The Evolution of Open Source Malware: From Volume to Trust Abuse

The Evolution of Open Source Malware: From Volume to Trust Abuse

Open source malware is no longer just a numbers game. What was once largely a volume problem — thousands of malicious packages flooding public registries through typosquatting, brandjacking, and low-effort deception — ...

Autonomous Development and AI: Speed vs. Security

AI-assisted development is changing how software gets built. What began as a productivity boost is quickly becoming something bigger ...

Guardrails Make AI-Assisted Development Safer By Design

AI coding assistants are rapidly becoming part of everyday software development. From generating boilerplate code to suggesting entire dependency stacks, these tools promise faster delivery and higher productivity ...
Closing the Gaps: Protecting Your Pipeline from Open Source Malware

Closing the Gaps: Protecting Your Pipeline from Open Source Malware

Open source software is the backbone of modern development, powering everything from business applications to AI-driven systems. But with that growth has come a new frontier of risk: open source malware ...

The Future of Developer Velocity with Sonatype and AWS

The pressure to ship faster has never been higher. Artificial intelligence (AI) is accelerating how software is planned, built, and delivered ...

Managing AI Risks in the Modern Software Supply Chain

Artificial Intelligence (AI) and Machine Learning (ML) continue to reshape software development at an unprecedented pace. Platforms like Hugging Face make millions of pre-trained models easily accessible, enabling faster innovation and powerful ...

Building Resilience and DORA Compliance: Lessons, Gaps, What’s Next

Operational resilience is more than a nice-to-have. It's a business imperative. For financial institutions, this principle has been codified by the European Union's Digital Operational Resilience Act (DORA), which aims to ensure ...