Custom Code 10% 대비 Open Source 90% 의존 구조의 Supply Chain 리스크 해결
Day 15 - Software Composition Analysis(SCA)
Day 15 - Software Composition Analysis(SCA)
Kexa.io: Open-Source IT Security for Local AI Governance
Arctype: Cross-Platform Database GUI for LLM Artifacts
Score Any CVSS Vector Offline - v3.1 and v4.0, Zero Dependencies
Why npm supply chain attacks keep happening and how to harden your installs
NIST Narrows the NVD: What Container Security Programs Should Reassess
OSSGuard – CLI to adopt OpenSSF security best practices in any project
Leading Open Source Author Calls for Verification over Trust in Software Supply Chains
Precision Container Security with Docker and Black Duck
60–80% of your CVEs are unreachable. Here's how to prove it.
Mythos Found a 27-Year-Old Bug in OpenBSD. Your Code Is Next.
A Semantic Kernel Alternative for .NET — When and Why You'd Reach for One
War Story: We Implemented SBOMs with Syft 0.10 and Cut Compliance Audit Time 60% for 500 Services
Let the ORM fight begin!
Risk Management for Developers: A 2026 Practitioner Guide"
Generating SBOM with Docker Scout
CI/CD Build Systems for Cloud-Native Applications
pnpm 11 Release Candidate: ESM Distribution, Supply Chain Defaults and a New Store Format
Presentation: Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation
Why We Chose the Harder Path: Docker Hardened Images, One Year Later