Research, product launches, and field notes on software supply-chain security from the Kusari team.
Security shouldn’t slow you down. Kusari and Cloudsmith enable faster, safer releases by turning noisy CVE scans into actionable insight and enforcing policy from build to deploy. Go fast and secure.
A strategic guide for CISOs and software security leaders
Large language models write code quickly, but to get value to your customers, you need better security processes.
You can prepare yourself for future updates by bringing your post-market applications into a modern security paradigm.
Compare the best SBOM tools for 2025. Expert analysis of cdxgen, Syft, npm-sbom & more. Choose the right SBOM generator for your needs.
Medical devices often far outlast their support period. How can these reliable devices avoid becoming a security liability?
CISA has proposed updates to the SBOM Minimum Elements. What does this mean for business leaders and engineers?
How Medical Devices Can Comply with Section 524B to Meet FDA Cybersecurity Requirements
Companies need to pay attention to the security of their open source dependencies. Kusari Platform can help.
Kusari celebrates the past, present, and future of the Open Source Security Foundation.
Here’s what the new report from the White House means for software supply chain leaders, and how you can get ahead.
Kusari’s software supply chain expertise gives you the ability to overcome the challenges in securing your cloud-native applications.
Software supply chain security doesn’t stop at the application layer. Kusari Inspector can help secure your infrastructure-as-code, too.
The pull request workflow might seem unnecessary for projects with one developer, but it offers security, testing, and feedback benefits.
Explore essential GitHub code security review strategies, specifically designed for projects where security cannot be compromised.
Your security reviews need to be based on facts, not vibes.
Implementing secure pull requests has become essential to prevent security vulnerabilities from making their way into the codebase.
For maintainers responsible for project integrity, understanding these risks isn't optional. It's essential for protecting your software supply chain.
Kusari Inspector is now generally available to provide immediate supply chain security insights in pull requests.
Artificial intelligence can help secure the software supply chain, but it also brings additional considerations.
Securing the software supply chain doesn't end when a release ships. Maintaining released software is an important part of security.
There are so many tools to build SBOMs for your application. How do you know which one to pick?
Asking open source contributors to prove their legal identity doesn’t make software more secure.
The US DoD’s Software Fast-Track Initiative looks to improve software procurement and security. Open source software must be a key part of this.