Sponsor of the Day:
Jerkmate
https://www.activestate.com/resources/webinars/outsourcing-open-source-pains/
Outsourcing Open Source Supply Chain Security
Nov 21, 2024 - Learn how outsourcing your open source maintenance can reclaim dev resources, keep you up-to-date and ensure software supply chain security.
open source supplychain securityoutsourcing
https://www.activestate.com/resources/press-releases/activestate-partners-with-aquion-to-deliver-comprehensive-open-source-supply-chain-security-to-the-australian-market/
ActiveState & Aquion: Open Source Supply Chain Security for Australia
Apr 24, 2025 - ctiveState partners with Aquion to deliver comprehensive open-source supply chain security solutions to the Australian market. Learn how this partnership...
open source supplychain securityactivestateaquionaustralia
https://www.linux.com/news/understanding-open-source-supply-chain-security/
Understanding Open Source Supply Chain Security - Linux.com
Dec 8, 2021 - Open Source Software supply chain security has become a hot topic recently after an executive order by the Biden administration. We sat down with Chris Wright,...
open source supplychain securityunderstandinglinux
https://www.sonatype.com/press-releases/sonatype-finds-700-average-increase-in-open-source-supply-chain-attacks
Sonatype Finds 700% Rise in Open Source Supply Chain Attacks
Early findings from Sonatype's 8th Software Supply Chain Report reveal a surge in cyberattacks on open source ecosystems.
open source supplychain attackssonatypefinds700
https://opensourcesecuritypodcast.libsyn.com/2026-state-of-the-software-supply-chain-with-brian-fox
Open Source Security: 2026 State of the Software Supply Chain with Brian Fox
Josh chats with Brian Fox from Sonatype about their 2026 State of the Software Supply Chain report. Most of the number continue to grow at alarming rates, but...
open source securitysoftware supply chain2026 statebrianfox
https://www.harness.io:443/resources/software-supply-chain-security-more-than-open-source
Software Supply Chain Security: More Than Open Source
In this OnDemand session, you'll discover why addressing open source vulnerabilities is just the first step in securing your software supply chain. We'll...
software supply chainopen sourcesecurity
https://openssf.org/groups/supply-chain-integrity/
Supply Chain Integrity – Open Source Security Foundation
supply chain integrityopen source securityfoundation
https://safedep.io/malicious-forge-jsx-npm-rat/
forge-jsx npm Package: Purpose-Built Multi-Platform RAT - Real-time Open Source Software Supply...
forge-jsx poses as an Autodesk Forge SDK on npm. On install it deploys a system-wide keylogger, recursive .env file scanner, shell history exfiltrator, and a...
real time opensource software supplynpm packagepurpose builtmulti platform
https://www.securitynewspaper.com/2025/07/23/how-to-use-googles-oss-rebuild-a-new-open-source-software-supply-chain-security-tool/
How to Use Google’s OSS Rebuild: A New Open Source Software Supply Chain Security Tool –...
new open sourcesoftware supply chainsecurity tooluseoss
https://app.safedep.io/auth
SafeDep | Open Source Software Supply Chain Security Platform
Welcome to SafeDep. Onboard to SafeDep cloud, generate authentication credentials and access platform APIs
open source softwaresupply chain securitysafedepplatform
https://opensource.com/article/21/7/open-source-news
Open source sustainable cities, AI on Arduino, supply chain security, and more | Opensource.com
Open source made it into a lot of news headlines last month. Read on to learn about some of the major advances.
supply chain securityopen sourcesustainable citiesarduinoopensource