5 Steps to improving your Secure Scorecard

Improve the security of your software development pipeline by following these five simple steps
Photo by Markus Winkler on Unsplash
The Secure Scorecard project, established by the Open Source Security Foundation (OpenSSF), sets out a series of eightee… Continue reading 5 Steps to improving your Secure Scorecard

Demystifying the 18 Checks for Secure Scorecards

What are Secure Scorecards for open source projects? And how they help you produce secure software.
Photo by Glenn Carstens-Peters on Unsplash
“No need to remake the wheel.” The reason this cliche exists is that it’s true. If something already exists a… Continue reading Demystifying the 18 Checks for Secure Scorecards

The Software Bill of Materials and Software Development

Building secure software using the Software Bill of Materials
Photo by Josue Isai Ramos Figueroa on Unsplash
In May 2021, the President released the Executive Order on Improving the Nation’s Cybersecurity (Executive Order). The Software Bill of Materia… Continue reading The Software Bill of Materials and Software Development

How to Prevent Supply Chain Attacks by Securing DevOps

Best practices for securing the software supply chain
Photo by Andy Li on Unsplash
In the wake of several highly publicized supply chain attacks, regulatory and media focus is shifting to address third-party software risk. The Department of Defense’s C… Continue reading How to Prevent Supply Chain Attacks by Securing DevOps