Research, product launches, and field notes on software supply-chain security from the Kusari team.
Open source projects are in the spotlight as regulated industries, governments and those that sell to them ramp cybersecurity expectations. Enter Open Source Project Security (OSPS) Baseline!
Endpoint security is a key part of many IT security efforts, but it’s not always thought about in the specific context of software supply chain security.
Many threats present themselves while implementing software. Here's how to find and address them.
Recent funding concerns have highlighted the need for a more resilient system of vulnerability identification.
Kusari CTO Mike Lieberman shares his thoughts after attending the second-annual VulnCon conference.
Beyond knowing why transitive dependencies are important, you have to know how to manage them.
in-toto helps ensure product integrity by making transparent what steps were performed, by whom, and in what order.
Transitive dependencies are the invisible majority of your applications. Failure to properly understand them increases your risk.
A secure and resilient method for distributing software updates is a key part of keeping your supply chain trustworthy.
This new book from Michael Liberman and Brandon Lum guides you from the basics of supply chain security through to being a security expert.
GUAC v0.14.0 includes a Kubescape collector that can be run inside your Kubernetes cluster to watch for new scan results from Kubescape and ingest those results into GUAC
The abilities of generative and agentic AI models require a proactive approach to protecting the AI supply chain.
When you need a solution for managing your software supply chain, the Kusari Platform provides enterprise-ready features backed by security expertise.
Comparing two SBOMs is useful, but as your portfolio grows, you need to take a holistic approach.
Once you have multiple releases, you have multiple SBOMs. What can you learn from comparing them?
A hypothetical organization takes the first step on their software supply chain security journey by creating an SBOM for their application.
Kusari Platform gives you the information you need to secure your software supply chain.
Kusari is proud to contribute to the Open Source Project Security Baseline, an OpenSSF project to help open source maintainers improve their security posture.
Once you've discovered the third-party risks in the open source projects you consume, how do you address those risks without having a vendor relationship with the projects?
Third-party risk management is an important part of protecting your organization. But how do you manage the risks of open source software when you have no vendor relationship?
Creating a secure foundation of trust enables organizations to safely delegate specific actions in the software development life cycle.
Get a clear understanding of the work involved in remediating a vulnerability so you can schedule it in your sprint without blocking feature work.
Cut through the noise to prioritize which vulnerability gets fixed next
Medical monitors have critical security flaws, allowing unauthorized code execution and patient data leaks.