• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Security»Want open-source security? Focus on app dependencies
Security

Want open-source security? Focus on app dependencies

October 10, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Cybrary confronts the cyberskills gap head on; raises $25M 
Share
Facebook Twitter LinkedIn Pinterest Email

Learn how your company can create applications to automate tasks and generate further efficiencies through low-code/no-code tools on November 9 at the virtual Low-Code/No-Code Summit. Register here.


When it comes to creating applications, most developers have a secret weapon to innovate at pace: open-source software. Research shows that open-source libraries and components make up more than 75% of the code in the average software application, with the average software application depending on more than 500 components. 

While these open-source dependencies are convenient, they also present new vulnerabilities that threat actors can exploit. For instance, injecting malware into a popular open-source project has the potential to affect thousands of downstream users. 

In an attempt to increase enterprise visibility over open-source software components, today Endor Labs came out of stealth with a Dependency Lifecycle Management Platform and $25 million in seed funding.

The new solution provides developers with a tool to evaluate, maintain and update dependencies used for the environment. 

Event

Low-Code/No-Code Summit

Join today’s leading executives at the Low-Code/No-Code Summit virtually on November 9. Register for your free pass today.

Register Here

Moving on from software composition analysis 

The announcement comes as more and more organizations are committing to securing the software supply chain following President Biden’s Executive Order On Improving the Nation’s Cybersecurity. 

The order called for software vendors selling solutions to the government to maintain a software bill of materials (SBOM) and automated vulnerability scanning. Fundamentally, the order recognized that the spiraling complexity of open-source components needed to be addressed to get the threat landscape under control. 

See also  Samsung says a data breach revealed some customers’ names, birthdays, and more

“Eighty percent of the code in modern applications is code your developers didn’t write but depend on through open-source packages. When our founding team was leading the Prisma Cloud engineering group at Palo Alto Networks, we realized the true magnitude of this issue,” said cofounder and CEO, Endor Labs, Varun Badhwar. 

“Having previously created the cloud security posture management (CSPM) category, this team knows how to take on next-generation threats. Our mission is to enable OSS [open-source software] to live up to its true potential without introducing unnecessary risk. It’s exciting to once again take a new approach to the market, and we believe these solutions will radically enhance application development everywhere,” Badhwar said. 

In an era where the U.S. government is calling on enterprises to produce SBOMs and increase the maturity of open-source security, Endor Labs offers a solution to monitor dependencies and increase transparency over how they’re used throughout the organization to build an accurate SBOM. 

Instead of just pointing out insecure dependencies, Endor Labs also enables users to pick dependencies that are less vulnerable to compromise. 

How Endor Labs is competing against the SCA market 

Traditionally, organizations use software composition analysis (SCA) tools to analyze applications and detect open-source software. SCA tools can check the security of the code used in critical applications. Researchers estimated the software composition analysis market would reach $398.4 million by 2022. 

One of the main vendors in this market is Snyk, with Snyk Open Source, a tool for automatically monitoring process and code for vulnerabilities with the assistance of open source vulnerability intelligence, while offering real-time reporting capabilities to support GRC teams. 

See also  What is the key to protecting IoT devices at the network’s edge?  

Snyk most recently raised $530 million as part of a series F funding round in 2021, bringing its total valuation to $8.5 billion. 

Another significant competitor is Synopsys with Black Duck, which combines multifactor open-source detection and a KnowledgeBase of over 4 million components to increase transparency over applications and containers to offer automated vulnerability notifications, reports that detail severity, and more. 

Synopsys recently announced raising $1.25 billion in revenue for Q3 FY 2022. 

However, Badhwar argues that Endor Labs differentiates itself from SCA tools based on its ability to help select secure and high-quality dependencies. Traditional SCA tools offer limited context on how dependencies are used and potential alternatives.

Source link

app dependencies focus opensource security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitdefender Total Security review

March 6, 2024

Avast Premium Security review

March 6, 2024

Eset Home Security Ultimate review

January 23, 2024

AVG Internet Security review

October 31, 2023
Add A Comment

Comments are closed.

Editors Picks

Sky Glass review

February 8, 2023

CIO interview: Carl Dawson, CIO, Asda

July 6, 2022

Sunstar GUM Playbrush review

August 14, 2023

MultiVersus has what it takes to be one of the best free-to-play sport on PlayStation, Xbox, and PC

July 28, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.