Blog

Learn about software supply chain security and Endor Labs

AI-Generated Malware Risk: A Practical Guide for Developers

AI-Generated Malware Risk: A Practical Guide for Developers

Understand ai-generated malware risk and learn how developers can detect malicious packages, stop supply chain attacks, and harden workflows

Heaps of Built-in's: How JavaScript Sandboxes work

Heaps of Built-in's: How JavaScript Sandboxes work

How JavaScript Sandboxes Work

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

Why C Has Always Broken Static Analysis

Why C Has Always Broken Static Analysis

Why C Has Always Broken Static Analysis

Why Endor Labs AI SAST for C finds what other tools miss

Why Endor Labs AI SAST for C finds what other tools miss

Why Endor Labs AI SAST for C finds what other tools miss

Hacking your life with AI can get you hacked

Hacking your life with AI can get you hacked

Hacking your life with AI can get you hacked

When you can't upgrade: open source examples of Endor Patches

When you can't upgrade: open source examples of Endor Patches

When you can't upgrade: open source examples of Endor Patches

What are agentic workflows? A practical guide to building and securing them

What are agentic workflows? A practical guide to building and securing them

Harness engineering: how to make AI coding agents reliable and secure

Harness engineering: how to make AI coding agents reliable and secure

What is an agent harness? The software that turns a model into an agent

What is an agent harness? The software that turns a model into an agent

Why NPM Malware Keeps Reaching for Bun

Why NPM Malware Keeps Reaching for Bun

Why NPM Malware Keeps Reaching for Bun | Supply Chain Security

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.

The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages

Mean Time to Remediate (MTTR): How to Measure It and Cut It

Mean Time to Remediate (MTTR): How to Measure It and Cut It

SCA Remediation: A Complete Guide for AppSec Teams

SCA Remediation: A Complete Guide for AppSec Teams

What Is Reachability Analysis and Why Does It Matter?

What Is Reachability Analysis and Why Does It Matter?

How to Automate Vulnerability Remediation in 2026

How to Automate Vulnerability Remediation in 2026

Automated Dependency Updates Done Right: A Security-First Guide

Automated Dependency Updates Done Right: A Security-First Guide

Agentic Remediation vs. Manual Patching: What Changes When AI Fixes Vulnerabilities

Agentic Remediation vs. Manual Patching: What Changes When AI Fixes Vulnerabilities

How AI Vulnerability Remediation Actually Works in 2026

How AI Vulnerability Remediation Actually Works in 2026

Upgrade Impact Analysis: Patch Without Breaking Your Build

Upgrade Impact Analysis: Patch Without Breaking Your Build

Top Vulnerability Remediation Tools for AppSec Teams in 2026

Top Vulnerability Remediation Tools for AppSec Teams in 2026

What Is Agentic Remediation? The Complete Guide

What Is Agentic Remediation? The Complete Guide

Critical Security Controls for Governing AI Coding Agents

Critical Security Controls for Governing AI Coding Agents

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.