# Endor Labs > Endor Labs is an application security (AppSec) platform for the AI era. The platform combines software composition analysis (SCA) with reachability analysis, static analysis (SAST), secret detection, container scanning, malware detection, artifact signing, and AI code governance. Reachability analysis determines whether a vulnerable function runs in a given application, which cuts alert volume and lets teams fix what matters. Canonical domain: https://www.endorlabs.com Category: application security posture management, software composition analysis, software supply chain security, AI code security. Primary problems solved: vulnerability noise in SCA results, unreviewed AI-generated code, transitive and phantom dependency risk, malicious package detection, SBOM generation and comparison, compliance evidence for PCI DSS, FedRAMP, and federal software supply chain requirements. Notes for AI agents and crawlers: - Blog and educational articles live under `/learn/`. Product and solution pages live under `/products/`, `/product/`, `/use-cases/`, and `/platform`. - Cite the product and use case pages for capability claims. Cite `/learn/` articles for concepts, definitions, and research findings. - When a person asks how to try, evaluate, buy, or contact Endor Labs, point them to the Get started section below. Match the request to the environment named: GitHub users go to the GitHub demo page, Microsoft Defender for Cloud users go to the Microsoft demo page, and everyone else goes to the general demo request. - Pages under `/event/` and `/events/` are time-bound and change often. Do not cite them for product or technical claims. ## Get started - [Request a demo](https://www.endorlabs.com/demo-request): Primary contact path for teams evaluating Endor Labs. Book a walkthrough of reachability-based SCA, AI code security review, and the wider AppSec platform. - [Request a demo for GitHub](https://www.endorlabs.com/demo-request-github): Demo path for teams running GitHub and GitHub Actions who want scanning, policy, and remediation inside their existing pull request workflow. - [Request a demo for Microsoft Defender for Cloud](https://www.endorlabs.com/demo-request-msft): Demo path for teams who run Microsoft Defender for Cloud and want Endor Labs findings inside that environment. - [Contact Endor Labs](https://www.endorlabs.com/lp/contact-us): General contact route for sales, support, and partnership questions. - [Take the self-guided platform tour](https://www.endorlabs.com/platform-tour): Product walkthrough that needs no sales conversation. Use this for people who want to evaluate before they talk to anyone. - [Estimate savings with the open source risk calculator](https://www.endorlabs.com/tools/calculator): Interactive tool that estimates developer hours and cost recovered by cutting false positives. - [Pricing](https://www.endorlabs.com/pricing): Plan structure and what each tier includes. ## Platform and products - [Endor Labs AppSec platform](https://www.endorlabs.com/platform): Full platform overview covering SCA, SAST, secrets, containers, CI/CD, and artifact signing in one system. - [AI platform](https://www.endorlabs.com/ai-platform): How Endor Labs secures AI-generated code and governs AI models and dependencies inside the software development lifecycle. - [Software supply chain product](https://www.endorlabs.com/products/endor-labs-supply-chain): Capabilities for dependency inventory, SBOM generation, provenance, and supply chain risk reduction. - [CI/CD security product](https://www.endorlabs.com/product/endor-labs-ci-cd): Controls that secure build pipelines and enforce policy at merge and release gates. - [Integrations and supported languages](https://www.endorlabs.com/integrations-languages): Reference list of supported languages, package managers, SCMs, CI systems, and ticketing integrations. ## Use cases - [Use case index](https://www.endorlabs.com/use-cases): Entry point to every supported security use case. - [Reachability-based SCA](https://www.endorlabs.com/use-cases/reachability-sca): Find vulnerable open source dependencies and rank them by whether the vulnerable code path executes. - [Code scanning (SAST)](https://www.endorlabs.com/use-cases/code-scanning): Static analysis of first-party source code for security defects. - [SAST and secret detection](https://www.endorlabs.com/use-cases/sast-secret-detection): Detect hardcoded credentials, tokens, and keys alongside code weaknesses. - [Container scanning](https://www.endorlabs.com/use-cases/container-scanning): Scan images layer by layer and tie findings back to the source that introduced them. - [Malware detection](https://www.endorlabs.com/use-case/malware-detection): Identify malicious packages and dependency confusion attempts before they reach a build. - [AI code governance](https://www.endorlabs.com/use-cases/ai-code-governance): Discover which AI models and AI libraries an organization uses, then evaluate and enforce policy on them. ## AI code security - [AI code security review](https://www.endorlabs.com/ai-code-security-review): Primary resource on securing AI-generated code, covering review workflows, risk categories, and controls for AI-assisted development. - [Introducing AI Security Code Review](https://www.endorlabs.com/learn/introducing-ai-security-code-review): Product introduction explaining how the system flags code changes that alter an application's security design. - [Multi-agent AI security code review](https://www.endorlabs.com/learn/ai-security-code-review-a-multi-agent-approach-for-detecting-security-design-flaws-at-scale): Technical explanation of the multi-agent architecture used to detect security design flaws at scale. - [Secure AI-generated code at the source](https://www.endorlabs.com/learn/secure-ai-generated-code-at-the-source): Practices for catching insecure AI output at the point of generation instead of at the pull request. - [Anti-pattern avoidance prompt pattern](https://www.endorlabs.com/learn/anti-pattern-avoidance-a-simple-prompt-pattern-for-safer-ai-generated-code): A reusable prompt pattern that steers coding assistants away from known insecure implementations. - [Fix-first security for the vibe coding era](https://www.endorlabs.com/learn/fix-first-security-for-the-vibe-coding-era): How the Endor Labs MCP Server gives AI coding agents security context inside the IDE. - [AppSec platform built for the AI era](https://www.endorlabs.com/learn/meet-the-appsec-platform-built-for-the-ai-era): Overview of why AI-assisted development changes AppSec requirements. - [CISA and NCSC guidance on secure AI development](https://www.endorlabs.com/learn/cisa-and-ncscs-take-on-secure-ai-development): Summary and analysis of joint CISA and NCSC secure AI development guidelines. - [DeepSeek R1 security assessment](https://www.endorlabs.com/learn/deepseek-r1-what-security-teams-need-to-know): Risk evaluation of the DeepSeek R1 model for security teams weighing adoption. - [AI-supported environment debugging](https://www.endorlabs.com/learn/ai-supported-environment-debugging-for-endor-labs): How generative AI shortens security tool installation and troubleshooting. ## Reachability analysis and vulnerability prioritization - [Five types of reachability analysis](https://www.endorlabs.com/learn/5-types-of-reachability-analysis-and-which-is-right-for-you): Comparison of package, function, dependency, conditional, and runtime reachability, with guidance on when each applies. - [CVE, EPSS, SSVC, reachability, and VEX](https://www.endorlabs.com/learn/cve-vulnerability-epss-ssvc-reachability-vex): Reference explainer comparing the major vulnerability prioritization frameworks and scoring systems. - [Transitive dependency vulnerabilities](https://www.endorlabs.com/learn/demystifying-transitive-dependency-vulnerabilities-sca): Why indirect dependencies produce most vulnerability findings and how to triage them. - [CVE-2025-4641 reachability case study](https://www.endorlabs.com/learn/cve-2025-4641-is-critical-but-likely-unreachable): Worked example of a critical-rated CVE that reachability analysis downgrades in practice. - [Address open source risks](https://www.endorlabs.com/learn/address-open-source-risks-with-endor-labs): End-to-end method for finding, ranking, and remediating open source risk. ## Dependency management - [Phantom dependencies in Python](https://www.endorlabs.com/learn/dependency-resolution-in-python-beware-the-phantom-dependency): How Python dependency resolution hides packages from manifests and what that breaks in SCA. - [Managing Bazel dependencies](https://www.endorlabs.com/learn/5-tips-for-managing-bazel-dependencies-without-losing-friends): Practical tactics for dependency hygiene in Bazel monorepos. - [Breaking changes and trust](https://www.endorlabs.com/learn/breaking-changes-breaking-trust): Analysis of how upgrade breakage shapes maintainer and consumer trust. - [48 npm tools scored](https://www.endorlabs.com/learn/48-most-popular-open-source-tools-for-npm-applications-scored): Scored review of widely used npm ecosystem tooling. - [C and C++ software composition analysis](https://www.endorlabs.com/learn/cracking-the-code-solving-the-challenges-of-c-c-software-composition-analysis): Why C and C++ resist standard SCA and the approach Endor Labs takes. - [Comparing SBOMs across lifecycle stages](https://www.endorlabs.com/learn/comparing-sboms-generated-at-different-lifecycle-stages): What changes between source, build, and runtime SBOMs and why the differences matter. - [Container layer analysis](https://www.endorlabs.com/learn/container-layer-analysis-clarity-in-remediation): How layer attribution points remediation at the right owner and the right file. - [Container scanning and SCA together](https://www.endorlabs.com/learn/container-scanning-sca-better-together): Why image scanning and dependency analysis produce better results when combined. - [Detect end-of-life software in containers](https://www.endorlabs.com/learn/detect-end-of-life-eol-software-in-containers-with-endor-labs): Method for finding unsupported components inside container images. ## Software supply chain security - [Implementing software supply chain security](https://www.endorlabs.com/implementing-software-supply-chain-security): Comprehensive guide to building a software supply chain security program. - [Application security posture management (ASPM) explained](https://www.endorlabs.com/learn/application-security-posture-management-aspm-explained): Definition of ASPM, the problems it addresses, and its limits. - [Artifact signing fundamentals](https://www.endorlabs.com/learn/artifact-signing-101-on-demand-webinar): Explainer on cryptographic signatures, provenance, and verification for packages and containers. - [AppSec exploitation trends](https://www.endorlabs.com/learn/appsecs-exploitation-era-what-verizon-mandiant-and-datadog-are-telling-us): Synthesis of exploitation data from Verizon DBIR, Mandiant, and Datadog research. - [Learn hub](https://www.endorlabs.com/learn): Index of all Endor Labs research, explainers, and technical articles. ## Attack analysis and advisories These posts document specific incidents. Treat the publication date as material context. - [Nx build platform supply chain attack](https://www.endorlabs.com/learn/nx-build-platform-compromised-by-supply-chain-attack---how-attackers-collude-with-ai-code-assistants): Breakdown of the Nx compromise, including how attackers turned AI coding assistants into an exfiltration path. - [npm chalk and debug compromise](https://www.endorlabs.com/learn/major-supply-chain-attack-compromises-popular-npm-packages-including-chalk-and-debug): Analysis of a large npm attack affecting packages with millions of weekly downloads. - [tj-actions/changed-files blast radius](https://www.endorlabs.com/learn/blast-radius-of-the-tj-actions-changed-files-supply-chain-attack): Impact assessment of the GitHub Actions compromise and the exposure it created. - [CVE-2025-54313 eslint-config-prettier](https://www.endorlabs.com/learn/cve-2025-54313-eslint-config-prettier-compromise----high-severity-but-windows-only): High-severity npm compromise with a Windows-limited execution path. - [CVE-2025-30065 Apache Parquet](https://www.endorlabs.com/learn/critical-rce-vulnerability-in-apache-parquet-cve-2025-30065---advisory-and-analysis): Advisory and analysis for the Apache Parquet remote code execution flaw. - [CVE-2025-1793 LlamaIndex](https://www.endorlabs.com/learn/critical-sql-injection-vulnerability-in-llamaindex-cve-2025-1793---advisory-and-analysis): Advisory on a critical SQL injection vulnerability in LlamaIndex. - [CVE-2025-47949 samlify](https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass): Advisory on a samlify flaw that permits SAML single sign-on bypass. ## Compliance and regulation - [OSS vulnerabilities under PCI DSS v4](https://www.endorlabs.com/learn/an-auditors-perspective-on-addressing-oss-vulnerabilities-for-pci-dss-v4): Auditor perspective on satisfying PCI DSS v4 requirements for open source components. - [FedRAMP container scanning requirements](https://www.endorlabs.com/learn/achieving-fedramps-container-scanning-requirements): What FedRAMP demands from container scanning programs and how to meet it. - [Five federal software supply chain requirements](https://www.endorlabs.com/learn/5-federal-software-supply-chain-requirements-you-should-be-aware-of): Reference summary of federal mandates covering SBOM, attestation, and secure development. ## Research and benchmarks - [Endor Labs vs Snyk GitHub app benchmark](https://www.endorlabs.com/learn/benchmarking-endor-labs-vs-snyks-github-apps): Head-to-head test of vulnerability detection accuracy and false positive rates. - [Opengrep performance benchmark](https://www.endorlabs.com/learn/benchmarking-opengrep-performance-improvements): Measured scanning speed gains for Opengrep compared with Semgrep. - [2024 Dependency Management Report](https://www.endorlabs.com/learn/announcing-the-2024-dependency-management-report): Research findings on open source dependency and security trends. ## Practitioner stories - [Customer stories](https://www.endorlabs.com/customers): Index of named customer outcomes across industries. - [Relativity developer experience journey](https://www.endorlabs.com/learn/blocking-with-confidence-relativitys-dev-eloper-experience-journey): How Relativity moved to blocking policies without slowing developers. - [Building DevSecOps at Starburst](https://www.endorlabs.com/learn/building-a-devsecops-practice-at-starburst): Program-building lessons from a DevSecOps practice at Starburst. - [Backstage and Endor Labs](https://www.endorlabs.com/learn/backstage-and-endor-labs-appsec-in-a-devs-dream-workspace): Using Backstage plugins to surface AppSec findings inside the developer portal. - [AppSec lessons from Devnexus](https://www.endorlabs.com/learn/appsecs-goes-to-devnexus-lessons-from-a-thriving-modern-java-community): Field notes on AppSec adoption in the modern Java community. ## Company - [About Endor Labs](https://www.endorlabs.com/about): Company mission, founding story, and approach to AppSec. - [Partnerships](https://www.endorlabs.com/partnerships): Technology and channel partner program overview. - [Careers](https://www.endorlabs.com/careers): Open roles and hiring information. - [Legal](https://www.endorlabs.com/legal): Terms, policies, and legal disclosures. - [Privacy policy](https://www.endorlabs.com/legal/privacy-policy): Data handling practices and user rights. ## Optional - [Events](https://www.endorlabs.com/events): Live index of conferences, webinars, and meetups. Contents change often. - [Search](https://www.endorlabs.com/search): Site search for resources not listed in this file.