# software composition analysis

Published articles for software composition analysis.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard Images are the Gold Standard for PCI DSS v4.0

DevFeed: [Chainguard Images are the Gold Standard for PCI DSS v4.0](<https://devfeed.tech/articles/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0-12954.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-are-the-gold-standard-for-pci-dss-v4-0>)

Published: 2025-02-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [financial](<https://devfeed.tech/tags/financial.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [pci-dss-v4-0](<https://devfeed.tech/tags/pci-dss-v4-0.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [stig](<https://devfeed.tech/tags/stig.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how Chainguard Images can support selected PCI DSS v4.0 container-security controls. It focuses on asset and vulnerability management, hardened images, FIPS cryptography, build-time SBOMs, software supply chain inventory, and continuously updated containers.

### Source excerpt

Chainguard Images are designed to make container image compliance for PCI DSS v4.0 easy for any company involved in card transactions.

## Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report

DevFeed: [Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report](<https://devfeed.tech/articles/snyk-named-a-customer-favorite-in-the-forrester-wavetm-software-composition-analysis-software-q4-2024-report-8135.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-forrester-wave-2024/>)

Author: Peter McKay

Published: 2024-11-13T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [automation](<https://devfeed.tech/tags/automation.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [component](<https://devfeed.tech/tags/component.md>), [customer](<https://devfeed.tech/tags/customer.md>), [developer-security-platform](<https://devfeed.tech/tags/developer-security-platform.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [integration](<https://devfeed.tech/tags/integration.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [recognition](<https://devfeed.tech/tags/recognition.md>), [report](<https://devfeed.tech/tags/report.md>), [sca](<https://devfeed.tech/tags/sca.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [support](<https://devfeed.tech/tags/support.md>)

### AI overview

Snyk announces that it was recognized as a Leader and a Customer Favorite in The Forrester Wave: Software Composition Analysis Software, Q4 2024. The article highlights Snyk's scores for strategy, risk intelligence, remediation and automation, reporting and analytics, toolchain integration, and component health, along with its developer-first approach to application security and DevSecOps.

### Source excerpt

Snyk's developer-first approach secures recognition as a Customer Favorite and a Leader in The Forrester Wave™: Software Composition Analysis (SCA) Software, Q4 2024 report.

## Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities

DevFeed: [Vulnerability fixes in plain sight: How your scanners are missing hundreds of vulnerabilities](<https://devfeed.tech/articles/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities-13312.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vulnerability-fixes-in-plain-sight-how-your-scanners-are-missing-hundreds-of-vulnerabilities>)

Published: 2024-06-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [cves](<https://devfeed.tech/tags/cves.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [research](<https://devfeed.tech/tags/research.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-fix](<https://devfeed.tech/tags/vulnerability-fix.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

An analysis of more than 600 Wolfi-packaged projects found over 100 security fixes without associated CVEs. Because vulnerability scanners and SCA tools rely on vulnerability databases such as the NVD, organizations may miss fixes unless they keep software updated.

### Source excerpt

Are your vulnerability scanners missing critical security flaws? Discover how Chainguard's research reveals hundreds of vulnerabilities hiding in plain sight.

## Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration

DevFeed: [Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration](<https://devfeed.tech/articles/secure-your-software-supply-chain-with-the-new-snyk-vulnerability-intelligence-for-sbom-servicenow-integration-8180.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-vulnerability-intelligence-sbom-servicenow/>)

Author: Sarah Conway

Published: 2023-11-07T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article introduces Snyk Vulnerability Intelligence for SBOM, an integration that brings Snyk vulnerability data into SBOMs stored in ServiceNow Vulnerability Response. It uses package URLs to identify vulnerable components, provides contextual severity and remediation information, and supports dashboards and workflows for tracking and fixing software supply chain risk.

### Source excerpt

The new Snyk Vulnerability Intelligence for SBOM integration brings visibility to your SBOMs in ServiceNow Vulnerability Response for a more accurate understanding of risk within the enterprise supply chain.

## Snyk's 2023 State of Open Source Security: Supply chain security, AI, and more

DevFeed: [Snyk's 2023 State of Open Source Security: Supply chain security, AI, and more](<https://devfeed.tech/articles/snyk-s-2023-state-of-open-source-security-supply-chain-security-ai-and-more-8171.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-state-of-open-source-security-2023/>)

Author: Simon Maple

Published: 2023-07-26T13:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [executive](<https://devfeed.tech/tags/executive.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [report](<https://devfeed.tech/tags/report.md>), [sca](<https://devfeed.tech/tags/sca.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Snyk's 2023 State of Open Source Security report examines whether open source software security is improving after Log4Shell. It highlights gaps in supply chain security practices, slow adoption of foundational tools such as SCA and SAST, and mixed results and opinions surrounding AI and automation, including increased false positives.

### Source excerpt

Read Snyk's 2023 State of Open Source Security report to learn why AI, false positives, and slow security tool adoption remain concerns but faster fixes and supply chain security progress are encouraging signs in open source security.

## 8 tips for securing your CI/CD pipeline with Snyk

DevFeed: [8 tips for securing your CI/CD pipeline with Snyk](<https://devfeed.tech/articles/8-tips-for-securing-your-ci-cd-pipeline-with-snyk-8082.md>)

Original publisher: [Read original article](<https://snyk.io/blog/securing-ci-cd-pipeline-with-snyk/>)

Author: Eric Smalling

Published: 2023-07-20T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [ci-cd-pipeline](<https://devfeed.tech/tags/ci-cd-pipeline.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>)

### AI overview

This cheat sheet presents eight tips for securing CI/CD pipelines with Snyk. It covers dependency and open-source component scanning, vulnerability detection, remediation guidance, and implementation examples for Jenkins and GitHub Actions.

### Source excerpt

In this post, we'll cover using Snyk in your CI/CD pipelines to catch security issues quickly and empower your developers to fix them before they ever get to production.

## Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation

DevFeed: [Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation](<https://devfeed.tech/articles/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation-13142.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation>)

Published: 2023-01-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software dark matter](<https://devfeed.tech/topics/software-dark-matter.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [guessbom](<https://devfeed.tech/tags/guessbom.md>), [melange](<https://devfeed.tech/tags/melange.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that SBOMs generated after a build by software composition analysis tools can be incomplete because they may miss components that bypass recorded metadata, such as files copied through Dockerfiles. It presents build-time generation as a better way to produce complete SBOMs and describes untracked files as software dark matter, which can make post-build SBOMs closer to best guesses than reliable inventories.

### Source excerpt

GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.

## Improving the Developer Experience -- Our Application Security Journey (Part 3)

DevFeed: [Improving the Developer Experience -- Our Application Security Journey (Part 3)](<https://devfeed.tech/articles/improving-the-developer-experience-our-application-security-journey-part-3-15456.md>)

Original publisher: [Read original article](<https://medium.com/wise-engineering/improving-the-developer-experience-our-application-security-journey-part-3-757e0e6d32e4?source=rss----f2565bbe9c46---4>)

Author: Florian Wirtz

Published: 2023-01-17T11:19:44Z

Content type: article

Language: en

Sources: [Wise Engineering - Medium](<https://devfeed.tech/sources/wise-engineering-medium.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [platform](<https://devfeed.tech/tags/platform.md>), [security](<https://devfeed.tech/tags/security.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This third article in Wise's application security series examines how to improve developers' experience when fixing vulnerabilities. It describes feedback gathered through surveys and interviews, identifying slow dashboards and the need for developers to proactively check them as key pain points.

### Source excerpt

Improving the Developer Experience -- Our Application Security Journey (Part 3) This is the third in a series of articles on the state of Application Security at Wise, describing our integration of security in the Software Development Lifecycle. Photo by Possessed Photography on Unsplash In part three of our blog post series we will be focusing on how we can improve the developers' experience around fixing vulnerabilities. We explore how we identified the main pain points developers were facing, what we did to improve this experience and future improvement ideas that we are planning to work on. Recap: What happened so far? Over the course of the last year we have created our new setup for identifying vulnerabilities at Wise. It's centred around DefectDojo as our vulnerability management tool and we use scanners, such as Trivy for Software Composition Analysis, as inputs. You can learn more about our setup in part one of this blog series. Since then we have also created various dashboards to report vulnerabilities to our stakeholders, and also improved our Service-level agreement (SLA) with our developers to resolve new vulnerabilities. To learn more about that, please read part two of this series. What issues are our developers facing? As a next step, it's important to check in with our developers to see how they're interacting with our program. It's one thing to set up a vulnerability management program, but we also need to make sure that it actually works for our users and that the recommendations provided are actioned in a timely manner. While the initial feedback we received from developers was promising, we decided to share a survey with them to collect more actionable feedback. Our survey had a mix of multiple-choice and free-form questions and was mostly focused on how developers are using our tools and what issues they might be facing with them. We also interviewed them for analogous use cases, including what works well and what doesn't work well in other too