#SoftwareSupplyChainSecurity

Finite StateFiniteState
2025-05-20

We're honored to be featured in Omdia’s latest report spotlighting the leaders in firmware & πŸŽ‰

Read the full report to explore what sets us apart πŸ‘‰ omdia.tech.informa.com/om12971

Colan Schwartzcolanschwartz
2025-05-07

Until these tools learn how to properly trust sources, check them yourself, and ensure their trustworthiness before using them.

I'm wondering if some kind of trust ecosystem could work here, though? It wouldn't be hard for the AIs to verify digital signatures, right?

arstechnica.com/security/2025/

Finite StateFiniteState
2025-04-10

Finite State is heading to πŸŽ‰

The team will be in the AppSec village, discussing the latest in software supply chain security, & sharing insights on , vuln management, & compliance.

Attending? Drop by and say hi! πŸ‘‹

Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2025-03-27

#NPM: Two malicious packages were discovered on npm (#NodeJS package manager) that covertly patch legitimate, locally installed packages to inject a persistent reverse shell backdoor:
#SoftwareSupplyChainSecurity
πŸ‘‡
bleepingcomputer.com/news/secu

Beth Pariseau @ #RHSummitBPariseau@hachyderm.io
2025-03-17
Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2025-03-17

#PyPI: 20 Malicious Python PyPI Packages Stole Cloud Tokens - Over 14,100 Downloads Before Removal:
#SoftwareSupplyChainSecurity
πŸ‘‡
thehackernews.com/2025/03/mali

Sam Stepanyan :verified: 🐘securestep9@infosec.exchange
2025-03-16

⚠️#GitHub: Critical security incident involving the popular tj-actions/changed-files GitHub Action which contained credentials/secrets exfiltration malware! ☣️ (CVE-2025-30066)
#SoftwareSupplyChainSecurity
#tjactions
πŸ‘‡
stepsecurity.io/blog/harden-ru

2025-03-06

Complex SBOM integration? Anchore Enterprise makes it effortless with automation, compliance, and developer-friendly tools.

Read our blog: anchore.com/blog/effortless-sb

#SBOM #DevSecOps #SoftwareSupplyChainSecurity

2025-03-01

Secure your software supply chain effortlessly. Anchore Enterprise streamlines SBOM analysis with easy integration and robust automation.

Dive in: anchore.com/blog/effortless-sb

#SBOM #DevSecOps #SoftwareSupplyChainSecurity

2025-02-26

Simplify your SBOM analysis with Anchore Enterprise! Automate security checks & integrate seamlessly with CI/CD pipelines.

Learn more: anchore.com/blog/effortless-sb

#SBOM #DevSecOps #SoftwareSupplyChainSecurity

Beth Pariseau @ #RHSummitBPariseau@hachyderm.io
2025-02-20
2025-02-14

πŸ”Ž Is your organization prepared for DORA compliance?

Learn how SBOMs and Anchore Enterprise make proactive risk management and supply chain security easier.

#dora #sbom #compliance #softwaresupplychainsecurity

2025-02-13

Ready to secure your software supply chain? Our free ebook, SBOM 101, covers everything from SBOM fundamentals to integration in DevSecOps pipelines. Explore, learn, and contribute today:

πŸ‘‰ anchore.com/blog/sboms-101-a-f

#SBOM #OpenSource #SoftwareSupplyChainSecurity

2025-02-12

🌐 Curious about DORA and how it reshapes software supply chain security?

Find out how SBOMs are the cornerstone of compliance for financial institutions: anchore.com/blog/dora-overview

#dora #sbom #compliance #softwaresupplychainsecurity

2025-02-10

SBOM sprawl blocking your security gains? Discover how to centralize and operationalize SBOMs for faster zero-day response and better compliance.

Read more: anchore.com/blog/sbom-manageme

#SBOM #SoftwareSupplyChainSecurity #SBOMManagement

2025-02-10

Now on AWS Marketplace: @anchore Enterprise! πŸ›’ Streamline your #DevSecOps with advanced container scanning and policy enforcement. More info: aws.amazon.com/marketplace/pp/ #ContainerSecurity #SoftwareSupplyChainSecurity

2025-02-07

Fighting SBOM sprawl? Discover how to store, enrich & query SBOMs effortlessly. Our new blog breaks down the essentials of SBOMOps + a peek at Anchore Enterprise.

Read on: anchore.com/blog/sbom-manageme

#SBOM #SoftwareSupplyChainSecurity #SBOMManagement

2025-02-07

πŸš€ Announcing SBOM 101 – a free, open-source ebook for developers, security engineers, & the DevSecOps community! Master SBOM best practices and secure your software supply chain.

πŸ‘‰ anchore.com/blog/sboms-101-a-f

#SBOM #OpenSource #SoftwareSupplyChainSecurity

Finite StateFiniteState
2025-02-06

Gartner’s "Leader’s Guide to Software Supply Chain Security" breaks down a proven framework to help organizations strengthen security across the supply chain. Download your free copy today: πŸ‘‰

info.finitestate.io/gartner-le

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst