#softwaresupplychain

2025-06-25

You can't secure what you can't see—and traditional SBOMs can't see the connections where tomorrow's vulnerabilities hide.

How SPDX 3.0 transforms software inventory into system risk orchestration 👇

🔗 anchore.com/blog/spdx-3-0-from

#SPDX #SBOM #SoftwareSupplyChain

2025-06-18

The team was busy shipping last week! 🚢 While Grype got some new scanners, Syft got quality-of-life improvements for enterprise users and better SPDX handling. A rising tide lifts all boats!
See what we were up to: anchorecommunity.discourse.gro
#SBOM #OpenSource #SoftwareSupplyChain

2025-06-16

The most successful standards start by doing almost nothing.

HTTP in 1991: Just GET requests
HTTP today: Powers the entire internet

SBOMs in 2024: "Barely valid"
SBOMs in 2030: ?

Sometimes "useless" is a strategy.

anchore.com/blog/the-sbom-para

#SoftwareSupplyChain #SBOM #SPDX

2025-06-10

Kate Stewart spent 14 years building something everyone thinks is useless.

Plot twist: That's exactly why SBOMs will succeed.

The "useless" label isn't a bug—it's the feature that ensures adoption.

Blog on the SBOM paradox: anchore.com/blog/the-sbom-para

#SoftwareSupplyChain #SBOM

2025-06-07

"Which applications use Log4j?"
"How fast can we respond to CVEs?"
"Are we compliant with EU CRA?"

Can your team answer these questions in minutes or days?

SCA + SBOM = Minutes Manual processes = Days/Weeks

anchore.com/sbom/sca-vs-sbom/

#SoftwareSupplyChain #SCA #SBOM

Finite StateFiniteState
2025-06-03

On June 12th, Matt will be joining a panel at IMC's IoT Days Summer Conference to discuss how global manufacturers can operationalize security throughout the software supply chain.

Reserve your spot bigmarker.com/horizon-house-pu

Finite StateFiniteState
2025-05-28

Dario & Tim will be at June 3–5 — no booth, just real convos.

Want to talk SBOMs, IoT security, or CRA prep? Look out for them on the conference floor

2025-05-27

Anchore extends its container security offering with Bring Your Own SBOM support! Anchore SBOM provides a centralized platform for viewing, managing, and analyzing SBOMs, giving organizations comprehensive visibility into their software supply chains. Learn more about how you can identify and mitigate security and compliance risks: anchore.com/news/anchore-relea #SBOM #SoftwareSupplyChain #Anchore

Brian Greenberg :verified:brian_greenberg@infosec.exchange
2025-05-26

🚨 Critical alert for developers & security teams! 🚨

Over 70 malicious npm & VS Code packages have been uncovered, targeting developers by:

🐍 Embedding data- & crypto-stealing scripts
🐱‍💻 Exploiting helper libraries & legitimate-looking extensions
⚡ Using advanced obfuscation, Discord webhooks, & multi-stage payloads
💥 Even sneaking malware through browser extensions + phishing chains

This highlights why software supply chain security is no longer optional — attackers are innovative, patient, and increasingly targeting developers’ environments.

If you use npm, VS Code, or build in Solidity, audit your environments now. Stay ahead with continuous monitoring, threat intelligence, and team awareness.

How is your org strengthening its supply chain defenses?

#Cybersecurity #SoftwareSupplyChain #npm #VSCode #ThreatIntelligence #Malware

thehackernews.com/2025/05/over

2025-05-23

Join our launch webinar on June 4th at 10 AM PT to learn how Anchore SBOM helps you establish visibility & manage risk in your software supply chain. We'll cover importing SBOMs, validating integrity, and addressing vulnerabilities. Register now: go.anchore.com/introducing-anc #SBOM #SoftwareSupplyChain #DevSecOps

Finite StateFiniteState
2025-05-22

As attacks rise, verifying quality is vital to identifying hidden risks, managing 3rd-party dependencies & meeting global compliance standards. Catch up on Beecham Research's webinar to learn what good looks like & why it matters
beecham-research.webinargeek.c

Finite StateFiniteState
2025-05-21

Matt will be on the panel "Security by Design/Default: Breach Defense as Embedded Concept" at 's IoT Days Summer event (June 12th), joining the conversation on how global leaders are embedding resilience into the .

Don't miss it! bigmarker.com/horizon-house-pu

2025-05-21

Announcing Anchore SBOM! Gain comprehensive visibility & transparency into your software supply chain with our new capabilities in Anchore Enterprise. Manage internal and external SBOMs in a single location to track software supply chain issues and meet compliance requirements. Learn more here: #SBOM #SoftwareSupplyChain #Security #Anchore

ActiveStateactivestate
2025-05-14

Open-source vulnerabilities keeping you up at night? 😬 ActiveState’s platform is here to help. From proactive risk prioritization to precision remediation, we make managing open-source security simple, scalable, and effective.

🎥 Watch our latest video to see how we reduce open-source risks: activestate.com/resources/vide

Finite StateFiniteState
2025-05-12

📢 IoT cybersecurity is now a boardroom priority.

Matt joined @BeechamResearch & Aeris to unpack the latest in security—from global regs like EU CRA to why SBOMs & visibility are non-negotiable 👉 finitestate.io/blog/bridging-i

JAVAPROjavapro
2025-05-11

Global software, local laws. Part 4 of Steve Poole’s series dives into export controls liability & compliance in a divided world. Regional hosting, risk audits & readiness matter more than ever.
👉Read: javapro.io/2025/04/10/move-fas

ActiveStateactivestate
2025-05-07

What’s shaping the future of cybersecurity in 2025? ActiveState’s insights from RSA reveal critical trends in open-source security and software supply chain resilience. From compliance to proactive threat mitigation, these takeaways are a must-read for security professionals and developers alike.

🔗 Read the blog: activestate.com/blog/learnings

Colan Schwartzcolanschwartz
2025-05-07

Until these tools learn how to properly trust sources, check them yourself, and ensure their trustworthiness before using them.

I'm wondering if some kind of trust ecosystem could work here, though? It wouldn't be hard for the AIs to verify digital signatures, right?

arstechnica.com/security/2025/

JAVAPROjavapro
2025-05-07

Think EU laws don’t affect you? The Brussels Effect is real – and it’s just the start. Steve Poole reveals why your stack isn't safe anywhere.

👇 Read Part 2 of his series: javapro.io/2025/04/03/move-fas

2025-04-25

Syft v1.23.0 is out! 🎉 Now detecting R packages in directories, JS assets in .NET via libman, Chrome binaries, and undeclared Python licenses. Plus, faster scans by optionally skipping archive extraction!
#SBOM #OpenSource #SoftwareSupplyChain
github.com/anchore/syft/releas

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst