Mend.io Blog

You can’t rely on open source for security — not even when ai is involved

You can’t rely on open source for security — not even when AI is involved

LATEST
Learn more

Filter & Search

3 new github features to reinforce your code, repo, and dependency security - 3 new github features to boost your security 1 1

3 New GitHub Features to Reinforce Your Code, Repo, and Dependency Security

Learn about the latest GitHub features to enhance your code security and dependency management. Stay ahead of vulnerabilities.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - cloud architecture security

Cloud Security Architecture: A Practical Guide

Learn about Cloud Security Architecture. Understand the importance, core principles, and threats to secure your cloud environment effectively.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - integration of diffend via artifactory plugin

Introducing Mend Supply Chain Defender Integration with JFrog Artifactory

Discover how Mend Supply Chain Defender integrates with JFrog Artifactory to block malicious software threats in your code base.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - brand announce navy 1920 1080 scaled 1

From WhiteSource to Mend—A Rebrand Journey

From WhiteSource to Mend—A Rebrand Journey. Follow our evolution from open source to all code application security.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - brand announce navy 1920 1080 scaled 1

WhiteSource is Now Mend: You Code, We Cure

Mend, formerly WhiteSource, focuses on automating application security with a remediation-first approach for open source and custom code.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - vulnerability remediation a practical guide

Vulnerability Remediation: A Practical Guide

Practical guide to vulnerability remediation for developers & security teams. Learn how to detect, prioritize, fix, & monitor vulnerabilities.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - blog

New Typosquatting Attack on npm Package ’colors’ Using Cross language Technique Explained

Discover the latest typosquatting attack on the npm package 'colors' using a cross-language technique.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - rubygems critical cve 2022 29176

Impact Analysis: RubyGems Critical CVE-2022-29176 Unauthorized Package Takeover 

Impact Analysis of RubyGems Critical CVE-2022-29176 Unauthorized Package Takeover. Learn about the vulnerability, impact assessment, and more

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - what is the nist supply chain risk management program

What is the NIST Supply Chain Risk Management Program?

Discover the NIST Supply Chain Risk Management Program.. Learn how to manage cybersecurity risks in digital supply chains effectively.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - blog why vulnerability management must go beyond cvss to priority scoring

Why Vulnerability Management Must Go Beyond CVSS to Priority Scoring

Learn why vulnerability management must go beyond CVSS to priority scoring for better open source security and remediation prioritization.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - news aws target

AWS Targeted by a Package Backfill Attack

Discover how AWS was targeted by a malicious package backfill attack, the methods used by attackers, and how to protect against such attacks.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - blog image 2 assessment tools

5 Vulnerability Assessment Scanning Tools: 5 Solutions Compared

Discover the top 5 vulnerability assessment scanning tools and learn how to prioritize and remediate vulnerabilities to secure your org.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - spring4shell best practices

Get the Response to Spring4Shell Right: Best Practices for Immediate Remediation

Learn best practices for immediate remediation of the Spring4Shell vulnerability, including detection, and prioritization.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - spring4shell fdt blog

Spring4Shell: What to Expect and How to Prepare

Learn about the Spring4Shell vulnerability (CVE-2022-22965), its potential impact, and how to prepare your Java applications.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security - automated software supply chain attacks

Automated Software Supply Chain Attacks: Should You be Worried?

Learn why automated software supply chain attacks are a growing threat. Discover how to protecting your org from malicious NPM packages.

Read More Read More
3 new github features to reinforce your code, repo, and dependency security -

Spring4Shell Zero-Day Vulnerability: Information and Remediation for CVE-2022-22965

Learn about the Spring4Shell Zero-Day Vulnerability CVE-2022-22965 with information, updates, mitigation guidance, and more.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.