Filter & Search

How Does SLSA Help Strengthen Software Supply Chain Security?

Learn how SLSA enhances software supply chain security with levels of protection. Understand the risks, benefits, and best practices.

Read More

Why You Should Avoid Copy and Paste Code

Discover why copying and pasting code can compromise your software’s security, quality, and compliance with licensing.

Read More

Announcing the Open-Source Reliability Leaderboard: A New Resource for Preventive AppSec

Discover the top open-source packages for preventive AppSec with Mend.io’s Reliability Leaderboard. Learn about package reliability and more.

Read More

Five Tips for Using SBOMs to Boost Supply Chain Security

Learn how to boost your supply chain security with Software Bill of Materials (SBOMs) through five expert tips.

Read More

Top 10 Questions About the Apache License

Explore the Apache License terms and ensure compliance.

Read More

CVSS 4.0 — What’s New?

Learn about the new features and improvements in CVSS 4.0, the Common Vulnerability Scoring System. Understand how to use it.

Read More

How to Boost Confidence in Your Open Source Security with Mend Smart Merge Control

Learn how to boost confidence in your open source security. Automate updates and reduce risks with confidence scores for seamless integration.

Read More

Mend.io Launches AppSec Risk Assessment Program

Mend.io launches AppSec Risk Assessment Program to help organizations visualize and remediate application security risks.

Read More

Understanding the Anatomy of a Malicious Package Attack

Learn to protect your applications from malicious packages with our guide. Understand the anatomy of attacks and how to prevent them.

Read More

The Top 10 Questions about the GPL License – Answered!

Learn about the GPL License and its compliance requirements.

Read More

What’s Driving the Adoption of SBOMs? What’s Next for Them?

Discover what’s driving the adoption of SBOMs and what’s next for them in terms of malicious packages and supply chain security.

Read More

The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name

Mend.io research discovered a threat actor takeover of the name ‘gemnasium-gitlab-service’, a retired Ruby gem with two million+ downloads.

Read More

Mend.io + Jira Security: Doing DevSecOps Better Together

Discover how Mend.io & Jira Security are revolutionizing DevSecOps, improving application security, & streamlining workflows for dev teams.

Read More

Magic Quadrant™ for Application Security Testing, 2023 Gartner® report

Mend.io is recognized as a Visionary in the 2023 Gartner Magic Quadrant for Application Security Testing. Learn about their approach.

Read More

What You Should Know About Open Source License Compliance for M&A Activity

Learn about open source license compliance for M&A activity, the risks of copyleft licenses like GPL, and how to ensure compliance with SCA.

Read More

What is Software Composition Analysis (SCA)?

Learn about Software Composition Analysis (SCA) and how it helps manage open source code to reduce security risks.

Read More

Subscribe to our Newsletter

Join our subscriber list to get the latest news and updates

Thanks for signing up!