Learn

Learn about software supply chain security and Endor Labs.

Featured resources

A virus-like npm malware attack has spread to 180+ packages so far, including CrowdStrike and Tinycolor.
Blog

npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised

Sep 16, 2025
AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale
Ebook/Report

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale

Apr 23, 2025
Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era
Blog

Introducing the Endor Labs MCP Server: fix-first security for the vibe coding era

Apr 23, 2025
Introducing AI Security Code Review
Blog

Introducing AI Security Code Review

Apr 23, 2025
Topic
Medium
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Compliance & SBOM
SCA
Managing Open Source Vulnerabilities for PCI DSS Compliance- On-Demand Webinar
Video

Managing Open Source Vulnerabilities for PCI DSS Compliance - On-Demand Webinar

Jun 18, 2024
SCA
Open Source
Security
Compliance & SBOM
Container Scanning + SCA = Better Together
Blog

Container Scanning + SCA = Better Together

Jun 11, 2024
News
Blog

Endor Labs Named to Rising in Cyber by CISOs and Venture Capital Investors

Jun 4, 2024
SCA
Open Source
Security
Blog

Evaluating and Scoring OSS Packages

Jun 4, 2024
SCA
Compliance & SBOM
Open Source
Security
Demystifying Transitive Dependency Vulnerabilities
Blog

Demystifying Transitive Dependency Vulnerabilities

May 31, 2024
CI/CD
Security
Open Source
Surprise! Your GitHub Actions Are Dependencies Too
Blog

Surprise! Your GitHub Actions Are Dependencies, Too

May 28, 2024
Compliance & SBOM
SCA
Security
OSS Vulnerabilities and the Digital Operational Resilience Act (DORA)
Blog

OSS Vulnerabilities and the Digital Operational Resilience Act (DORA)

May 21, 2024
SCA
Security
Protect Mobile Apps with Kotlin and Swift SCA
Blog

Protect Mobile Apps with Kotlin and Swift SCA

May 21, 2024
News
Blog

Endor Labs Partners with GuidePoint Security to Secure The Software Supply Chain

May 21, 2024
CI/CD
Compliance & SBOM
SCA
Intro to Endor Labs- On-Demand Webinar
Video

Intro to Endor Labs - On-Demand Webinar

May 15, 2024
SCA
Open Source
Security
 OWASP OSS Risk 1: Known Vulnerabilities, by Camila Odlund and Jenn Gile
Blog

OWASP OSS Risk 1: Known Vulnerabilities

May 14, 2024
CI/CD
Security
Low-Code/No Code Artifact Signing by Diamantis Kourkouzelis
Blog

Low-Code/No Code Artifact Signing

May 7, 2024
Compliance & SBOM
Open Source
SCA
An Auditor’s Perspective on Addressing OSS Vulnerabilities for PCI DSS v4 by Jenn Gile
Blog

An Auditor’s Perspective on Addressing OSS Vulnerabilities for PCI DSS v4

May 2, 2024
CI/CD
Compliance & SBOM
Security
Your Git Repo is a Supply Chain Risk by Darren Meyer
Blog

Your Git Repo is a Supply Chain Risk

Apr 30, 2024
Security
SCA
CI/CD
Compliance & SBOM
Open Source
Guide to Implementing Software Supply Chain Security, What to Consider When Designing a Program
Ebook/Report

Guide to Implementing Software Supply Chain Security

Apr 30, 2024
CI/CD
Security
Improve Kubernetes Security with Signed Artifacts and Admission Controllers by David Archer
Blog

Improve Kubernetes Security with Signed Artifacts and Admission Controllers

Apr 23, 2024
Developer Productivity
Open Source
Opinion
Security
Tech
AppSec Goes to Devnexus: Lessons from a Thriving, Modern Java Community by Darren Meyer
Blog

AppSec Goes to Devnexus: Lessons from a Thriving, Modern Java Community

Apr 16, 2024
CI/CD
Security
Compliance & SBOM
Artifact Signing 101 - On-Demand Webinar
Video

Artifact Signing 101 - On-Demand Webinar

Apr 10, 2024
Security
Open Source
Compliance & SBOM
SCA
XZ Backdoor: How to Prepare for the Next One by Jamie Scott
Blog

XZ Backdoor: How to Prepare for the Next One

Apr 3, 2024
Security
Open Source
Opinion
XZ is A Wake Up Call For Software Security: Here's Why by Dimitri Stiliadis
Blog

XZ is A Wake Up Call For Software Security: Here's Why

Apr 1, 2024
Compliance & SBOM
SSDF Compliance and Attestation by Chris Hughes
Blog

SSDF Compliance and Attestation

Mar 26, 2024
no-results
Sorry, no results matching your search.

Want to stay in the loop?

Sign up for our newsletter.