Ebook/Report

Learn about software supply chain security and Endor Labs

Context Engineering for Application Security

Context Engineering for Application Security

The New era of Code-to-Cloud Security

The New era of Code-to-Cloud Security

AI SAST: Combining Agents, Program Analysis, and Rules for High-Confidence Code Security

AI SAST: Combining Agents, Program Analysis, and Rules for High-Confidence Code Security

This whitepaper details Endor Labs' multi-modal approach to AI SAST, leveraging agentic reasoning, program analysis, and advanced rules to eliminate 95% of false positives while surfacing complex logic flaws.

Invisible Threats and the Blind Spots of Security 


Invisible Threats and the Blind Spots of Security 


How GlassWorm Exploited Unicode Shadows in VS Code Supply Chains

State of Dependency Management 2025

State of Dependency Management 2025

AI Coding Agents and Software Supply Chain Risk

A Practical Guide to AI and Application Security

A Practical Guide to AI and Application Security

As AI reshapes software development, security teams can be the catalyst for unlocking productivity without sacrificing safety.

Cracking the Code: Solving the Challenges of C/C++ Software Composition Analysis

Cracking the Code: Solving the Challenges of C/C++ Software Composition Analysis

This whitepaper details Endor Labs’ novel approach to indexing open source dependencies and detecting vulnerabilities in C and C++ codebases.

Endor Labs Policies: Developer-Friendly Security Automation

Endor Labs Policies: Developer-Friendly Security Automation

This whitepaper talks about how Endor Labs uses context-aware security policies, like finding, action, exception, and remediation policies, to reduce noise, improve remediation speed, and help developers focus on real risks.

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale

This whitepaper introduces how AI Security Code Review works, what it detects, how it integrates into your workflows, and why it represents the next generation of code scanning technology — built for the complexity and speed of AI-native software development.

Endor Patches Whitepaper

Endor Patches Whitepaper

When upgrading is too risky, complex, or time consuming due to regressions, breaking changes, or new bugs, you can use Endor Patches to stay safe now while still meeting your SLA requirements.

Dependency Management Report

Dependency Management Report

Endor Labs Brand Guidelines

Endor Labs Brand Guidelines

Guide to Implementing Software Supply Chain Security

Guide to Implementing Software Supply Chain Security

In this free guide, experts answer key questions like "what is it?", "why is it important?", "and how do I secure it?" so you can make informed decisions and thoughtfully design your organization's SSCS program.

State of Dependency Management 2023

State of Dependency Management 2023

Emerging trends impacting open source dependency management in 2023

OWASP Top 10 Risks for Open Source

OWASP Top 10 Risks for Open Source

Emerging trends impacting open source dependency management

State of Dependency Management 2022

State of Dependency Management 2022

In their inaugural report, the Station 9 research team explores the complexities of open source dependencies and the top security considerations for open source adoption at the enterprise.

Book a Demo

Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.