Blog

From the Kusari team.

Research, product launches, and field notes on software supply-chain security from the Kusari team.

Graph for Understanding Artifact Composition (GUAC) adds persistent storage in v0.6.0 release

Graph for Understanding Artifact Composition (GUAC) adds persistent storage in v0.6.0 release

Open source supply chain observability tool standardizes on PostgreSQL

Proactive Security in the Post-Log4j Era

Proactive Security in the Post-Log4j Era

Gone are the days when signing containers and running vulnerability scans through CI processes provided a sense of security.

XZ Backdoor: Software Security Lessons

XZ Backdoor: Software Security Lessons

The recent incident involving the XZ backdoor brings to light the critical importance of vigilance and proactive security measures, while not losing sight of the human element.

Unveiling GUAC as an OpenSSF Incubating Project for Software Dependency Management

Unveiling GUAC as an OpenSSF Incubating Project for Software Dependency Management

Today, we find ourselves in a moment akin to proud parents, as we witness a significant milestone in the journey of Graph for Understanding Artifact Composition (GUAC).

Graph for Understanding Artifact Composition (GUAC)  Joins OpenSSF as Incubating Project

Graph for Understanding Artifact Composition (GUAC) Joins OpenSSF as Incubating Project

The GUAC maintainers are pleased to announce the project has joined the Open Source Security Foundation (OpenSSF) as an Incubating Project.

From Open Source Community to Joining a Start-up – while in High School

From Open Source Community to Joining a Start-up – while in High School

Nathan Naveen, a 17-year-old high schooler, shares his journey to becoming an intern at Kusari

Kusari Soaks up Community at FOSDEM and Beyond

Kusari Soaks up Community at FOSDEM and Beyond

Kusari speaking at FOSDEM and other EU community venues

Our $8M Funding Round Fuels our Mission to Make the Software Supply Chain Transparent and Secure

Our $8M Funding Round Fuels our Mission to Make the Software Supply Chain Transparent and Secure

Kusari raises seed funding

Contributor to Leader: Securing Open Source Software at OpenSSF

Contributor to Leader: Securing Open Source Software at OpenSSF

Kusari elected to OpenSSF leadership roles

What the NSA Missed in its SBOM Management Recommendations

What the NSA Missed in its SBOM Management Recommendations

The missing first step that most organizations are still struggling with

Spooky Enhancements: Unveiling GUAC's OpenVEX Feature

Spooky Enhancements: Unveiling GUAC's OpenVEX Feature

GUAC's OpenVEX Integration

Terror of cURL - Preparation is Half the Battle

Terror of cURL - Preparation is Half the Battle

CVE-2023-38545 - HIGH Severity Vulnerability

Announcing the Kusari YouTube Channel and GUACademy

Announcing the Kusari YouTube Channel and GUACademy

Kusari have just launched a YouTube Channel!

Case Study: A discussion with Guidewire on GUAC

Case Study: A discussion with Guidewire on GUAC

A look into Guidewire's software supply chain security use case and why they are using GUAC

Announcing Helm Chart for GUAC

Announcing Helm Chart for GUAC

Helm Chart for GUAC

daBOM Podcast with Tim & DJ

daBOM Podcast with Tim & DJ

Tim appeared as a guest on the daBOM podcast.

Quest to determine the 'G' in GUAC

Quest to determine the 'G' in GUAC

Working towards determining a persistent database for GUAC

GUAC v0.1 Beta Release

GUAC v0.1 Beta Release

Kusari is excited to announce the v0.1 beta release of GUAC — Graph for Understanding Artifact Composition.

Kusari Open-Sources Spector

Kusari Open-Sources Spector

We’re excited to announce the open-sourcing of Spector.

Figure Out Who's Lurking in Your Supply Chain With Signatures and Attestations

Figure Out Who's Lurking in Your Supply Chain With Signatures and Attestations

A Story of Software and Cats

Applying Zero Trust to the Software Supply Chain

Applying Zero Trust to the Software Supply Chain

Understanding Zero Trust and Its Benefits

Kusari's Software Supply Chain Security Overview

Kusari's Software Supply Chain Security Overview

What is Software Supply Chain security, and why should I care?

The Next Heartbleed?

The Next Heartbleed?

Heartbleed (CVE-2014-0160) in 2014 left the industry in a scramble...

Kusari presenting at KubeCon and Cloud Native SecurityCon NA 2022

Kusari presenting at KubeCon and Cloud Native SecurityCon NA 2022

KubeCon + CloudNativeCon is right around the corner and we are excited to be attending in person!