Spike Curtis, principal engineer for Coder Technologies, dives into why open source software security concerns are valid, and why the only viable option is to invest more in securing software […]
Life After Death, HeroDevs Acquires Xeol To Remediate Unsupported Software Zombies
Xeol tracks end-of-life data in 100,000+ open-source software packages to help identify and remediate unsupported software in one streamlined workflow.
Endor Labs Forks Semgrep to Opengrep for Static Code Analysis
Software application development lifecycle (SDLC) analysis company Endor Labs has worked with a cadre of industry partners to now launch Opengrep, a toolset designed to ensure static software application code analysis remains open and accessible.
Software Dev Culture Shock: “I Have to Do WHAT Now!?”
Software bills of materials (SBOMs) have sparked a real culture shock in developer teams that are being made to account for – and be scrutinized over – the minute decisions they make in the development of software.
Best of 2024: Valkey is Rapidly Overtaking Redis
Redis is taking it in the chops, as both maintainers and customers move to the Valkey Redis fork.
Perforce Forks Puppet, Community Considers Muppet
DevOps platform company Perforce is forking Puppet, the open-source configuration management technology it acquired in May 2022.
Report Shines Spotlight on Open Source Software Security Challenges
An analysis of more than five million open-source software packages published by Lineaje, a provider of a platform for tracking open-source software components, finds 95% of security issues involve some type of open-source software package dependency, with more than half (51%) of the vulnerabilities discovered having no known existing fix available.
Code Busters: Are Ghost Engineers Haunting DevOps Productivity?
A study coming out of Stanford University conducted by software engineering productivity specialist Yegor Denisov-Blanch claims that developer teams are rife with so-called ghost engineers who do virtually no work.
Sonatype Report Surfaces Software Supply Chain Security Challenges
Sonatype today during a virtual All-Day DevOps (ADD) event shared the results of a report that finds there has been a 156% increase in the number of malicious open source packages year-over-year, reaching more than 512,847 for a 156% increase in the past year.
Survey Finds Compensation Drives Better Open Source Software Security Behavior
A survey of 400 maintainers of open-source software projects suggests IT organizations should be paying a lot more attention to the degree to which the stewards of these projects are compensated before downloading software components.
- « Previous Page
- 1
- 2
- 3
- 4
- 5
- 6
- …
- 49
- Next Page »











