Our Third Annual “State of Software Supply Chain” Report is Now Available (opens in new tab)
Are your vulnerability management practices actually reducing risk, or are they quietly disrupting your ability to deliver software? That is the main question behind this year’s research. Most organizations now have some kind of process for detecting and responding to vulnerabilities in open-source dependencies. They have scanners, alerts, dashboards, dependency update PRs, security policies, and remediation workflows. To explore this, we spent more than 100 hours reviewing industry reports, ...
Read the original article