Research, product launches, and field notes on software supply-chain security from the Kusari team.
Most CVEs can't actually be reached by your code. Kusari's new AI Analysis Agent reads your codebase and traces each vulnerability so you can fix what matters and prove what doesn't.
The kusari-cli 1.0 release means you can connect to Kusari Inspector and Kusari Platform no matter what platform you use.
If provenance is not evaluated, it is merely metadata. Enforcement is what transforms integrity into control.
Signing artifacts is not new. Making that signing keyless, auditable, and transparently verifiable is.
Modern software delivery now resembles global manufacturing. If we demand traceability for physical components, we must demand the same for code.
Mythos undoubtedly represents an advancement in the capability of frontier models. It’s also not the apocalypse.
Most security leaders think they have a handle on their attack surface, using SCA, SBOMs, tracking libraries. But there's a problem with that confidence.
Recent attacks against projects like Trivy, LiteLLM, and Axios show the need for automated supply chain checks.
Open source software powers the modern world; securing it remains a shared responsibility.
AI coding assistants (LLMs) dramatically increase developer velocity, but introduce critical new AppSec risks. AI-generated code is consistently less secure.
Your security team just finished a vulnerability scan. The dashboard looks clean, but there's a catch: that scan only covered about 5% of your actual risk surface.
Most US software regulations are built around intent. The EU Cyber Resilience Act (CRA) is built around outcomes. That difference is why 2026 will feel like a shock for many US companies selling softw
Security leaders often talk about risk reduction. Developers talk about velocity. The tension between the two has defined AppSec for over a decade.
Why software integrity is becoming the defining security challenge of the next decade
For years, software security has lived in the realm of best practices. In 2026, software security stops being theoretical and moves firmly into the realm of requirements.
Use Kusari’s tools directly in GitLab workflows to improve your supply chain security.
Security shouldn’t slow you down. Kusari and Cloudsmith enable faster, safer releases by turning noisy CVE scans into actionable insight and enforcing policy from build to deploy. Go fast and secure.
A strategic guide for CISOs and software security leaders
Large language models write code quickly, but to get value to your customers, you need better security processes.
You can prepare yourself for future updates by bringing your post-market applications into a modern security paradigm.
Compare the best SBOM tools for 2025. Expert analysis of cdxgen, Syft, npm-sbom & more. Choose the right SBOM generator for your needs.
Medical devices often far outlast their support period. How can these reliable devices avoid becoming a security liability?
CISA has proposed updates to the SBOM Minimum Elements. What does this mean for business leaders and engineers?
How Medical Devices Can Comply with Section 524B to Meet FDA Cybersecurity Requirements
Companies need to pay attention to the security of their open source dependencies. Kusari Platform can help.
Kusari celebrates the past, present, and future of the Open Source Security Foundation.
Here’s what the new report from the White House means for software supply chain leaders, and how you can get ahead.
Kusari’s software supply chain expertise gives you the ability to overcome the challenges in securing your cloud-native applications.
Software supply chain security doesn’t stop at the application layer. Kusari Inspector can help secure your infrastructure-as-code, too.
The pull request workflow might seem unnecessary for projects with one developer, but it offers security, testing, and feedback benefits.
Explore essential GitHub code security review strategies, specifically designed for projects where security cannot be compromised.
Your security reviews need to be based on facts, not vibes.
Implementing secure pull requests has become essential to prevent security vulnerabilities from making their way into the codebase.
For maintainers responsible for project integrity, understanding these risks isn't optional. It's essential for protecting your software supply chain.
Kusari Inspector is now generally available to provide immediate supply chain security insights in pull requests.
Artificial intelligence can help secure the software supply chain, but it also brings additional considerations.
Securing the software supply chain doesn't end when a release ships. Maintaining released software is an important part of security.
There are so many tools to build SBOMs for your application. How do you know which one to pick?
Asking open source contributors to prove their legal identity doesn’t make software more secure.
The US DoD’s Software Fast-Track Initiative looks to improve software procurement and security. Open source software must be a key part of this.
Open source projects are in the spotlight as regulated industries, governments and those that sell to them ramp cybersecurity expectations. Enter Open Source Project Security (OSPS) Baseline!
Endpoint security is a key part of many IT security efforts, but it’s not always thought about in the specific context of software supply chain security.
Many threats present themselves while implementing software. Here's how to find and address them.
Recent funding concerns have highlighted the need for a more resilient system of vulnerability identification.
Kusari CTO Mike Lieberman shares his thoughts after attending the second-annual VulnCon conference.
Beyond knowing why transitive dependencies are important, you have to know how to manage them.
in-toto helps ensure product integrity by making transparent what steps were performed, by whom, and in what order.
Transitive dependencies are the invisible majority of your applications. Failure to properly understand them increases your risk.
A secure and resilient method for distributing software updates is a key part of keeping your supply chain trustworthy.
This new book from Michael Liberman and Brandon Lum guides you from the basics of supply chain security through to being a security expert.
GUAC v0.14.0 includes a Kubescape collector that can be run inside your Kubernetes cluster to watch for new scan results from Kubescape and ingest those results into GUAC
The abilities of generative and agentic AI models require a proactive approach to protecting the AI supply chain.
When you need a solution for managing your software supply chain, the Kusari Platform provides enterprise-ready features backed by security expertise.
Comparing two SBOMs is useful, but as your portfolio grows, you need to take a holistic approach.
Once you have multiple releases, you have multiple SBOMs. What can you learn from comparing them?
A hypothetical organization takes the first step on their software supply chain security journey by creating an SBOM for their application.
Kusari Platform gives you the information you need to secure your software supply chain.
Kusari is proud to contribute to the Open Source Project Security Baseline, an OpenSSF project to help open source maintainers improve their security posture.
Once you've discovered the third-party risks in the open source projects you consume, how do you address those risks without having a vendor relationship with the projects?
Third-party risk management is an important part of protecting your organization. But how do you manage the risks of open source software when you have no vendor relationship?
Creating a secure foundation of trust enables organizations to safely delegate specific actions in the software development life cycle.
Get a clear understanding of the work involved in remediating a vulnerability so you can schedule it in your sprint without blocking feature work.
Cut through the noise to prioritize which vulnerability gets fixed next
Medical monitors have critical security flaws, allowing unauthorized code execution and patient data leaks.
Managing software dependencies is an important part of software supply chain security. Here are three approaches you can take to pin your dependencies to known-good versions.
This year, we focus on the evolving role of AI, pressing software security concerns, and emerging regulations.
Properly integrating AI into your processes can help identify risks and offer proactive insights, but the final decisions must always remain in human hands.
As 2025 approaches, it’s time to revisit our 2024 software supply chain security predictions to see how they held up.
Software supply chain security is like a stack of turtles—each layer depends on the integrity of the one below it. Continuous vigilance is key to maintaining security all the way down.
What are you defending against? From upstream dependencies to code repositories, threat modeling ensures you're prepared to mitigate risks, reduce vulnerabilities, and avoid costly compromises.
Rust is promising for addressing memory safety issues. Improving existing C/C++ toolchains will take time, but these steps help set a realistic path forward.
Open source software powers 96% of modern applications, but it comes with challenges. Companies can secure their supply chains by actively participating in the open source projects they rely on.
Amid the flurry of innovation and collaboration at last week's KubeCon North America, a critical theme emerged: the precarious state of open source security.
Addressing Common Vulnerabilities and Exposures (CVEs) is no longer optional—aiming to eliminate them is a critical priority for securing modern systems.
Secure development starts with developers: bring forth the code masters
Navigating modern software development is a complex challenge. Kusari’s aim is to make it easier.
Organizations often struggle to identify vulnerabilities and risks hidden within the layers of dependencies. Address it by using a holistic approach to software security.
The White House commits $11 million to enhance our collective understanding of the challenges surrounding open source software.
v0.8.0 features new integration with ClearlyDefined
Practical ways to protect against AI software attacks
Actionable insights come from SBOMs plus additional information
GUAC v0.8.0 brings support for license information, running vuln scans upon SBOM ingestion, node deletion, and many other improvements.
It's not enough to just have the data, you need to be able to see it.
Only two months left until the Secure Software Development Attestation Form deadline
How you handle your dependencies will change how you secure your software supply chain
The Secure By Design Pledge is a great starting point, but it can’t be the end.
CVE IDs don't tell you much, but somehow we started using them as a proxy for security
Improving performance with pagination and more
Open source supply chain observability tool standardizes on PostgreSQL
Gone are the days when signing containers and running vulnerability scans through CI processes provided a sense of security.
The recent incident involving the XZ backdoor brings to light the critical importance of vigilance and proactive security measures, while not losing sight of the human element.
Today, we find ourselves in a moment akin to proud parents, as we witness a significant milestone in the journey of Graph for Understanding Artifact Composition (GUAC).
The GUAC maintainers are pleased to announce the project has joined the Open Source Security Foundation (OpenSSF) as an Incubating Project.
Nathan Naveen, a 17-year-old high schooler, shares his journey to becoming an intern at Kusari
Kusari speaking at FOSDEM and other EU community venues
Kusari raises seed funding
Kusari elected to OpenSSF leadership roles
The missing first step that most organizations are still struggling with
GUAC's OpenVEX Integration
CVE-2023-38545 - HIGH Severity Vulnerability
Kusari have just launched a YouTube Channel!
A look into Guidewire's software supply chain security use case and why they are using GUAC
Helm Chart for GUAC
Tim appeared as a guest on the daBOM podcast.
Working towards determining a persistent database for GUAC
Kusari is excited to announce the v0.1 beta release of GUAC — Graph for Understanding Artifact Composition.
We’re excited to announce the open-sourcing of Spector.
A Story of Software and Cats
Understanding Zero Trust and Its Benefits
What is Software Supply Chain security, and why should I care?
Heartbleed (CVE-2014-0160) in 2014 left the industry in a scramble...
KubeCon + CloudNativeCon is right around the corner and we are excited to be attending in person!
Understanding and maintaining your software supply chain can be a task that needs 24/7 vigilance.
Executive Order (EO) 14028, Improving the Nation’s Cybersecurity was released last year in May.
There’s a misconception in Cybersecurity among some that Software Supply Chain Security is just Third Party Risk Mana...
Overview of the SPIFFE/SPIRE CSI Driver
Takeaways & Learnings