July 2024 Summaries
9 posts from Endor Labs
Filter
Month:
Year:
Post Summaries
Back to Blog
Choosing quality open-source software (OSS) dependencies is crucial for applications, particularly those built with Maven, as they often rely heavily on open-source components. Endor Labs facilitates this by offering a public summary of commonly used open-source tools along with Endor Scores, which evaluate packages based on security, activity, popularity, and code quality. These scores, ranging from 0 to 10, provide insight into how well a package adheres to best practices, with higher scores indicating better performance in these areas. Key categories include logging, JSON processing, Spring Framework components, general utilities, networking, bytecode manipulation, data binding and serialization, and reactive programming. Tools like SLF4J, Logback, Jackson, and Spring Core are highlighted for their respective functionalities and popularity. Endor Labs' DroidGPT feature allows users to research OSS packages conversationally, using the combined capabilities of ChatGPT and Endor Labs' proprietary risk data to provide instant answers and risk assessments for different packages.
Jul 29, 2024
3,570 words in the original blog post.
Endor Labs announced its participation in BlackHat 2026 in Las Vegas, inviting attendees to learn more about their offerings. The announcement includes a prompt for users to accept cookies, which facilitate enhanced site navigation, site usage analysis, and marketing efforts. The information is part of a broader communication strategy that includes details about their Partner Program, authored by Ron Harnik, and published in July 2024 with an update in August 2025. The text emphasizes the importance of cookies in improving user experience and directs users to their Privacy Policy for further details.
Jul 24, 2024
77 words in the original blog post.
Jellyfish, an engineering management platform, transitioned from using Snyk to Endor Labs to enhance their application security (AppSec) by better identifying and prioritizing open source risks. The previous tool, Snyk, presented challenges such as inaccurate risk modeling and operational inefficiencies, particularly in assessing reachability and aligning with Jellyfish's data-driven security approach. Endor Labs met Jellyfish's requirements by providing accurate risk prioritization, seamless integration into workflows, and support for generating Software Bill of Materials (SBOMs) in standard formats. This switch enabled Jellyfish to confidently prioritize and remediate risks, improve their risk models, and streamline workflows without complicating developers' tasks, ultimately allowing them to focus on evolving their product and platform.
Jul 24, 2024
923 words in the original blog post.
The blog post by Jellyfish security team members James Kirk and Josiah Bruner discusses the establishment and evolution of Jellyfish's security team, highlighting their unique approach to integrating security into the software development lifecycle. At Jellyfish, security is embraced not as a regulatory burden but as an integral part of product development, thanks to a pre-existing culture of "shift left" security. The company utilizes data-driven methods to measure and predict security effectiveness, focusing on swift incident response and risk management rather than merely counting vulnerabilities. The post also details their journey to find a suitable software composition analysis (SCA) tool, culminating in their adoption of Endor Labs due to its function-level reachability and efficient risk prioritization capabilities. This tool has significantly improved their ability to accurately assess and mitigate risks, allowing them to confidently report security status to executives and the board. Additionally, Jellyfish's security team works closely with developers to prevent the introduction of new risks, using policies to manage dependencies effectively. Overall, the post emphasizes a collaborative and proactive approach to security, treating it as an equal partner in engineering efforts.
Jul 24, 2024
2,175 words in the original blog post.
In an increasingly complex and costly environment for managing CI/CD pipelines within the software development lifecycle (SDLC), particularly for Application Security (AppSec) and Production Security (ProdSec) teams, an emerging solution is the creation of independent security pipelines dedicated to executing security tasks. An on-demand webinar introduces this concept, discussing common patterns and trade-offs associated with implementing security pipelines. Additionally, Endor Labs offers solutions such as JavaScript SCA capabilities that surpass traditional manifest scanning tools, and Endor Patches, which provide a safe alternative to upgrading in the presence of potential regressions or new bugs. These innovations aim to enhance security and maintain compliance with Service Level Agreements (SLAs) while addressing key vulnerabilities in the open-source software supply chain.
Jul 17, 2024
241 words in the original blog post.
Endor Labs, a company focused on advancing Software Composition Analysis (SCA), aims to provide more than just problem identification by offering solutions through program analysis at the time of build. This approach allows for an accurate inventory of software and reduces alert noise by determining function-level reachability, thereby speeding up remediation processes. Trusted by companies like OpenAI, Peloton, and Robinhood, Endor Labs significantly cuts through the noise of false positives that conventional tools generate, enabling AppSec teams to address real risks swiftly. The platform has demonstrated substantial improvements, such as a 99.97% noise reduction and saving one million developer hours, by offering better visibility and prioritization of third-party library vulnerabilities, thus transforming application security practices for its clients.
Jul 16, 2024
302 words in the original blog post.
Endor Labs, a company specializing in software supply chain security, has announced a strategic investment from Citi Ventures, following its previous $70 million Series A funding. Founded in 2022 by Varun Badhwar and Dimitri Stiliadis, Endor Labs addresses the often-overlooked risks in application security that arise from dependencies such as open source software and CI/CD pipeline tools. Their platform prioritizes critical vulnerabilities, reducing noise by over 90%, and integrates seamlessly into developer workflows, which has attracted attention from Fortune 500 companies and large financial institutions. Citi's investment highlights the growing importance of software supply chain security as a board-level concern and reflects the potential of Endor Labs' technological innovations, such as reachability analysis, to significantly enhance developer productivity and security efforts. The company has been recognized in various industry accolades and offers a comprehensive approach to compliance with global standards, ensuring the authenticity and security of software artifacts through features like artifact signing.
Jul 15, 2024
880 words in the original blog post.
Endor Labs has been recognized on Inc.’s 2024 Best Workplaces list, a testament to its commitment to fostering a collaborative and innovative work environment, particularly within a hybrid model. The company attributes this achievement to its employees' passion and dedication, supported by a feedback process facilitated by Quantum Workplace that helps identify areas for improvement. Notable achievements over the past year include hosting a company offsite in Greece, being named one of the top cybersecurity companies to watch at RSA, and receiving recognition in Times Square, highlighting its influence in the cybersecurity sector. The company expresses gratitude to its customers and partners, whose collaboration has been integral to its success, and is actively expanding its team across various departments to continue building a supportive and empowering workplace.
Jul 08, 2024
661 words in the original blog post.
The report highlights three newly-discovered vulnerabilities in CocoaPods, a widely-used package manager for macOS and iOS development, raising concerns about software supply chain security. The vulnerabilities, identified as CVE-2024-38368, CVE-2024-38367, and CVE-2024-38366, involve potential unauthorized claiming of unowned Pods, email validation bypass leading to account takeovers, and remote code execution on CocoaPods servers, respectively. Although these issues have been patched, there remains uncertainty about whether adversaries exploited them, potentially affecting Swift and Objective-C applications. The report underscores the importance of a collaborative approach to software supply chain security, stressing the need for continuous monitoring, accurate software inventories, and proactive risk management, while acknowledging the role of vulnerable open-source components and the responsibility of both developers and organizations in maintaining security.
Jul 03, 2024
1,065 words in the original blog post.