WhiteSource Develops SBOM Solution to Help Developers Protect Software Supply Chain, Meet New Governmental Regulations
WhiteSource SBOM provides unrivaled visibility into software components and presents a path to remediation for vulnerabilities
TEL AVIV AND BOSTON โ Nov. 9, 2021 โย In an effort to help developers meet new governmental regulations for protecting the software supply chain,ย WhiteSource, the leader in open source security and management, today releasedย WhiteSource SBOM, a new tool that quickly and easily creates a software bill of materials (SBOM) and uniquely provides a path to remediation when vulnerabilities are identified.
The software supply chain has come under increasing scrutiny since the SolarWinds attack in late 2020, which exposed data from more than 18,000 companies and governmental agencies. In response, theย White House issued an executive orderย that aims to improve the nationโs cybersecurity in order to protect governmental agencies and vital infrastructure from software supply chain attacks. A key part of those efforts is the need for all software to contain SBOMs, a formal, machine-readable inventory of software components and dependencies used to track their supply chain relationships, dependencies, and hierarchical relationships.
WhiteSource SBOM identifies open source libraries, tracks and documents components, and automatically updates when changes are made, providing deep inspection and insight that make it possible to identify unintentional or malicious content being installed during application builds. When vulnerabilities are identified, WhiteSource SBOM provides a path to remediation that ensures updates wonโt break the build.
โAttacks against the software supply chain increased more than 600 percent in the past year, and in two-thirds of those attacks, cyberattackers used code from suppliers to expand the attack,โ said Rami Sass, Co-Founder and CEO of WhiteSource. โOrganizations can now leverage WhiteSource SBOM to detect and remediate vulnerabilities, significantly reducing the risk of successful attacks.โ
To learn more about WhiteSource SBOM and create a trial SBOM, visitย https://www.mend.io/sbom
About Mend.io
Mend.io is a leading application security solution that helps organizations fix less and reduce risk faster. Built for both AI-driven and modern development workflows, Mend.io gives teams visibility into all code โ human-written, AI-generated, open source, third-party and container components โ and helps them prioritize and remediate the risks that matter most.