# SCA

Published articles for SCA.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## AI SAST: Challenges for Application Security Teams

DevFeed: [AI SAST: Challenges for Application Security Teams](<https://devfeed.tech/articles/ai-sast-explained-what-works-what-doesn-t-and-what-comes-13363.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/ai-sast-explained-devsecops-guide>)

Author: Nicole Morgan

Published: 2026-08-05T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sca](<https://devfeed.tech/tags/sca.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article discusses how AI-assisted development increases pressure on static application security testing (SAST) programs. It identifies false positives, vulnerability backlogs, low remediation rates, and limited pipeline coverage as obstacles to helping developers address findings quickly.

### Source excerpt

Learn how AI is transforming SAST, reducing security friction, and helping teams secure AI-generated code without slowing delivery. | Blog

## Come join us at the next SQGNE Meeting! Open-Source Malware: Defending Your Software Supply Chain From Evolving Threats - June 17, 2026

DevFeed: [Come join us at the next SQGNE Meeting! Open-Source Malware: Defending Your Software Supply Chain From Evolving Threats - June 17, 2026](<https://devfeed.tech/articles/come-join-us-at-the-next-sqgne-meeting-open-source-malware-defending-your-software-supply-chain-from-evolving-threats-june-17-2026-22409.md>)

Original publisher: [Read original article](<https://www.tjmaher.com/2026/06/come-join-us-at-next-sqgne-meeting-open.html>)

Author: T.J. Maher (noreply@blogger.com)

Published: 2026-06-02T02:34:08Z

Content type: news

Language: en

Sources: [T.J. Maher](<https://devfeed.tech/sources/t-j-maher.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [sqgne](<https://devfeed.tech/tags/sqgne.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

The Software Quality Group of New England will host a June 17, 2026 meeting featuring Bryan Whyte of Sonatype on open-source malware and software supply chain defense. The session will cover threats targeting npm, PyPI, GitHub, and development pipelines; differences between open-source malware and traditional malware or vulnerabilities; and common tactics used in software supply chain attacks.

### Source excerpt

"Open-Source Malware: Defending Your Software Supply Chain From Evolving Threats" will be the topic of the next Software Quality Group of New England (sqgne.org) meeting. Speaker: Bryan Whyte, CISSP Director, Solutions Engineering @Sonatype Date: June 17, 2026 @ 6:00 pm Join us on Zoom or in person at Burlington, MA ( Register Here ) "Bryan Whyte breaks down the latest wave of open source malware, explains how these threats diverge from traditional vulnerabilities, and shares actionable steps for organizations to defend mission-critical software. "As organizations deepen their reliance on open-source software, evolving security threats are reshaping the landscape at an unprecedented pace. "Threat actors are now increasingly targeting development pipelines and trusted ecosystems like npm to orchestrate supply chain attacks with significant downstream impact. Incidents such as the 2025 Shai-Hulud npm campaign, the XZ Utils backdoor, and the widespread compromise of over 23,000 GitHub repositories illustrate how open-source malware has quickly become a critical, top-tier threat built to evade legacy scanning and exploit trust woven into modern delivery pipelines. "--The shifting tactics of threat actors targeting npm, PyPi, GitHub, and development pipelines "--Key differences between open-source malware and traditional malware or vulnerabilities "--The most prevalent malware types and tactics driving today's software supply chain attacks "After spending 20 years in software development, Bryan started his journey into Application Security in 2015 with the AppScan tool suite for Static, Dynamic and Mobile Application Security Testing. In 2018, he expanded his Cybersecurity proficiency, earning the Certified Information Systems Security Professional (CISSP). In 2019, he was excited to join Sonatype due to the explosive growth of open-source software, which has made Software Composition Analysis (SCA) a critical aspect of Application Security". See you there! Happy Testing

## Chainguard Images: The Easy Button for FedRAMP

DevFeed: [Chainguard Images: The Easy Button for FedRAMP](<https://devfeed.tech/articles/chainguard-images-the-easy-button-for-fedramp-12960.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-the-easy-button-for-fedramp>)

Published: 2025-01-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard sboms](<https://devfeed.tech/topics/chainguard-sboms.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [asset-management](<https://devfeed.tech/tags/asset-management.md>), [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how Chainguard Images can simplify and accelerate FedRAMP Authority to Operate compliance for organizations deploying containerized cloud products to federal government customers. It describes secure-by-design containers as helping address asset management, hardening, cryptography, and vulnerability management requirements, and notes Snowflake's achievement of FedRAMP High with Chainguard Images.

### Source excerpt

Chainguard Images are designed to make achieving FedRAMP compliance for container images easier. Learn more about how we make vulnerability management simple.

## Understanding the EU's Cyber Resilience Act (CRA)

DevFeed: [Understanding the EU's Cyber Resilience Act (CRA)](<https://devfeed.tech/articles/understanding-the-eu-s-cyber-resilience-act-cra-8226.md>)

Original publisher: [Read original article](<https://snyk.io/blog/understanding-the-eus-cyber-resilience-act-cra/>)

Author: Ben Desjardins

Published: 2025-01-22T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [executive](<https://devfeed.tech/tags/executive.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article explains how the EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements. It discusses secure-by-design practices, vulnerability handling throughout the product lifecycle, upcoming reporting and compliance deadlines, and the role of SAST, SCA, and software supply chain security.

### Source excerpt

Find out how the Cyber Resilience Act (CRA) sets new security standards for the EU and how Snyk can help simplify compliance with its developer-friendly tools.

## Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report

DevFeed: [Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report](<https://devfeed.tech/articles/snyk-named-a-customer-favorite-in-the-forrester-wavetm-software-composition-analysis-software-q4-2024-report-8135.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-forrester-wave-2024/>)

Author: Peter McKay

Published: 2024-11-13T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [automation](<https://devfeed.tech/tags/automation.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [component](<https://devfeed.tech/tags/component.md>), [customer](<https://devfeed.tech/tags/customer.md>), [developer-security-platform](<https://devfeed.tech/tags/developer-security-platform.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [integration](<https://devfeed.tech/tags/integration.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [recognition](<https://devfeed.tech/tags/recognition.md>), [report](<https://devfeed.tech/tags/report.md>), [sca](<https://devfeed.tech/tags/sca.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [support](<https://devfeed.tech/tags/support.md>)

### AI overview

Snyk announces that it was recognized as a Leader and a Customer Favorite in The Forrester Wave: Software Composition Analysis Software, Q4 2024. The article highlights Snyk's scores for strategy, risk intelligence, remediation and automation, reporting and analytics, toolchain integration, and component health, along with its developer-first approach to application security and DevSecOps.

### Source excerpt

Snyk's developer-first approach secures recognition as a Customer Favorite and a Leader in The Forrester Wave™: Software Composition Analysis (SCA) Software, Q4 2024 report.

## Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities

DevFeed: [Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities](<https://devfeed.tech/articles/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities-13312.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities>)

Published: 2024-06-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [cves](<https://devfeed.tech/tags/cves.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [research](<https://devfeed.tech/tags/research.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-fix](<https://devfeed.tech/tags/vulnerability-fix.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

An analysis of more than 600 Wolfi-packaged projects found over 100 security fixes without associated CVEs. Because vulnerability scanners and SCA tools rely on vulnerability databases such as the NVD, organizations may miss fixes unless they keep software updated.

### Source excerpt

Are your vulnerability scanners missing critical security flaws? Discover how Chainguard's research reveals hundreds of vulnerabilities hiding in plain sight.

## Three reasons to invest in an ASPM solution in 2024

DevFeed: [Three reasons to invest in an ASPM solution in 2024](<https://devfeed.tech/articles/three-reasons-to-invest-in-an-aspm-solution-in-2024-8059.md>)

Original publisher: [Read original article](<https://snyk.io/blog/reasons-to-invest-in-an-aspm-solution/>)

Author: Julia Kraut

Published: 2023-12-12T12:55:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk-apprisk](<https://devfeed.tech/topics/snyk-apprisk.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [snyk-platform](<https://devfeed.tech/topics/snyk-platform.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [snyk-container](<https://devfeed.tech/topics/snyk-container.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [blog](<https://devfeed.tech/tags/blog.md>), [executive](<https://devfeed.tech/tags/executive.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

This guide presents three reasons to invest in an application security posture management solution: consolidating security vendors, improving application security tool coverage, and managing security and compliance controls. It specifically promotes Snyk AppRisk and its integration with the Snyk platform.

### Source excerpt

Learn three compelling reasons to invest in an application security posture management (ASPM) solution like Snyk AppRisk.

## Handling security vulnerabilities in Spring Boot

DevFeed: [Handling security vulnerabilities in Spring Boot](<https://devfeed.tech/articles/handling-security-vulnerabilities-in-spring-boot-8093.md>)

Original publisher: [Read original article](<https://snyk.io/blog/security-vulnerabilities-spring-boot/>)

Author: Brian Vermeer

Published: 2023-11-29T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Spring Boot](<https://devfeed.tech/topics/spring-boot.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [dependency-management](<https://devfeed.tech/tags/dependency-management.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [java](<https://devfeed.tech/tags/java.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [spring-boot](<https://devfeed.tech/tags/spring-boot.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how to identify and remediate open source security vulnerabilities in Spring Boot applications. It emphasizes dependency management, uses Snyk Open Source as a software composition analysis tool, and discusses updating vulnerable transitive dependencies, including updating the Spring Boot Webflux starter from 2.7.16 to 2.7.17. The supplied text ends while discussing Maven and Gradle configuration.

### Source excerpt

In this blog, we'll demonstrate the best way to find and remediate open source vulnerabilities in Spring Boot.

## Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration

DevFeed: [Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration](<https://devfeed.tech/articles/secure-your-software-supply-chain-with-the-new-snyk-vulnerability-intelligence-for-sbom-servicenow-integration-8180.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-vulnerability-intelligence-sbom-servicenow/>)

Author: Sarah Conway

Published: 2023-11-07T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article introduces Snyk Vulnerability Intelligence for SBOM, an integration that brings Snyk vulnerability data into SBOMs stored in ServiceNow Vulnerability Response. It uses package URLs to identify vulnerable components, provides contextual severity and remediation information, and supports dashboards and workflows for tracking and fixing software supply chain risk.

### Source excerpt

The new Snyk Vulnerability Intelligence for SBOM integration brings visibility to your SBOMs in ServiceNow Vulnerability Response for a more accurate understanding of risk within the enterprise supply chain.

## Improving product reliability by imposing constraints as a part of CI/CD process

DevFeed: [Improving product reliability by imposing constraints as a part of CI/CD process](<https://devfeed.tech/articles/improving-product-reliability-by-imposing-constraints-as-a-part-of-ci-cd-process-26344.md>)

Original publisher: [Read original article](<https://medium.com/revolut/improving-product-reliability-by-imposing-constraints-as-a-part-of-ci-cd-process-597cf2307224?source=rss----44c5ac415e14---4>)

Author: Pedro Moura

Published: 2023-11-03T14:26:59Z

Content type: article

Language: en

Sources: [Revolut Engineering](<https://devfeed.tech/sources/revolut-engineering.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Data analysis](<https://devfeed.tech/topics/data-analysis.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [blocking](<https://devfeed.tech/tags/blocking.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [data-analysis](<https://devfeed.tech/tags/data-analysis.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sca](<https://devfeed.tech/tags/sca.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [software-development](<https://devfeed.tech/tags/software-development.md>)

### AI overview

Revolut describes a CI/CD approach that uses automated risk calculation, data analysis, security scanning, and deployment constraints to improve product reliability. The approach aims to identify vulnerabilities and bugs early, mitigate them, and potentially block high-risk applications from reaching production.

### Source excerpt

At Revolut, we always aim to consistently provide efficient, high-quality, and secure services. Our primary goals are to enhance product quality, increase customer satisfaction, and reduce business risk. To achieve those goals, we should aim to be as proactive -- rather than reactive -- as possible. This means fixing any point of failure before it reaches production by identifying, reporting, and potentially blocking deployments that can impact the reliability of our products. In this article, we'll explain how we achieve those goals using automated risk calculation, data analysis, and imposing constraints to push for the mitigation of open vulnerabilities and the fix of reported bugs identified in our products. Challenges faced by Revolut Each application/service has its own specifications, with different technology stacks and architectures, bringing a diversity of security challenges and different vulnerabilities. That being said, application risk cannot be based only on the reported security vulnerabilities but also in the context of that specific application. Continuous scanning, reporting, visibility, and risk evaluation are essential to providing the best security advice and automated security controls. Nowadays there are several types of security scanners (SAST, SCA, DAST, IaC, etc.) that help security professionals to identify and report vulnerabilities, where each of them can belong to a different third-party provider. For further information on these, read our article on continuous security. Data scraped from different sources creates friction when it's needed to group findings and provide mitigations. This can also decrease mean time to identify vulnerabilities and mean time to provide mitigations. Also, to avoid such negative workflow impact, security must be shifted left. Without a centralised source of truth for security-related application data, most of the time is wasted on searching for information/findings in segmented platforms and finding the corre

## A growing ecosystem of vulnerability scanners that now support Chainguard Images and Wolfi

DevFeed: [A growing ecosystem of vulnerability scanners that now support Chainguard Images and Wolfi](<https://devfeed.tech/articles/a-growing-ecosystem-of-vulnerability-scanners-that-now-support-chainguard-images-and-wolfi-12857.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-growing-ecosystem-of-vulnerability-scanners-that-now-support-chainguard-images-and-wolfi>)

Published: 2023-09-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [grype](<https://devfeed.tech/tags/grype.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sca](<https://devfeed.tech/tags/sca.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Images and the Wolfi distribution are now supported by a growing ecosystem of open-source and enterprise vulnerability scanners, including Docker Scout, Grype, Snyk, Trivy, and Wiz. The broader integration helps users monitor and prioritize scan results, verify vulnerabilities, reduce scanner noise and false positives, and build more secure software.

### Source excerpt

Secure your software with Chainguard & Wolfi, now recognized by leading vulnerability scanners.

## Chainguard Announces Participation in Hacker Summer Camp Security Conferences

DevFeed: [Chainguard Announces Participation in Hacker Summer Camp Security Conferences](<https://devfeed.tech/articles/get-in-chainguard-we-re-going-to-fabulous-las-vegas-13059.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-in-chainguard-were-going-to-fabulous-las-vegas>)

Published: 2023-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [defcon](<https://devfeed.tech/tags/defcon.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>)

### AI overview

Chainguard announces its participation in BSides, Black Hat, and DEFCON in Las Vegas, including a talk on limitations of software composition analysis and software bills of material in vulnerability management.

### Source excerpt

Join the Hacker Summer Camp: A hub for cybersecurity enthusiasts to explore, learn, and collaborate on cutting-edge security strategies.

## Snyk's 2023 State of Open Source Security: Supply chain security, AI, and more

DevFeed: [Snyk's 2023 State of Open Source Security: Supply chain security, AI, and more](<https://devfeed.tech/articles/snyk-s-2023-state-of-open-source-security-supply-chain-security-ai-and-more-8171.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-state-of-open-source-security-2023/>)

Author: Simon Maple

Published: 2023-07-26T13:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [executive](<https://devfeed.tech/tags/executive.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [report](<https://devfeed.tech/tags/report.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Snyk's 2023 State of Open Source Security report examines whether open source software security is improving after Log4Shell. It highlights gaps in supply chain security practices, slow adoption of foundational tools such as SCA and SAST, and mixed results and opinions surrounding AI and automation, including increased false positives.

### Source excerpt

Read Snyk's 2023 State of Open Source Security report to learn why AI, false positives, and slow security tool adoption remain concerns but faster fixes and supply chain security progress are encouraging signs in open source security.

## Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation

DevFeed: [Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation](<https://devfeed.tech/articles/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation-13142.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation>)

Published: 2023-01-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software dark matter](<https://devfeed.tech/topics/software-dark-matter.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [guessbom](<https://devfeed.tech/tags/guessbom.md>), [melange](<https://devfeed.tech/tags/melange.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that SBOMs generated after a build by software composition analysis tools can be incomplete because they may miss components that bypass recorded metadata, such as files copied through Dockerfiles. It presents build-time generation as a better way to produce complete SBOMs and describes untracked files as software dark matter, which can make post-build SBOMs closer to best guesses than reliable inventories.

### Source excerpt

GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.

## Cashier v10

DevFeed: [Cashier v10](<https://devfeed.tech/articles/cashier-v10-3609.md>)

Original publisher: [Read original article](<https://laravel.com/blog/cashier-v10>)

Author: Dries Vints

Published: 2019-08-08T14:58:00Z

Content type: article

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [stripe](<https://devfeed.tech/topics/stripe.md>), [API](<https://devfeed.tech/topics/api.md>), [Transactions](<https://devfeed.tech/topics/transactions.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apis](<https://devfeed.tech/tags/apis.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [exception](<https://devfeed.tech/tags/exception.md>), [payments](<https://devfeed.tech/tags/payments.md>), [release](<https://devfeed.tech/tags/release.md>), [sca](<https://devfeed.tech/tags/sca.md>), [stripe](<https://devfeed.tech/tags/stripe.md>), [token](<https://devfeed.tech/tags/token.md>), [transactions](<https://devfeed.tech/tags/transactions.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Cashier v10 is a major release that updates its internals and public API to support Stripe Payment Intents and Payment Methods APIs, including secondary payment actions such as 3D Secure under European SCA requirements. It replaces the older Sources and token-based APIs while preserving charging compatibility for existing subscribers.

### Source excerpt

We're very excited to announce the immediate availability of Cashier v10. This new Cashier release is a major update with lots of changes to Cashier's internals and public API. Cashier has been upgrad...