Blog

From the Kusari team.

Research, product launches, and field notes on software supply-chain security from the Kusari team.

Breaking the "Department of No" - Ship Fast, but also Secure

Breaking the "Department of No" - Ship Fast, but also Secure

Security shouldn’t slow you down. Kusari and Cloudsmith enable faster, safer releases by turning noisy CVE scans into actionable insight and enforcing policy from build to deploy. Go fast and secure.

The Top 10 To-Dos for CRA Compliance Right Now

The Top 10 To-Dos for CRA Compliance Right Now

A strategic guide for CISOs and software security leaders

It Takes More Than AI to Deliver Code Faster

It Takes More Than AI to Deliver Code Faster

Large language models write code quickly, but to get value to your customers, you need better security processes.

Updating Legacy Medical Applications for Modern Security Requirements

Updating Legacy Medical Applications for Modern Security Requirements

You can prepare yourself for future updates by bringing your post-market applications into a modern security paradigm.

Best SBOM Tools 2025: How to Choose the Right SBOM Generation Tool

Best SBOM Tools 2025: How to Choose the Right SBOM Generation Tool

Compare the best SBOM tools for 2025. Expert analysis of cdxgen, Syft, npm-sbom & more. Choose the right SBOM generator for your needs.

Securing Yesterday’s Medical Devices against Cyber Threats: Addressing Legacy MedTech

Securing Yesterday’s Medical Devices against Cyber Threats: Addressing Legacy MedTech

Medical devices often far outlast their support period. How can these reliable devices avoid becoming a security liability?

Understanding the Proposed CISA 2025 SBOM Minimum Elements

Understanding the Proposed CISA 2025 SBOM Minimum Elements

CISA has proposed updates to the SBOM Minimum Elements. What does this mean for business leaders and engineers?

Securing Medical Devices: Cyber Threats, SBOMs, and FDA Premarket Readiness

Securing Medical Devices: Cyber Threats, SBOMs, and FDA Premarket Readiness

How Medical Devices Can Comply with Section 524B to Meet FDA Cybersecurity Requirements

Using Kusari to Manage your Open Source Dependencies

Using Kusari to Manage your Open Source Dependencies

Companies need to pay attention to the security of their open source dependencies. Kusari Platform can help.

Celebrating OpenSSF’s Anniversary

Celebrating OpenSSF’s Anniversary

Kusari celebrates the past, present, and future of the Open Source Security Foundation.

What Security Leaders Need to Know about America’s AI Action Plan

What Security Leaders Need to Know about America’s AI Action Plan

Here’s what the new report from the White House means for software supply chain leaders, and how you can get ahead.

Addressing the Challenges of Cloud-Native Application Security

Addressing the Challenges of Cloud-Native Application Security

Kusari’s software supply chain expertise gives you the ability to overcome the challenges in securing your cloud-native applications.

Supply Chain Security for GitOps

Supply Chain Security for GitOps

Software supply chain security doesn’t stop at the application layer. Kusari Inspector can help secure your infrastructure-as-code, too.

Using Pull Requests on a Single-Developer Project

Using Pull Requests on a Single-Developer Project

The pull request workflow might seem unnecessary for projects with one developer, but it offers security, testing, and feedback benefits.

GitHub Code Review Best Practices for Security-Critical Projects

GitHub Code Review Best Practices for Security-Critical Projects

Explore essential GitHub code security review strategies, specifically designed for projects where security cannot be compromised.

Going Beyond Vibes with Kusari Inspector

Going Beyond Vibes with Kusari Inspector

Your security reviews need to be based on facts, not vibes.

Stop Merging Risky Code: Secure Pull Requests with Automated Security Checks

Stop Merging Risky Code: Secure Pull Requests with Automated Security Checks

Implementing secure pull requests has become essential to prevent security vulnerabilities from making their way into the codebase.

Top 5 Pull Request Security Risks Every Maintainer Should Know

Top 5 Pull Request Security Risks Every Maintainer Should Know

For maintainers responsible for project integrity, understanding these risks isn't optional. It's essential for protecting your software supply chain.

Kusari Inspector: Security Insights Where You Need Them

Kusari Inspector: Security Insights Where You Need Them

Kusari Inspector is now generally available to provide immediate supply chain security insights in pull requests.

AI and the Secure Software Factory

AI and the Secure Software Factory

Artificial intelligence can help secure the software supply chain, but it also brings additional considerations.

Securing the Maintenance Phase

Securing the Maintenance Phase

Securing the software supply chain doesn't end when a release ships. Maintaining released software is an important part of security.

Choosing an SBOM Generation Tool

Choosing an SBOM Generation Tool

There are so many tools to build SBOMs for your application. How do you know which one to pick?

Code is More Important than Identity for Security

Code is More Important than Identity for Security

Asking open source contributors to prove their legal identity doesn’t make software more secure.

Open Source Accelerates Secure Software

Open Source Accelerates Secure Software

The US DoD’s Software Fast-Track Initiative looks to improve software procurement and security. Open source software must be a key part of this.