Blog

From the Kusari team.

Research, product launches, and field notes on software supply-chain security from the Kusari team.

A screen shot of the vulnerability table in Kusari Console showing vulnerabilities that don't affect the software

Kusari Platform now tells you which vulnerabilities can actually be exploited — and writes the VEX

Most CVEs can't actually be reached by your code. Kusari's new AI Analysis Agent reads your codebase and traces each vulnerability so you can fix what matters and prove what doesn't.

kusari-cli gives you Kusari’s power wherever you go

kusari-cli gives you Kusari’s power wherever you go

The kusari-cli 1.0 release means you can connect to Kusari Inspector and Kusari Platform no matter what platform you use.

From Provenance to Enforcement:  SLSA, in-toto, and Kubernetes Admission Control

From Provenance to Enforcement: SLSA, in-toto, and Kubernetes Admission Control

If provenance is not evaluated, it is merely metadata. Enforcement is what transforms integrity into control.

Identity, Signing, and Transparency: The Foundation of Verifiable Builds

Identity, Signing, and Transparency: The Foundation of Verifiable Builds

Signing artifacts is not new. Making that signing keyless, auditable, and transparently verifiable is.

Software Is a Supply Chain — Start Treating It Like One

Software Is a Supply Chain — Start Treating It Like One

Modern software delivery now resembles global manufacturing. If we demand traceability for physical components, we must demand the same for code.

A statue of a three-headed monster

Facts and Mythos: understanding the future of AI security analysis

Mythos undoubtedly represents an advancement in the capability of frontier models. It’s also not the apocalypse.

Why 72% of Organizations Can't See Their Real Attack Surface: Solving the Transitive Dependency Visibility Gap

Why 72% of Organizations Can't See Their Real Attack Surface: Solving the Transitive Dependency Visibility Gap

Most security leaders think they have a handle on their attack surface, using SCA, SBOMs, tracking libraries. But there's a problem with that confidence.

How Kusari Protects Against Recent Supply Chain Attacks

How Kusari Protects Against Recent Supply Chain Attacks

Recent attacks against projects like Trivy, LiteLLM, and Axios show the need for automated supply chain checks.

Vibe Coding & Vulnerabilities: A Security Team's Guide to AI-Generated Code Risks

Vibe Coding & Vulnerabilities: A Security Team's Guide to AI-Generated Code Risks

Kusari Partners with OpenSSF to Strengthen Open Source Software Supply Chain Security

Kusari Partners with OpenSSF to Strengthen Open Source Software Supply Chain Security

Open source software powers the modern world; securing it remains a shared responsibility.

Kusari and CNCF: Advancing Software Supply Chain Security for Cloud Native Projects

Kusari and CNCF: Advancing Software Supply Chain Security for Cloud Native Projects

AI Coding Assistants in 2026: 4× Faster, 10× Riskier and The Hidden Security Cost

AI Coding Assistants in 2026: 4× Faster, 10× Riskier and The Hidden Security Cost

AI coding assistants (LLMs) dramatically increase developer velocity, but introduce critical new AppSec risks. AI-generated code is consistently less secure.

The 95% Problem: Why Transitive Dependencies Are Your Biggest Software Supply Chain Blind Spot in 2026

The 95% Problem: Why Transitive Dependencies Are Your Biggest Software Supply Chain Blind Spot in 2026

Your security team just finished a vulnerability scan. The dashboard looks clean, but there's a catch: that scan only covered about 5% of your actual risk surface.

Why the EU Cyber Resilience Act Will Catch US Software Companies Off Guard

Why the EU Cyber Resilience Act Will Catch US Software Companies Off Guard

Most US software regulations are built around intent. The EU Cyber Resilience Act (CRA) is built around outcomes. That difference is why 2026 will feel like a shock for many US companies selling softw

The Hidden Cost of Reactive AppSec

The Hidden Cost of Reactive AppSec

Security leaders often talk about risk reduction. Developers talk about velocity. The tension between the two has defined AppSec for over a decade.

Compliance Is Getting Real

Compliance Is Getting Real

Why software integrity is becoming the defining security challenge of the next decade

2026 Predictions: Open Source Accountability, AI Security, and Standardization Will Define the Next Era of Software

2026 Predictions: Open Source Accountability, AI Security, and Standardization Will Define the Next Era of Software

For years, software security has lived in the realm of best practices. In 2026, software security stops being theoretical and moves firmly into the realm of requirements.

Integrating GitLab and Kusari

Integrating GitLab and Kusari

Use Kusari’s tools directly in GitLab workflows to improve your supply chain security.

Breaking the "Department of No" - Ship Fast, but also Secure

Breaking the "Department of No" - Ship Fast, but also Secure

Security shouldn’t slow you down. Kusari and Cloudsmith enable faster, safer releases by turning noisy CVE scans into actionable insight and enforcing policy from build to deploy. Go fast and secure.

The Top 10 To-Dos for CRA Compliance Right Now

The Top 10 To-Dos for CRA Compliance Right Now

A strategic guide for CISOs and software security leaders

It Takes More Than AI to Deliver Code Faster

It Takes More Than AI to Deliver Code Faster

Large language models write code quickly, but to get value to your customers, you need better security processes.

Updating Legacy Medical Applications for Modern Security Requirements

Updating Legacy Medical Applications for Modern Security Requirements

You can prepare yourself for future updates by bringing your post-market applications into a modern security paradigm.

Best SBOM Tools 2025: How to Choose the Right SBOM Generation Tool

Best SBOM Tools 2025: How to Choose the Right SBOM Generation Tool

Compare the best SBOM tools for 2025. Expert analysis of cdxgen, Syft, npm-sbom & more. Choose the right SBOM generator for your needs.

Securing Yesterday’s Medical Devices against Cyber Threats: Addressing Legacy MedTech

Securing Yesterday’s Medical Devices against Cyber Threats: Addressing Legacy MedTech

Medical devices often far outlast their support period. How can these reliable devices avoid becoming a security liability?

Understanding the Proposed CISA 2025 SBOM Minimum Elements

Understanding the Proposed CISA 2025 SBOM Minimum Elements

CISA has proposed updates to the SBOM Minimum Elements. What does this mean for business leaders and engineers?

Securing Medical Devices: Cyber Threats, SBOMs, and FDA Premarket Readiness

Securing Medical Devices: Cyber Threats, SBOMs, and FDA Premarket Readiness

How Medical Devices Can Comply with Section 524B to Meet FDA Cybersecurity Requirements

Using Kusari to Manage your Open Source Dependencies

Using Kusari to Manage your Open Source Dependencies

Companies need to pay attention to the security of their open source dependencies. Kusari Platform can help.

Celebrating OpenSSF’s Anniversary

Celebrating OpenSSF’s Anniversary

Kusari celebrates the past, present, and future of the Open Source Security Foundation.

What Security Leaders Need to Know about America’s AI Action Plan

What Security Leaders Need to Know about America’s AI Action Plan

Here’s what the new report from the White House means for software supply chain leaders, and how you can get ahead.

Addressing the Challenges of Cloud-Native Application Security

Addressing the Challenges of Cloud-Native Application Security

Kusari’s software supply chain expertise gives you the ability to overcome the challenges in securing your cloud-native applications.

Supply Chain Security for GitOps

Supply Chain Security for GitOps

Software supply chain security doesn’t stop at the application layer. Kusari Inspector can help secure your infrastructure-as-code, too.

Using Pull Requests on a Single-Developer Project

Using Pull Requests on a Single-Developer Project

The pull request workflow might seem unnecessary for projects with one developer, but it offers security, testing, and feedback benefits.

GitHub Code Review Best Practices for Security-Critical Projects

GitHub Code Review Best Practices for Security-Critical Projects

Explore essential GitHub code security review strategies, specifically designed for projects where security cannot be compromised.

Going Beyond Vibes with Kusari Inspector

Going Beyond Vibes with Kusari Inspector

Your security reviews need to be based on facts, not vibes.

Stop Merging Risky Code: Secure Pull Requests with Automated Security Checks

Stop Merging Risky Code: Secure Pull Requests with Automated Security Checks

Implementing secure pull requests has become essential to prevent security vulnerabilities from making their way into the codebase.

Top 5 Pull Request Security Risks Every Maintainer Should Know

Top 5 Pull Request Security Risks Every Maintainer Should Know

For maintainers responsible for project integrity, understanding these risks isn't optional. It's essential for protecting your software supply chain.

Kusari Inspector: Security Insights Where You Need Them

Kusari Inspector: Security Insights Where You Need Them

Kusari Inspector is now generally available to provide immediate supply chain security insights in pull requests.

AI and the Secure Software Factory

AI and the Secure Software Factory

Artificial intelligence can help secure the software supply chain, but it also brings additional considerations.

Securing the Maintenance Phase

Securing the Maintenance Phase

Securing the software supply chain doesn't end when a release ships. Maintaining released software is an important part of security.

Choosing an SBOM Generation Tool

Choosing an SBOM Generation Tool

There are so many tools to build SBOMs for your application. How do you know which one to pick?

Code is More Important than Identity for Security

Code is More Important than Identity for Security

Asking open source contributors to prove their legal identity doesn’t make software more secure.

Open Source Accelerates Secure Software

Open Source Accelerates Secure Software

The US DoD’s Software Fast-Track Initiative looks to improve software procurement and security. Open source software must be a key part of this.

OpenSSF Tech Talk Recap: Using the OSPS Baseline to Navigate Standards and Regulations

OpenSSF Tech Talk Recap: Using the OSPS Baseline to Navigate Standards and Regulations

Open source projects are in the spotlight as regulated industries, governments and those that sell to them ramp cybersecurity expectations. Enter Open Source Project Security (OSPS) Baseline!

Endpoint Security is Supply Chain Security

Endpoint Security is Supply Chain Security

Endpoint security is a key part of many IT security efforts, but it’s not always thought about in the specific context of software supply chain security.

Identifying Threats in the Implementation Phase

Identifying Threats in the Implementation Phase

Many threats present themselves while implementing software. Here's how to find and address them.

The Future of CVEs

The Future of CVEs

Recent funding concerns have highlighted the need for a more resilient system of vulnerability identification.

VulnCon 2025 Recap

VulnCon 2025 Recap

Kusari CTO Mike Lieberman shares his thoughts after attending the second-annual VulnCon conference.

The Hidden Risk in Your Software: Managing Transitive Dependencies

The Hidden Risk in Your Software: Managing Transitive Dependencies

Beyond knowing why transitive dependencies are important, you have to know how to manage them.

Codifying the SDLC with in-toto

Codifying the SDLC with in-toto

in-toto helps ensure product integrity by making transparent what steps were performed, by whom, and in what order.

The Hidden Risk in Your Software: Understanding Transitive Dependencies

The Hidden Risk in Your Software: Understanding Transitive Dependencies

Transitive dependencies are the invisible majority of your applications. Failure to properly understand them increases your risk.

Providing Secure Updates with TUF

Providing Secure Updates with TUF

A secure and resilient method for distributing software updates is a key part of keeping your supply chain trustworthy.

Securing the Software Supply Chain book now available!

Securing the Software Supply Chain book now available!

This new book from Michael Liberman and Brandon Lum guides you from the basics of supply chain security through to being a security expert.

GUAC Now Supports Runtime Kubernetes SBOMs using Kubescape

GUAC Now Supports Runtime Kubernetes SBOMs using Kubescape

GUAC v0.14.0 includes a Kubescape collector that can be run inside your Kubernetes cluster to watch for new scan results from Kubescape and ingest those results into GUAC

Securing Your AI Models

Securing Your AI Models

The abilities of generative and agentic AI models require a proactive approach to protecting the AI supply chain.

The Last Step on the Security Journey: Kusari Platform

The Last Step on the Security Journey: Kusari Platform

When you need a solution for managing your software supply chain, the Kusari Platform provides enterprise-ready features backed by security expertise.

Another Step on the Security Journey: A Constellation of SBOMs

Another Step on the Security Journey: A Constellation of SBOMs

Comparing two SBOMs is useful, but as your portfolio grows, you need to take a holistic approach.

The Next Step in the Security Journey: Comparing SBOMs

The Next Step in the Security Journey: Comparing SBOMs

Once you have multiple releases, you have multiple SBOMs. What can you learn from comparing them?

Starting the Security Journey: Producing an SBOM

Starting the Security Journey: Producing an SBOM

A hypothetical organization takes the first step on their software supply chain security journey by creating an SBOM for their application.

Unpacking Kusari Platform Views

Unpacking Kusari Platform Views

Kusari Platform gives you the information you need to secure your software supply chain.

Raising the Bar for Open Source Security: Introducing the OSPS Baseline

Raising the Bar for Open Source Security: Introducing the OSPS Baseline

Kusari is proud to contribute to the Open Source Project Security Baseline, an OpenSSF project to help open source maintainers improve their security posture.

Addressing Third-Party Risk in Open Source Software

Addressing Third-Party Risk in Open Source Software

Once you've discovered the third-party risks in the open source projects you consume, how do you address those risks without having a vendor relationship with the projects?

Analyzing Third-Party Risk in Open Source Software

Analyzing Third-Party Risk in Open Source Software

Third-party risk management is an important part of protecting your organization. But how do you manage the risks of open source software when you have no vendor relationship?

Building a Foundation of Trust for a Stronger Software Supply Chain

Building a Foundation of Trust for a Stronger Software Supply Chain

Creating a secure foundation of trust enables organizations to safely delegate specific actions in the software development life cycle.

Unpacking the Kusari “Effort to Fix” Capability

Unpacking the Kusari “Effort to Fix” Capability

Get a clear understanding of the work involved in remediating a vulnerability so you can schedule it in your sprint without blocking feature work.

Unpacking the Kusari Score

Unpacking the Kusari Score

Cut through the noise to prioritize which vulnerability gets fixed next

Alarms Raised by Critical Reverse Backdoor Vulnerability in Medical Devices

Alarms Raised by Critical Reverse Backdoor Vulnerability in Medical Devices

Medical monitors have critical security flaws, allowing unauthorized code execution and patient data leaks.

Stick a Pin in It: Managing Dependencies for Supply Chain Security

Stick a Pin in It: Managing Dependencies for Supply Chain Security

Managing software dependencies is an important part of software supply chain security. Here are three approaches you can take to pin your dependencies to known-good versions.

Software Supply Chain Security Predictions for 2025

Software Supply Chain Security Predictions for 2025

This year, we focus on the evolving role of AI, pressing software security concerns, and emerging regulations.

AI Alone Won’t Fix Your Supply Chain

AI Alone Won’t Fix Your Supply Chain

Properly integrating AI into your processes can help identify risks and offer proactive insights, but the final decisions must always remain in human hands.

Software Supply Chain Security Predictions: Hits & Misses from 2024

Software Supply Chain Security Predictions: Hits & Misses from 2024

As 2025 approaches, it’s time to revisit our 2024 software supply chain security predictions to see how they held up.

Solving the “Bottom Turtle” Problem in Supply Chain Security

Solving the “Bottom Turtle” Problem in Supply Chain Security

Software supply chain security is like a stack of turtles—each layer depends on the integrity of the one below it. Continuous vigilance is key to maintaining security all the way down.

Threat Modeling in the Software Development Life Cycle

Threat Modeling in the Software Development Life Cycle

What are you defending against? From upstream dependencies to code repositories, threat modeling ensures you're prepared to mitigate risks, reduce vulnerabilities, and avoid costly compromises.

Rust Won’t Fix Everything: Moving Toward a Memory-Safe Future

Rust Won’t Fix Everything: Moving Toward a Memory-Safe Future

Rust is promising for addressing memory safety issues. Improving existing C/C++ toolchains will take time, but these steps help set a realistic path forward.

The Best Way to Secure Your Open Source Supply Chain is to Participate

The Best Way to Secure Your Open Source Supply Chain is to Participate

Open source software powers 96% of modern applications, but it comes with challenges. Companies can secure their supply chains by actively participating in the open source projects they rely on.

Is the Internet on Fire? The State of Open Source Security

Is the Internet on Fire? The State of Open Source Security

Amid the flurry of innovation and collaboration at last week's KubeCon North America, a critical theme emerged: the precarious state of open source security.

The Path to Zero CVEs: Vanquishing Cyber Threats

The Path to Zero CVEs: Vanquishing Cyber Threats

Addressing Common Vulnerabilities and Exposures (CVEs) is no longer optional—aiming to eliminate them is a critical priority for securing modern systems.

Is Your Supply Chain Haunted by CVEs?

Is Your Supply Chain Haunted by CVEs?

Secure development starts with developers: bring forth the code masters

Introducing the Kusari Platform—know your software

Introducing the Kusari Platform—know your software

Navigating modern software development is a complex challenge. Kusari’s aim is to make it easier.

You Can’t Fix Issues if You Can’t Find Them

You Can’t Fix Issues if You Can’t Find Them

Organizations often struggle to identify vulnerabilities and risks hidden within the layers of dependencies. Address it by using a holistic approach to software security.

Understanding Prevalence is the First Step

Understanding Prevalence is the First Step

The White House commits $11 million to enhance our collective understanding of the challenges surrounding open source software.

GUAC Boosts License Transparency

GUAC Boosts License Transparency

v0.8.0 features new integration with ClearlyDefined

Hack-Proof Artificial Intelligence Supply Chains Using Open Source Security

Hack-Proof Artificial Intelligence Supply Chains Using Open Source Security

Practical ways to protect against AI software attacks

Why Software Cannot Be Secured by SBOMs Alone

Why Software Cannot Be Secured by SBOMs Alone

Actionable insights come from SBOMs plus additional information

Announcing GUAC v0.8.0 Enhancements

Announcing GUAC v0.8.0 Enhancements

GUAC v0.8.0 brings support for license information, running vuln scans upon SBOM ingestion, node deletion, and many other improvements.

Achieving Wisdom with GUAC Visualizer

Achieving Wisdom with GUAC Visualizer

It's not enough to just have the data, you need to be able to see it.

Meeting Federal Software Supply Chain Mandates

Meeting Federal Software Supply Chain Mandates

Only two months left until the Secure Software Development Attestation Form deadline

To Fork or Not to Fork

To Fork or Not to Fork

How you handle your dependencies will change how you secure your software supply chain

Kusari Signs the Secure by Design Pledge

Kusari Signs the Secure by Design Pledge

The Secure By Design Pledge is a great starting point, but it can’t be the end.

Counting CVEs Was Never Enough

Counting CVEs Was Never Enough

CVE IDs don't tell you much, but somehow we started using them as a proxy for security

Another Turn of the Page: GUAC v0.7.0 Released

Another Turn of the Page: GUAC v0.7.0 Released

Improving performance with pagination and more

Graph for Understanding Artifact Composition (GUAC) adds persistent storage in v0.6.0 release

Graph for Understanding Artifact Composition (GUAC) adds persistent storage in v0.6.0 release

Open source supply chain observability tool standardizes on PostgreSQL

Proactive Security in the Post-Log4j Era

Proactive Security in the Post-Log4j Era

Gone are the days when signing containers and running vulnerability scans through CI processes provided a sense of security.

XZ Backdoor: Software Security Lessons

XZ Backdoor: Software Security Lessons

The recent incident involving the XZ backdoor brings to light the critical importance of vigilance and proactive security measures, while not losing sight of the human element.

Unveiling GUAC as an OpenSSF Incubating Project for Software Dependency Management

Unveiling GUAC as an OpenSSF Incubating Project for Software Dependency Management

Today, we find ourselves in a moment akin to proud parents, as we witness a significant milestone in the journey of Graph for Understanding Artifact Composition (GUAC).

Graph for Understanding Artifact Composition (GUAC)  Joins OpenSSF as Incubating Project

Graph for Understanding Artifact Composition (GUAC) Joins OpenSSF as Incubating Project

The GUAC maintainers are pleased to announce the project has joined the Open Source Security Foundation (OpenSSF) as an Incubating Project.

From Open Source Community to Joining a Start-up – while in High School

From Open Source Community to Joining a Start-up – while in High School

Nathan Naveen, a 17-year-old high schooler, shares his journey to becoming an intern at Kusari

Kusari Soaks up Community at FOSDEM and Beyond

Kusari Soaks up Community at FOSDEM and Beyond

Kusari speaking at FOSDEM and other EU community venues

Our $8M Funding Round Fuels our Mission to Make the Software Supply Chain Transparent and Secure

Our $8M Funding Round Fuels our Mission to Make the Software Supply Chain Transparent and Secure

Kusari raises seed funding

Contributor to Leader: Securing Open Source Software at OpenSSF

Contributor to Leader: Securing Open Source Software at OpenSSF

Kusari elected to OpenSSF leadership roles

What the NSA Missed in its SBOM Management Recommendations

What the NSA Missed in its SBOM Management Recommendations

The missing first step that most organizations are still struggling with

Spooky Enhancements: Unveiling GUAC's OpenVEX Feature

Spooky Enhancements: Unveiling GUAC's OpenVEX Feature

GUAC's OpenVEX Integration

Terror of cURL - Preparation is Half the Battle

Terror of cURL - Preparation is Half the Battle

CVE-2023-38545 - HIGH Severity Vulnerability

Announcing the Kusari YouTube Channel and GUACademy

Announcing the Kusari YouTube Channel and GUACademy

Kusari have just launched a YouTube Channel!

Case Study: A discussion with Guidewire on GUAC

Case Study: A discussion with Guidewire on GUAC

A look into Guidewire's software supply chain security use case and why they are using GUAC

Announcing Helm Chart for GUAC

Announcing Helm Chart for GUAC

Helm Chart for GUAC

daBOM Podcast with Tim & DJ

daBOM Podcast with Tim & DJ

Tim appeared as a guest on the daBOM podcast.

Quest to determine the 'G' in GUAC

Quest to determine the 'G' in GUAC

Working towards determining a persistent database for GUAC

GUAC v0.1 Beta Release

GUAC v0.1 Beta Release

Kusari is excited to announce the v0.1 beta release of GUAC — Graph for Understanding Artifact Composition.

Kusari Open-Sources Spector

Kusari Open-Sources Spector

We’re excited to announce the open-sourcing of Spector.

Figure Out Who's Lurking in Your Supply Chain With Signatures and Attestations

Figure Out Who's Lurking in Your Supply Chain With Signatures and Attestations

A Story of Software and Cats

Applying Zero Trust to the Software Supply Chain

Applying Zero Trust to the Software Supply Chain

Understanding Zero Trust and Its Benefits

Kusari's Software Supply Chain Security Overview

Kusari's Software Supply Chain Security Overview

What is Software Supply Chain security, and why should I care?

The Next Heartbleed?

The Next Heartbleed?

Heartbleed (CVE-2014-0160) in 2014 left the industry in a scramble...

Kusari presenting at KubeCon and Cloud Native SecurityCon NA 2022

Kusari presenting at KubeCon and Cloud Native SecurityCon NA 2022

KubeCon + CloudNativeCon is right around the corner and we are excited to be attending in person!

A High Fidelity View of Software Supply Chain

A High Fidelity View of Software Supply Chain

Understanding and maintaining your software supply chain can be a task that needs 24/7 vigilance.

Government Memo for Enhancing the Security of the Software Supply Chain

Government Memo for Enhancing the Security of the Software Supply Chain

Executive Order (EO) 14028, Improving the Nation’s Cybersecurity was released last year in May.

Not Just Third Party Risk

Not Just Third Party Risk

There’s a misconception in Cybersecurity among some that Software Supply Chain Security is just Third Party Risk Mana...

SPIFFE/SPIRE CSI Driver

SPIFFE/SPIRE CSI Driver

Overview of the SPIFFE/SPIRE CSI Driver

Open Source Summit 2022

Open Source Summit 2022

Takeaways & Learnings