Blog

Learn about software supply chain security and Endor Labs

Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack

Tensorlake npm package compromised by Shai-Hulud in latest software supply chain attack

Endor Labs + SpaceXAI: Securing every stage of agentic software delivery

Endor Labs + SpaceXAI: Securing every stage of agentic software delivery

Endor Labs + SpaceXAI: Building the security foundation for agentic coding

What does it mean to sandbox an AI coding agent?

What does it mean to sandbox an AI coding agent?

A compromised release of the nx build package shipped a post-install script that did something the industry had not seen before.

GPT-6.1 Sol on Codex: Astra-level security, a third faster, zero cheating

GPT-6.1 Sol on Codex: Astra-level security, a third faster, zero cheating

Nine days after GPT-6 Sol, Codex with GPT-6.1 Sol scores 77.7% FuncPass and 34.1% SecPass — within one task of GPT-6 Astra on security, a third faster, and with zero confirmed cheating.

Sandboxes: A Primer on Containing Things That Don't Want to Be Contained

Sandboxes: A Primer on Containing Things That Don't Want to Be Contained

Sandboxes Explained: What Each Type Actually Isolates

GPT-6 Sol on Codex: average scores, quarter the cost

GPT-6 Sol on Codex: average scores, quarter the cost

Codex with GPT-6 Sol scores 72.1% FuncPass and 25.1% SecPass for $104 on Azure — 78% cheaper than Astra ($468) — with zero confirmed cheating.

Endor Labs Featured in Gartner Research on Claude Code Permissions and Agent Governance

Endor Labs Featured in Gartner Research on Claude Code Permissions and Agent Governance

Endor Labs was recently featured in the Gartner® report First Take: Claude Code Is Defaulting to Automated Permissions — Update Your Governance Controls, published August 24, 2026. The report examines an important change in how Claude Code handles permissions and the broader governance implications as coding agents take more actions without requiring a developer to approve each one.

Project-Mount Symlink Traversal in brig: How a Sandbox Reaches Host Directories It Was Never Given

Project-Mount Symlink Traversal in brig: How a Sandbox Reaches Host Directories It Was Never Given

Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure

Opus 5.5: 6x cheaper and 2x faster than Fable 5.1, but only 33.5% of code is secure

Claude Code with Opus 5.5 finishes coding tasks in a median of 2.2 minutes for $116 in total, the fastest run on our board and the cheapest Anthropic run by far, but lands at only 33.5% for secure code.

Engineering a security harness for AI coding agents

Engineering a security harness for AI coding agents

Engineering a security harness for AI coding agents

The first part of the EU Cyber Resiliency Act comes into effect on September 11th. Are you ready?

The first part of the EU Cyber Resiliency Act comes into effect on September 11th. Are you ready?

The first part of the EU Cyber Resiliency Act comes into effect on September 11th. Are you Ready?

Introducing Threat Center and Package Firewall for VS Code Extensions: Malware Protection From the Registry to the Developer Workstation

Introducing Threat Center and Package Firewall for VS Code Extensions: Malware Protection From the Registry to the Developer Workstation

Threat Center and Package Firewall for VS Code Extensions

Better models are making agent patch review more expensive, not less

Better models are making agent patch review more expensive, not less

Agent fixes got 47% cheaper to generate. Review still costs ten times more.

GPT-6 Astra on Codex - the Biggest Codex Leap to Date

GPT-6 Astra on Codex - the Biggest Codex Leap to Date

GPT-6 Astra on Codex - the Biggest Codex Leap to Date

How Endor Labs AI SAST Learns What Matters to Your Organization

How Endor Labs AI SAST Learns What Matters to Your Organization

How Endor Labs AI SAST Learns What Matters to Your Organization

AI-Generated Malware Risk: A Practical Guide for Developers

AI-Generated Malware Risk: A Practical Guide for Developers

Understand ai-generated malware risk and learn how developers can detect malicious packages, stop supply chain attacks, and harden workflows

From SDLC to ADLC: why application security needs coding agent governance

From SDLC to ADLC: why application security needs coding agent governance

From SDLC to ADLC: why application security needs coding agent governance

Prompt Injection Against Coding Agents: The Attack Surface Nobody Owns

Prompt Injection Against Coding Agents: The Attack Surface Nobody Owns

Hallucinated Packages: How AI Invents Dependencies Attackers Exploit

Hallucinated Packages: How AI Invents Dependencies Attackers Exploit

Secrets in AI-Generated Code: How Coding Agents Leak Credentials

Secrets in AI-Generated Code: How Coding Agents Leak Credentials

Application Security Monitoring for AI-Assisted Development

Application Security Monitoring for AI-Assisted Development

How to Secure AI-Generated Code:  A Developer's Workflow

How to Secure AI-Generated Code: A Developer's Workflow

Prompt Patterns That Make Coding Agents Write Safer Code

Prompt Patterns That Make Coding Agents Write Safer Code

SAST for AI-Generated Code: What Static Analysis Catches and Misses

SAST for AI-Generated Code: What Static Analysis Catches and Misses

AI Code Review: How to Actually Review Code an Agent Wrote

AI Code Review: How to Actually Review Code an Agent Wrote

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.