Visualize Your Open Source Governance With BOM Doctor

5 minute read time

Discover BOM Doctor, a free tool that simplifies open source dependency management with world-class research insights and powerful visualizations.
Read More...

Sonatype's SBOM Generation Capabilities Outpace the Competition

By Audra Davis-Hurst on March 22, 2023 Nexus Lifecycle

9 minute read time

Better data, a dedicated security team, and the analytical capabilities of BOM Doctor are all part of what makes Sonatype's SBOM capabilities superior.
Read More...

Comparing SBOM Standards: SPDX vs. CycloneDX

By Luke Mcbride on February 17, 2023 software bill of materials

5 minute read time

Do you know which format for generating a software bill of materials (SBOM) is the best option for your organization? A look at the two leading standards.
Read More...

5 Tools to Automate SBOM Creation

By Eddie Knight on February 13, 2023 agile development

6 minute read time

A look at five different tools that can be integrated into your development workflow to automatically generate a software bill of materials (SBOM).
Read More...

EU Cyber Resilience Act: Good for Software Supply Chain Security, Bad for Open Source?

By Brian Fox on December 22, 2022 secure software supply chain

10 minute read time

The Cyber Resilience Act is the European Union's proposed regulation to combat threats affecting any digital entity. What does that mean for open source?
Read More...

Open Source Basic Practices for Higher Quality Code to Fundamentally Strengthen Your Project

By Aaron Linskens on November 09, 2022 Open Source

8 minute read time

A look at some basic practices for higher quality code to help fundamentally strengthen your project.
Read More...

Using a Software Bill of Materials (SBOM) is Going Mainstream

2 minute read time

Crazy: OWASP A9 is about to turn seven and the DevSecOps Community Survey shows less than half of organizations can produce a Software Bill of Materials.
Read More...

UPDATE: 21 SaltStack Breaches with 2,900 Still Vulnerable

By Derek Weeks on May 31, 2020 vulnerabilities

6 minute read time

When a vulnerability is announced in an open source project, ask immediately: have we ever used that open source component, and (if yes) where is it?
Read More...

Gartner: Mitigate Risk by Hardening the Software Supply Chain

By Katie McCaskey on December 12, 2019 Sonatype Nexus

5 minute read time

As Gartner explains, key to mitigating open source risk, is a hardened software supply chain. But, where do you start?
Read More...