Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Introducing CI/CD Security with Endor Labs

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Ron Harnik
Word Count
1,161
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs has expanded its Software Supply Chain Security (SSCS) platform to include CI/CD security, aiming to protect both open-source code and CI/CD pipelines by integrating automation and continuous monitoring into the software development lifecycle. CI/CD security, also known as Software Pipeline Security, addresses the vulnerabilities in automated pipelines that can be exploited by malicious actors, thereby compromising software integrity, confidentiality, and availability. This security measure involves a series of safeguards incorporated into the building, testing, and deployment phases to ensure the secure delivery of high-quality code without sacrificing development speed. The platform tackles challenges such as shadow engineering, security coverage, and compliance, with tools like Security Composition Analysis (SCA), Static Application Security Testing (SAST), and Infrastructure-as-Code (IaC) scans. Endor Labs focuses on pipeline discovery, repository security posture management, and build integrity verification, emphasizing that effective code and pipeline security are interdependent. The platform's approach aims to prevent supply chain attacks similar to the SolarWinds and CodeCov breaches by enhancing visibility and ensuring rigorous compliance with industry standards.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.