Learn

Learn about software supply chain security and Endor Labs.

Featured resources

Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
Blog

Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec

Jan 23, 2026
How Fake Font Packages Abused npm as a CDN
Blog

How Fake Font Packages Abused npm as a CDN

Jan 23, 2026
Understanding NPM Worms and the Shai-Hulud Attack
Blog

Understanding NPM Worms and the Shai-Hulud Attack

Nov 25, 2025
StackHawk + Endor Labs: Correlating SAST and DAST Alerts
Blog

StackHawk + Endor Labs: Correlating SAST and DAST Alerts

Nov 20, 2025
Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Open Source
SCA
News
Security
Announcing the 2024 Dependency Management Report
Blog

Announcing the 2024 Dependency Management Report

Sep 12, 2024
SCA
Security
Data Management
Tech
Starburst Gets 98.3% Noise Reduction with Endor Labs
Customer Story

Starburst Gets 98.3% Noise Reduction with Endor Labs

Sep 9, 2024
Security
SCA
Developer Productivity
Building a DevSecOps Practice at Starburst
Blog

Under the Hood: Building a DevSecOps Practice at Starburst

Sep 9, 2024
CI/CD
Security
What is CI/CD Security and What Tools Do You Need to Do it?
Blog

What is CI/CD Security and What Tools Do You Need to Do it?

Sep 5, 2024
CI/CD
Security
Blog

PWN Request Threat: A Hidden Danger in GitHub Actions

Sep 3, 2024
SCA
Security
Blog

Address Open Source Risks with Endor Labs

Aug 27, 2024
SCA
Developer Productivity
Blog

Give Devs the Confidence to Fix: Making Remediation Less Painful

Aug 21, 2024
Security
SCA
Blog

Endor Labs Partners with Microsoft to Strengthen Software Supply Chains

Aug 21, 2024
No items found.
Blog

Prioritize Open Source Risks with Endor Labs

Aug 19, 2024
SCA
Security
Blog

Discover Open Source Risks with Endor Labs

Aug 14, 2024
Open Source
SCA
Blog

48 most popular open source tools for npm applications, scored

Aug 9, 2024
SCA
Security
Tech
Developer Productivity
Compare Endor Labs and Snyk GitHub Apps.
Blog

Benchmarking Endor Labs vs. Snyk’s GitHub Apps

Aug 8, 2024
CI/CD
Security
Compliance & SBOM
Blog

Using Artifact Signing to Establish Provenance for SLSA

Aug 8, 2024
SCA
Open Source
Developer Productivity
Fixed is Better than Found | Upgrades & Remediation with Endor Labs
Solution Brief

Fixed is Better than Found | Upgrades & Remediation with Endor Labs

Aug 7, 2024
Developer Productivity
SCA
Video

How to Fix Vulnerabilities Without Breaking Changes

Aug 7, 2024
SCA
Security
News
Developer Productivity
Blog

Introducing Upgrades & Remediation: Give Developers the Confidence to Fix

Aug 7, 2024
Security
SCA
Static SCA vs. Dynamic SCA: Which is Better and Why
Blog

Static SCA vs. Dynamic SCA: Which is Better (and Why It's Neither)

Aug 1, 2024
Open Source
Blog

33 Most Popular Open Source Tools for Maven Applications, Scored

Jul 29, 2024
SCA
Security
Tech
Customer Story

Jellyfish Enables Data-Driven AppSec with Endor Labs

Jul 24, 2024
Security
SCA
Blog

Under the Hood: Jellyfish’s Data-Driven Security Program

Jul 24, 2024
Security
What's a Security Pipeline? - On-Demand Webinar
Video

What's a Security Pipeline? - On-Demand Webinar

Jul 17, 2024

Want to stay in the loop?

Sign up for our newsletter.