With the focus on shifting security left and software supply chain security, Endor Labs has come out swinging with a strong focus on Dependency Management. Open-Source Software usage has increased tremendously, but most organizations and developers spend a ton of time and toil trying to manage those dependencies. Endor Labs boasts a strong founder with a proven track record along with a stellar research team to help tame the beast that is “dependency hell” as most developers know it, shifting security left and driving down software supply chain risk.
Endor Labs' State of Dependency Management Report evaluates Large Language Models' current potential to evaluate malware. The upshot: They're not ready for prime time.
Endor Labs released a report that identifies the top 10 open source software risks, including known vulnerabilities, compromised legitimate packages, untracked dependencies, and more. Chis Hughes explains.
Bill summarizes the main points from Endor's 2022 State of Dependency Management study to better understand how cybersecurity professionals should respond to OSS vulnerabilities.