Blog

Learn about software supply chain security and Endor Labs

Agentic Remediation vs. Manual Patching: What Changes When AI Fixes Vulnerabilities

Agentic Remediation vs. Manual Patching: What Changes When AI Fixes Vulnerabilities

How AI Vulnerability Remediation Actually Works in 2026

How AI Vulnerability Remediation Actually Works in 2026

Upgrade Impact Analysis: Patch Without Breaking Your Build

Upgrade Impact Analysis: Patch Without Breaking Your Build

Top Vulnerability Remediation Tools for AppSec Teams in 2026

Top Vulnerability Remediation Tools for AppSec Teams in 2026

What Is Agentic Remediation? The Complete Guide

What Is Agentic Remediation? The Complete Guide

Critical Security Controls for Governing AI Coding Agents

Critical Security Controls for Governing AI Coding Agents

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

Endor Labs Recognized by Gartner® in the 2026 Hype Cycle™ for Application Security

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

The OpenAI and Hugging Face security incident: why AI agents need deterministic guardrails

Beyond MCP: The New Security Playbook for Coding Agents

Beyond MCP: The New Security Playbook for Coding Agents

Beyond MCP: The New Security Playbook for Coding Agents

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix

How Unprotected Release Branches Let Attackers Compromise AsyncAPI

How Unprotected Release Branches Let Attackers Compromise AsyncAPI

Everyone Wins Their Own Benchmark

Everyone Wins Their Own Benchmark

Everyone Wins Their Own Benchmark

Securing Open Source Dependencies: A Developer's Guide

Securing Open Source Dependencies: A Developer's Guide

Securing Open Source Dependencies: A Developer's Guide

Dependency Confusion: How Attackers Poison Your Build

Dependency Confusion: How Attackers Poison Your Build

Dependency Confusion: How Attackers Poison Your Build

AI-Generated Malware and the Software Supply Chain

AI-Generated Malware and the Software Supply Chain

AI-Generated Malware and the Software Supply Chain

When AI Imports Vulnerable Dependencies: Securing AI-Generated Code

When AI Imports Vulnerable Dependencies: Securing AI-Generated Code

When AI Imports Vulnerable Dependencies: Securing AI-Generated Code

Slopsquatting: When AI Agents Hallucinate Malicious Packages

Slopsquatting: When AI Agents Hallucinate Malicious Packages

Slopsquatting: When AI Agents Hallucinate Malicious Packages

Veiled in Trust: Software Supply Chain Attacks Explained

Veiled in Trust: Software Supply Chain Attacks Explained

Veiled in Trust: Software Supply Chain Attacks Explained

What Is Malicious Code? Types, Examples & How to Protect Yourself

What Is Malicious Code? Types, Examples & How to Protect Yourself

What Is Malicious Code? Types, Examples & How to Protect Yourself

Best SBOM Tools in 2026, Compared

Best SBOM Tools in 2026, Compared

Best SBOM Tools in 2026, Compared

What Is a Software Bill of Materials? A Practical Guide

What Is a Software Bill of Materials? A Practical Guide

What Is a Software Bill of Materials? A Practical Guide

What Is Software Supply Chain Security? The Complete Guide

What Is Software Supply Chain Security? The Complete Guide

What Is Software Supply Chain Security? The Complete Guide

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Sonnet 5 vs Fable 5: reliable versus security-forward, not better versus worse

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Claude Sonnet 5 with Cursor: strong reasoning, throttled by the harness

Cyber insurers are pricing based on patching speed

Cyber insurers are pricing based on patching speed

Cyber insurers are pricing based on patching speed

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.