your Artifacts For Security, Quality, and Compliance
Blog

Signing Your Artifacts For Security, Quality, and Compliance

Mar 5, 2024
Open Source
SCA
Security
Detecting Malicious Packages in Open Source Dependencies by Henrik Plate
Blog

Detect Malicious Packages Among Your Open Source Dependencies

Feb 28, 2024
News
Tom Gleason Joins Endor Labs as VP of Customer Solutions
Blog

Tom Gleason Joins Endor Labs as VP of Customer Solutions

Feb 20, 2024
CI/CD
Compliance & SBOM
Security
Introducing CI/CD Security with Endor Labs
Blog

Introducing CI/CD Security with Endor Labs

Feb 14, 2024
Security
Open Source
SCA
How to Improve SCA in GitHub Advanced Security
Video

How to Improve SCA in GitHub Advanced Security - Tutorial

Feb 5, 2024
Security
Open Source
SCA
Compliance & SBOM
How to Ingest and Manage SBOMs
Video

How to Ingest and Manage SBOMs - Tutorial

Jan 30, 2024
No items found.
VMware achieves SBOM compliance for over 100 services with Endor Labs
Customer Story

VMware Achieves SBOM Compliance for Over 100 Services with Endor Labs

Jan 29, 2024
Security
AI/ML
AI-Supported Environment Debugging for Endor Labs
Blog

AI-Supported Environment Debugging for Endor Labs

Jan 25, 2024
Security
Open Source
SCA
Compliance & SBOM
How to Generate SBOM and VEX
Video

How to Generate SBOM and VEX - Tutorial

Jan 23, 2024
Security
AI/ML
Open Source
How to Use AI for Open Source Selection
Video

How to Use AI for Open Source Selection - Tutorial

Jan 9, 2024
no-results
Sorry, no results matching your search.

Want to stay in the loop?

Sign up for our newsletter.

Welcome to the resistance
Oops! Something went wrong while submitting the form.