Learn

Learn about software supply chain security and Endor Labs.

Featured resources

A virus-like npm malware attack has spread to 180+ packages so far, including CrowdStrike and Tinycolor.
Blog

npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised

Sep 16, 2025
AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale
Ebook/Report

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale

Apr 23, 2025
Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era
Blog

Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era

Apr 23, 2025
Introducing AI Security Code Review
Blog

Introducing AI Security Code Review

Apr 23, 2025
Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
SCA
Developer Productivity
Blog

Give Devs the Confidence to Fix: Making Remediation Less Painful

Aug 21, 2024
Security
SCA
Blog

Endor Labs Partners with Microsoft to Strengthen Software Supply Chains

Aug 21, 2024
No items found.
Blog

Prioritize Open Source Risks with Endor Labs

Aug 19, 2024
SCA
Security
Blog

Discover Open Source Risks with Endor Labs

Aug 14, 2024
Open Source
SCA
Blog

48 most popular open source tools for npm applications, scored

Aug 9, 2024
SCA
Security
Tech
Developer Productivity
Compare Endor Labs and Snyk GitHub Apps.
Blog

Benchmarking Endor Labs vs. Snyk’s GitHub Apps

Aug 8, 2024
CI/CD
Security
Compliance & SBOM
Blog

Using Artifact Signing to Establish Provenance for SLSA

Aug 8, 2024
SCA
Open Source
Developer Productivity
Fixed is Better than Found | Upgrades & Remediation with Endor Labs
Solution Brief

Fixed is Better than Found | Upgrades & Remediation with Endor Labs

Aug 7, 2024
Developer Productivity
SCA
Video

How to Fix Vulnerabilities Without Breaking Changes

Aug 7, 2024
SCA
Security
News
Developer Productivity
Blog

Introducing Upgrades & Remediation: Give Developers the Confidence to Fix

Aug 7, 2024
Security
SCA
Static SCA vs. Dynamic SCA: Which is Better and Why
Blog

Static SCA vs. Dynamic SCA: Which is Better (and Why It's Neither)

Aug 1, 2024
Open Source
Blog

33 Most Popular Open Source Tools for Maven Applications, Scored

Jul 29, 2024
SCA
Security
Tech
Customer Story

Jellyfish Enables Data-Driven AppSec with Endor Labs

Jul 24, 2024
Security
SCA
Blog

Under the Hood: Jellyfish’s Data-Driven Security Program

Jul 24, 2024
Security
What's a Security Pipeline? - On-Demand Webinar
Video

What's a Security Pipeline? - On-Demand Webinar

Jul 17, 2024
SCA
Open Source
Developer Productivity
CI/CD
Compliance & SBOM
Secure Everything Your Code Depends On | Endor Labs
Solution Brief

Secure Everything Your Code Depends On With Endor Labs

Jul 16, 2024
News
Blog

Endor Labs Receives Strategic Investment from Citi Ventures

Jul 15, 2024
News
We made the Inc. Best Workplaces List for 2024!
Blog

We made the Inc. Best Workplaces List for 2024!

Jul 8, 2024
Security
Open Source
Blog

New CocoaPods CVEs: Swift and Objective-C Supply Chains Are Fragile

Jul 3, 2024
SCA
Security
Questions to Ask Your Software Composition Analysis Vendor
Blog

Questions to Ask Your Software Composition Analysis Vendor

Jun 27, 2024
Security
Developer Productivity
SCA
Backstage and Endor Labs: AppSec in a Dev’s Dream Workspace
Blog

Backstage and Endor Labs: AppSec in a Dev’s Dream Workspace

Jun 18, 2024
no-results
Sorry, no results matching your search.

Want to stay in the loop?

Sign up for our newsletter.