March 2023 Summaries
4 posts from Endor Labs
Filter
Month:
Year:
Post Summaries
Back to Blog
Endor Labs, a Dependency Lifecycle Management Platform, has been selected as one of the ten finalists for the RSA Conference 2023 Innovation Sandbox contest, recognized for its innovative approach to managing open source risk through reachability analysis. The company, co-founded by Varun Badhwar and Dimitri Stiliadis, aims to optimize the adoption of open source software by enabling security and development teams to manage dependencies effectively, thereby reducing vulnerabilities and enhancing productivity. At the RSA Conference in San Francisco, Endor Labs will present its technology to a panel of industry judges, highlighting its capabilities in reducing security alerts and optimizing application security by managing the entire lifecycle of open source dependencies. The RSA Conference Innovation Sandbox has a history of propelling emerging cybersecurity companies to success, with past finalists achieving significant investments and acquisitions. The event serves as a platform for showcasing groundbreaking cybersecurity technologies and fostering discussions on evolving challenges and solutions in the industry.
Mar 22, 2023
845 words in the original blog post.
Endor Labs has announced the launch of Endor Labs Hyperdrive, a global partner program aimed at enhancing supply chain security and dependency lifecycle management for open source software (OSS). The initiative is designed to address the security challenges associated with the extensive use of OSS, which comprises over 80% of modern application code, and the vulnerabilities often found in 'transitive' dependencies. By collaborating with partners such as CleverBits and Grant Thornton, the program enhances the ability to manage OSS risks, maximize productivity, and provide comprehensive visibility of software dependencies. Hyperdrive leverages Endor Labs' Dependency Lifecycle Management platform to enable secure OSS adoption and management, offering partners competitive advantages in risk management and compliance. The program is available globally and is supported by significant investments from Lightspeed Venture Partners and Dell Technologies Capital, alongside endorsements from industry leaders.
Mar 16, 2023
923 words in the original blog post.
Endor Labs has announced a partnership with Zinfinity to facilitate the safe adoption of Open Source Software (OSS) for enterprises, following a $25 million seed funding round led by prominent investors such as Lightspeed Venture Partners and Dell Technology Capital. The collaboration aims to address the significant challenges posed by the reliance on OSS in modern applications, where a substantial portion of code comes from external packages. Endor Labs, co-founded by Varun Badhwar and Dimitri Stiliadis, offers a Dependency Lifecycle Managementâ„¢ Solution that helps organizations securely manage and utilize OSS, optimizing software reuse and enhancing development efficiency. Zinfinity, a global technology solutions provider with expertise in cybersecurity and digital infrastructure, complements this mission by leveraging technology to transform business visions into reality. The partnership underscores the importance of balancing speed and security in the competitive landscape of software development.
Mar 06, 2023
440 words in the original blog post.
Despite the widespread use of open-source software (OSS) in the software supply chain, the industry struggles with a lack of consistent risk assessment methods for OSS, which started with license management and evolved to Common Vulnerabilities and Exposures (CVEs) but still lacks a comprehensive approach. This document aims to address this gap by collaborating with industry experts to create a holistic risk management strategy that includes security, legal, and application resiliency aspects. Although CVEs are a key metric for known vulnerabilities, they do not capture the full spectrum of risks, such as operational risks from outdated software or sophisticated supply chain attacks. A recent study highlighted that a significant portion of codebases contains outdated OSS, and most vulnerabilities are found in transitive dependencies. The report identifies top risks, including known vulnerabilities, name confusion attacks, unmaintained software, and untracked dependencies, and provides detailed examples and mitigation tactics. The dependency management overview explains how direct and transitive dependencies are handled, emphasizing the high degree of automation in modern software development, which has led to a significant reliance on generic open-source projects. This reliance poses security and operational risks, emphasizing the need for improved OSS risk management.
Mar 01, 2023
1,100 words in the original blog post.