Blog

Learn about software supply chain security and Endor Labs

The Secure Agentic Development Lifecycle (ADLC), Explained

The Secure Agentic Development Lifecycle (ADLC), Explained

Agentic Development Security: How to Secure Code Your Agents Write

Agentic Development Security: How to Secure Code Your Agents Write

Hooks are the control plane for the agentic development lifecycle

Hooks are the control plane for the agentic development lifecycle

Hooks are the control plane for the agentic development lifecycle

The real test of AI-native code analysis: is your security debt shrinking?

The real test of AI-native code analysis: is your security debt shrinking?

The real test of AI-native code analysis: is your security debt shrinking?

Mini Shai-Hulud worm hits openapi-react-query-codegen, spreads across npm, RubyGems, and PyPI

Mini Shai-Hulud worm hits openapi-react-query-codegen, spreads across npm, RubyGems, and PyPI

FedRAMP 2026 vulnerability rules make reachability a requirement

FedRAMP 2026 vulnerability rules make reachability a requirement

FedRAMP 2026 vulnerability rules make reachability a requirement

Customer Zero: Implementing Package Firewall at Endor Labs

Customer Zero: Implementing Package Firewall at Endor Labs

Customer Zero: Implementing Package Firewall at Endor Labs

Heaps of Built-in's: How JavaScript Sandboxes work

Heaps of Built-in's: How JavaScript Sandboxes work

How JavaScript Sandboxes Work

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm

Why C Has Always Broken Static Analysis

Why C Has Always Broken Static Analysis

Why C Has Always Broken Static Analysis

Why Endor Labs AI SAST for C finds what other tools miss

Why Endor Labs AI SAST for C finds what other tools miss

Why Endor Labs AI SAST for C finds what other tools miss

Hacking your life with AI can get you hacked

Hacking your life with AI can get you hacked

Hacking your life with AI can get you hacked

When you can't upgrade: open source examples of Endor Patches

When you can't upgrade: open source examples of Endor Patches

When you can't upgrade: open source examples of Endor Patches

What are agentic workflows? A practical guide to building and securing them

What are agentic workflows? A practical guide to building and securing them

Harness engineering: how to make AI coding agents reliable and secure

Harness engineering: how to make AI coding agents reliable and secure

What is an agent harness? The software that turns a model into an agent

What is an agent harness? The software that turns a model into an agent

Why NPM Malware Keeps Reaching for Bun

Why NPM Malware Keeps Reaching for Bun

Why NPM Malware Keeps Reaching for Bun | Supply Chain Security

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

Best in Class, Novel in Method: Opus 5 and the Recall-Then-Diverge Pattern

The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.

The Registry Just Became a Checkpoint. It Still Isn't Your Perimeter.

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages

NPM Malware Compromises keyv and cacheable with 500M+ Weekly Downloads and Spreads to Hundreds of Packages

Mean Time to Remediate (MTTR): How to Measure It and Cut It

Mean Time to Remediate (MTTR): How to Measure It and Cut It

SCA Remediation: A Complete Guide for AppSec Teams

SCA Remediation: A Complete Guide for AppSec Teams

What Is Reachability Analysis and Why Does It Matter?

What Is Reachability Analysis and Why Does It Matter?

How to Automate Vulnerability Remediation in 2026

How to Automate Vulnerability Remediation in 2026

Automated Dependency Updates Done Right: A Security-First Guide

Automated Dependency Updates Done Right: A Security-First Guide

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.