Blog Adam Murray

Adam Murray

Writes about open source security and risk mitigation.

What Is CVSS v3.1? Understanding The New CVSS

Learn about the Common Vulnerability Scoring System (CVSS) v3.1 & how it measures severity, not risk, in assessing security vulnerabilities.

Read More

White Box Testing Guide

Learn about White Box Testing in software development with this comprehensive guide. Understand the types, techniques, tools, advantages.

Read More

Top Tips for Getting Started With a Software Composition Analysis Solution

Top tips for starting with a software composition analysis solution. Build a team, set goals beyond scanning, understand the data model, make policies work, start small.

Read More

Open Source Copyleft Licenses: All You Need to Know

All you need to know about Open Source Copyleft Licenses. Learn about the history, benefits, and considerations of using copyleft licenses.

Read More

Be Wise — Prioritize: Software Security Vulnerability Prioritization

Learn how to prioritize software security vulnerabilities effectively to ensure your team is addressing the most urgent threats first.

Read More

Eclipse SW360: Main Features

Learn about the main features of Eclipse SW360, an open source tool to manage software components.

Read More

Why Manually Tracking Open Source Components Is Futile

Learn why manually tracking open source components is futile and how automation through software composition analysis can help manage licenses.

Read More

Black Box Testing: What You Need to Know

Learn all about black box testing in application security & quality assurance. Discover techniques, & tools and more.

Read More

Top 7 Questions to Ask When Evaluating a Software Composition Analysis Solution

Discover the top 7 questions to ask when evaluating a Software Composition Analysis solution for managing open source components.

Read More

Top 9 Code Review Tools for Clean and Secure Source Code

Discover the top 9 code review tools for clean and secure source code, essential for detecting errors and defects before production.

Read More

Open Source Vulnerability Databases

Discover the top open source vulnerability databases beyond NVD. Learn how to track and remediate vulnerabilities in your software.

Read More

Why Patch Management is Important and How to Get It Right

Learn why patch management is crucial for application security and how to implement it effectively. Discover best practices, tools, and more.

Read More

Application Security Testing: Security Scanning Vs. Runtime Protection

Learn about the differences between security scanning and runtime protection in application security testing. Explore tools and tech.

Read More

License Compatibility: Combining Open Source Licenses

Learn about open source license compatibility and the importance of combining licenses. Understand permissive vs. copyleft licenses and more.

Read More

Why You Need an Open Source Vulnerability Scanner

Learn why you need an open source vulnerability scanner to protect your applications from cyber attacks.

Read More

The SaaS Loophole in GPL Open Source Licenses

Discover the SaaS loophole in GPL open source licenses and how it affects software distribution. Learn about the AGPL solution.

Read More

Subscribe to our Newsletter

Join our subscriber list to get the latest news and updates

Thanks for signing up!