software supply chain
Google's new open source platform will shield popular dependencies with automations and data visibility tools.
"These emails implored OpenJS to take action to update one of its popular JavaScript projects to ‘address any critical vulnerabilities'"
|
CISA
|
Feb 12, 2024
"Package managers are at a critical point in the open source ecosystem and have the capability to scale security improvements across open source ecosystems"
SolarWinds
|
Oct 31, 2023
SolarWinds’ poor controls... false and misleading statements and omissions, and the other misconduct... would have violated the federal securities laws even if SolarWinds had not experienced a major, targeted cybersecurity attack"