Search Results
Learn about software supply chain security and Endor Labs

CVE-2025-54313: eslint-config-prettier Compromise — High Severity but Windows-Only
CVE-2025-54313 tracks a supply chain attack on eslint-config-prettier, where four malicious versions of a popular npm library targeted Windows machines with a remote-code execution payload. Learn how it happened and how to stay safe.

AI Security Code Review: A Multi-Agent Approach for Detecting Security Design Flaws at Scale
This whitepaper introduces how AI Security Code Review works, what it detects, how it integrates into your workflows, and why it represents the next generation of code scanning technology — built for the complexity and speed of AI-native software development.

FedRAMP Requirements for Vulnerability Management and Dependency Upgrades
This blog covers key steps to simplify FedRAMP vulnerability management, helping you reduce risks and meet compliance timelines. It also provides practical tips to empower developers and streamline fixes for a smoother FedRAMP process.
Book a Demo
Protect your open source dependencies, secrets, and CI/CD pipelines without slowing down devs.