Intelligence and governance in the software supply chain with Endor Labs and Cloudsmith
Blog post from Endor Labs
The intricacies of the software supply chain have increased with the integration of open source, containers, and AI models, creating a complex web of dependencies that heighten security risks. Developers benefit from flexibility in building software but face challenges with expanded attack surfaces and lengthy remediation cycles. Effective management of these risks requires a strategy combining intelligence and control, as demonstrated by Endor Labs and Cloudsmith. Endor Labs provides in-depth analysis for vulnerability remediation, leveraging software mapping, context-aware risk signals, and function-level reachability analysis to guide decision-making. Meanwhile, Cloudsmith acts as a centralized point of control for managing software artifacts, offering automated security, policy management, and resilient delivery. Together, they ensure secure and efficient software development, extending these principles to the AI software supply chain by managing AI/ML models alongside code to maintain governance and security. This collaboration enables engineering teams to reduce vulnerability noise, prioritize risks, and integrate security seamlessly into their workflows, ultimately enhancing the speed and safety of application development.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 1 | 4,488 | 443 | 150 | +34% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.