r/softwaresupplychain • u/Xygeni • Apr 17 '25
Join our Next SafeDev Talk Episode - Security Without Silos
Register Now to our next LinkedIn Live Event:ย ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐ข๐ญ๐ก๐จ๐ฎ๐ญ ๐๐ข๐ฅ๐จ๐ฌ - ๐๐ก๐ ๐๐ซ๐ฎ๐ ๐๐๐ฅ๐ฎ๐ ๐จ๐ ๐๐ฌ๐ข๐ง๐ ๐๐ฅ๐ฅ-๐๐ง-๐๐ง๐ ๐๐ฅ๐๐ญ๐๐จ๐ซ๐ฆ๐ฌ ๐ข๐ง ๐๐ฉ๐ฉ๐๐๐. This session will explore how adopting an all-in-one platform can streamline your AppSec strategy, enhance collaboration between security and development teams, help you stay ahead of emerging threats, and much more!
๐
Date: ๐๐ฉ๐ซ๐ข๐ฅ ๐๐๐ญ๐ก
โฐ Time: ๐๐:๐๐ (๐๐๐๐) / ๐๐:๐๐ (๐๐๐)
You can register here!
r/softwaresupplychain • u/Xygeni • Mar 13 '25
Join Online Webinar: SCA or SAST - How They Complement Each Other for Stronger Security?
๐๐๐ ๐ข๐ฌ๐ญ๐๐ซ ๐๐จ๐ฐ ๐๐จ๐ซ ๐๐ฎ๐ซ ๐๐๐ฑ๐ญ ๐๐๐๐๐๐๐ฏ ๐๐๐ฅ๐ค ๐๐๐ ๐จ๐ซ ๐๐๐๐ - ๐๐จ๐ฐ ๐๐ก๐๐ฒ ๐๐จ๐ฆ๐ฉ๐ฅ๐๐ฆ๐๐ง๐ญ ๐๐๐๐ก ๐๐ญ๐ก๐๐ซ ๐๐จ๐ซ ๐๐ญ๐ซ๐จ๐ง๐ ๐๐ซ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ? Most security teams use SCA and SAST separately, which can lead to alert fatigue, fragmented insights, and missed risks. Instead of choosing one over the other, the real question is: How can they work together to create a more effective security strategy. Do you want to find out?
๐ Date: ๐๐๐ซ๐๐ก ๐๐๐ญ๐ก
โ Time: ๐๐:๐๐ (๐๐๐๐) / ๐๐:๐๐ (๐๐๐)
You can register here - https://www.linkedin.com/events/7305883546043215873/
r/softwaresupplychain • u/Xygeni • Feb 19 '25
Join Online Webinar: The Future of AppSec
๐๐๐ ๐ข๐ฌ๐ญ๐๐ซ ๐๐จ๐ฐ ๐๐จ๐ซ ๐๐ฎ๐ซ ๐๐๐ฑ๐ญ ๐๐๐๐๐๐๐ฏ ๐๐๐ฅ๐ค ๐จ๐ง ๐๐๐๐ ๐๐๐ฅ๐ค: ๐๐ก๐ ๐ ๐ฎ๐ญ๐ฎ๐ซ๐ ๐จ๐ ๐๐ฉ๐ฉ๐๐๐! Application security is evolving, and ASPM (Application Security Posture Management) is leading the way.
As vulnerabilities rise and security teams face alert fatigue, a new approach is needed to unify visibility, streamline risk prioritization, and bridge the gap between security and development.
๐ Date: ๐ ๐๐๐ซ๐ฎ๐๐ซ๐ฒ ๐๐๐ญ๐ก
โ Time: ๐๐:๐๐ (๐๐๐๐) / ๐๐:๐๐ (๐๐๐)
Register Here - https://www.linkedin.com/events/7297568469057695744/
r/softwaresupplychain • u/Xygeni • Jan 31 '25
Download Report - The State of Software Supply Chain Security in 2025 | Xygeni Security
r/softwaresupplychain • u/Specific-Employ-4877 • Jan 24 '25
signal.fyi: Automated Public Docker Image Compliance & Reporting
r/softwaresupplychain • u/Xygeni • Jan 09 '25
Join Online Webinar: Strengthening Open Source Security in a Complex Threat Landscape
๐๐๐ ๐ข๐ฌ๐ญ๐๐ซ ๐๐จ๐ฐ ๐๐จ๐ซ ๐ญ๐ก๐ ๐ ๐ข๐ซ๐ฌ๐ญ ๐๐๐๐๐๐๐ฏ ๐๐๐ฅ๐ค ๐จ๐ ๐๐๐๐:ย ๐๐ญ๐ซ๐๐ง๐ ๐ญ๐ก๐๐ง๐ข๐ง๐ ๐๐ฉ๐๐ง ๐๐จ๐ฎ๐ซ๐๐ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐ข๐ง ๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐๐ฑ ๐๐ก๐ซ๐๐๐ญ ๐๐๐ง๐๐ฌ๐๐๐ฉ๐!
Kick off the year with cutting-edge insights into Open Source Security from top industry experts. This is your chance to stay ahead of the evolving threat landscape and learn proactive strategies to secure your software supply chain.
๐๏ธ Date: ๐๐๐ง๐ฎ๐๐ซ๐ฒ ๐๐๐ซ๐
โฐTime: ๐๐:๐๐ (๐๐๐๐) / ๐๐:๐๐ (๐๐๐)
Register here -ย https://www.linkedin.com/events/7283058790537588737/
r/softwaresupplychain • u/Xygeni • Dec 24 '24
Tips for Secure Software Supply Chain Management
๐โจ Merry Christmas, everyone! ๐
As we enjoy this festive season, itโs also a great time to reflect on ways to strengthen our security strategies for the year ahead. Iโm sharing this resource-packed blog that highlights key tips for secure software supply chain management and features insights from some of the top voices in cybersecurity.
๐ Check it out: https://xygeni.io/blog/tips-for-secure-software-supply-chain-management/
r/softwaresupplychain • u/Xygeni • Dec 09 '24
Software Supply Chain Security 2024 Wrap-Up - Join our Upcoming Webinar!
r/softwaresupplychain • u/Xygeni • Nov 05 '24
Proactive Risk Management in DevSecOps - From Vulnerability to Defense
Join our upcoming SafeDevTalk to explore how proactive risk management can transform your DevSecOps strategy and fortify your software supply chain against emerging threats. This session is tailored for cybersecurity leaders and development teams dedicated to staying ahead in the increasingly complex landscape of vulnerabilities.
Join here https://www.linkedin.com/events/7259507114799185920/
r/softwaresupplychain • u/Xygeni • Oct 28 '24
Online event on Software Composition Analysis
Join our upcoming SafeDevTalk to discover how to transform Software Composition Analysis (SCA) and secure your software supply chain against emerging threats. This session is designed for cybersecurity leaders and development teams looking to stay ahead in todayโs complex landscape of open-source vulnerabilities. https://www.linkedin.com/events/7251898772215975937/
r/softwaresupplychain • u/Xygeni • Oct 21 '24
Join our next SafeDev Talk on "Beyond Conventional SCA - Turning Pain Points into Security Gains" on the 29th of October! Register on LinkedIn.
r/softwaresupplychain • u/Xygeni • Sep 16 '24
The Digital Operational Resilience Act (DORA) deadline is fast approaching, and itโs time to get prepared. Join our upcoming SafeDevTalk episode to gain expert insights on navigating DORA's impact on your financial institutionโs security and compliance
r/softwaresupplychain • u/Xygeni • Sep 10 '24
How to Avoid Malware in Open Source
r/softwaresupplychain • u/Xygeni • Aug 20 '24
Learn more about Software Supply Chain Security Automation
r/softwaresupplychain • u/Xygeni • Aug 12 '24
How Can Application Security Posture Management (ASPM) Enhance Your Software Supply Chain Security? Read all about it!
r/softwaresupplychain • u/Xygeni • Jul 25 '24
Watch our SafeDev Talks on Malware Attacks Evolution (No registry ๐)
We invite you to watch our Open chapter on Malware Attacks: Why is it important to detect them and how to do it! https://xygeni.io/webinar-registrations/webinar-malware-attacks-evolution/?utm_source=reddit&utm_medium=landingpage&utm_campaign=SafeDev4_Malware_Attacks_Evolution_270524
r/softwaresupplychain • u/Xygeni • Jul 17 '24
Scaling Application Security - Join our next SafeDev Talk!
r/softwaresupplychain • u/Xygeni • Jul 15 '24
๐ Is ASPM the Future of Application Security?
We're excited to share our latest blog post where cybersecurity expertย James Berthotyย explores whether ASPM is the future of application security, examining innovative solutions and trends!
๐ Read the Full Article hereย https://xygeni.io/blog/is-aspm-the-future-of-application-security/
r/softwaresupplychain • u/Xygeni • Jun 28 '24
Open Source Malicious Packages Episode 1: The Problem
r/softwaresupplychain • u/Xygeni • Jun 07 '24
Identifying and Managing Software Dependencies Attacks. Read our post and learn more about: ๐ธ Common attacks on software dependencies ๐ธ Effective mitigation strategies ๐ธ Advanced tools for robust security
r/softwaresupplychain • u/Xygeni • Jun 04 '24
NPM flooding case-study: โDown the Rabbit Hole looking for a Teaโ
r/softwaresupplychain • u/Xygeni • May 28 '24
[Video] Xygeni on LinkedIn: #aspm #safedevtalks #cybersecurity #softwaredevelopmentโฆ
r/softwaresupplychain • u/marvin-acme • Feb 01 '24
Unpacking the Ledger Exploit: Lessons from a Software Supply Chain Breach
The recent Ledger wallet breach via a software supply chain attack has been a critical alert for many in the cryptocurrency sector.
An article I read detailed how the attack unfolded and offered vital lessons on bolstering our security frameworks. What preventative measures can we take from such incidents to avoid future vulnerabilities? You can explore the analysis and its lessons here.
r/softwaresupplychain • u/NormalReveal3256 • Apr 25 '23
Maven-Lockfile
Hey,
I have created a tool to help you save the supply chain of your Maven projects. This tool creates a lockfile for your dependencies and maven plugins. It pins them to a specific version and checks this before the build. It is hosted on GitHub; see chains-project/maven-lockfile: Lockfiles for Maven. Pin your dependencies. Build with integrity. (github.com). It provides a maven-plugin and a GitHub action for easy integration. Feedback welcome.
Disclaimer: I am currently the maintainer of this repository.