Open Source

From Licensing to Security with ISO/IEC 18974

From Licensing to Security with ISO/IEC 18974

What do the security incidents Spring4Shell, OpenSSL Heartbleed, and the XZ Utils backdoor have in common? They all involved open source software components—and all led to significant security breaches through tampered code within those components. These are just a few examples that show how vulnerable our software supply chains are today. The use of open source software components has become an integral part of modern software development.

Read More
ISO/IEC 5230 as the Foundation for Secure Open Source Management

ISO/IEC 5230 as the Foundation for Secure Open Source Management

Every day, over 20,000 new open source software components are released. A modern software project without open source is virtually unthinkable. But with the many advantages also come responsibilities: What license applies to which code? What needs to be shipped alongside it? What legal or security risks are involved? When companies use open source at scale, they need clear and repeatable processes. That’s exactly where ISO/IEC 5230 comes in.

Read More
SBOM: The Foundation for Secure Software Supply Chains

SBOM: The Foundation for Secure Software Supply Chains

When shopping for groceries, we almost always look at the back of the package to study the list of ingredients. After all, as consumers, we want to know exactly what’s in our food. Over the past years and decades, labeling requirements have become significantly stricter.

Read More