Learn

Learn about software supply chain security and Endor Labs.

Featured resources

A virus-like npm malware attack has spread to 180+ packages so far, including CrowdStrike and Tinycolor.
Blog

npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised

Sep 16, 2025
AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale
Ebook/Report

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale

Apr 23, 2025
Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era
Blog

Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era

Apr 23, 2025
Introducing AI Security Code Review
Blog

Introducing AI Security Code Review

Apr 23, 2025
Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
First Party Code
Security
CVE-2025-47949 Reveals Flaw in samlify That Opens Door to SAML Single Sign-On Bypass
Blog

CVE-2025-47949 Reveals Flaw in samlify That Opens Door to SAML Single Sign-On Bypass

May 20, 2025
Security
Developer Productivity
Endor Labs Policies: Developer-Friendly Security Automation
Ebook/Report

Endor Labs Policies: Developer-Friendly Security Automation

May 19, 2025
Security
CVE-2025-4641 is Critical, But Likely Unreachable
Blog

CVE-2025-4641 is Critical, But Likely Unreachable

May 16, 2025
Security
Mastering Security Automation: Exception and Remediation Policies
Blog

Mastering Security Automation: Exception and Remediation Policies

May 15, 2025
Open Source
5 Tips for Managing Bazel Dependencies (Without Losing Friends)
Blog

5 Tips for Managing Bazel Dependencies (Without Losing Friends)

May 12, 2025
Security
Blog

Why Security Policies Frustrate Developers (and How We Can Fix Them)

May 6, 2025
Security
Open Source
News
Open Source Gets Political: What The easyjson Debate Misses (and what to do about it)
Blog

Open Source Gets Political: What The easyjson Debate Misses (and what to do about it)

May 5, 2025
News
Why We Raised a $93M Series B (In This Market)
Blog

Why We Raised a $93M Series B (In This Market)

Apr 23, 2025
AI/ML
Security
Secure AI-Generated Code at the Source
Solution Brief

Secure AI-Generated Code at the Source

Apr 23, 2025
AI/ML
Security
AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale
Ebook/Report

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale

Apr 23, 2025
AI/ML
Security
Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era
Blog

Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era

Apr 23, 2025
AI/ML
Security
Introducing AI Security Code Review
Blog

Introducing AI Security Code Review

Apr 23, 2025
AI/ML
News
Meet the application security platform built for the AI era
Blog

Meet the application security platform built for the AI era

Apr 23, 2025
Security
Open Source
Critical RCE Vulnerability in Apache Parquet (CVE-2025-30065) – Advisory and Analysis
Blog

Critical RCE Vulnerability in Apache Parquet (CVE-2025-30065) – Advisory and Analysis

Apr 2, 2025
No items found.
Blog

Reducing Noise and Fixing What Matters

Apr 2, 2025
Open Source
SCA
Security
OWASP OSS Risk 2: Compromise of Legitimate Package
Blog

OWASP OSS Risk 2: Compromise of Legitimate Package

Mar 25, 2025
CI/CD
Open Source
Security
Blast Radius of the tj-actions/changed-files Supply Chain Attack
Blog

Blast Radius of the tj-actions/changed-files Supply Chain Attack

Mar 19, 2025
Open Source
Security
Compliance & SBOM
What You Need to Know About UK Cyber Essentials Certification
Blog

What You Need to Know About UK Cyber Essentials Certification

Mar 18, 2025
CI/CD
Open Source
Security
GitHub Action tj-actions/changed-files supply chain attack: what you need to know
Blog

GitHub Action tj-actions/changed-files supply chain attack: what you need to know

Mar 15, 2025
Security
Application Security Posture Management (ASPM) Explained
Blog

Application Security Posture Management (ASPM) Explained

Mar 11, 2025
Open Source
Security
SCA
How Endor Patches Are Built and Tested
Blog

How Endor Patches Are Built and Tested

Feb 18, 2025
no-results
Sorry, no results matching your search.

Want to stay in the loop?

Sign up for our newsletter.