Skip to main content

Blog posts tagged "software supply chain"

Building an open source chain of trust: new research uncovers key blockers and ways forward

Canonical is pleased to share its latest research report, “The open source chain of trust.” Based on a survey of 500 DevOps professionals, the report highlights how organizations approach their open source software supply chains. While many companies are moving toward verifiable provenance and automated security workflows, internal misali

70% of IT teams spend more than 6 hours per week on security patching – new IDC research

Open source software is a popular tool for businesses for many reasons, but this adoption has introduced new challenges in maintaining their open source software supply chain. 57% of organizations source their packages from upstream open source repositories, and 51% from ecosystem packages like pip or npm. The research shows that while 9

What is SBOM? Software bill of materials explained

An SBOM boils down to a detailed and accessible list of all the components that make up your software and where they come from. n this article, we’ll examine what an SBOM is, what information it must include, and the approaches that developers and manufacturers alike should be considering as they start building their SBOM.