Mend.io Blog

Poisoned axios: npm account takeover, 50 million downloads, and a rat that vanishes after install

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

LATEST
Learn more

Filter & Search

Celebrating pride: lgbtq+ open source projects and programs we love - pride blog 01 1

Celebrating Pride: LGBTQ+ Open Source Projects and Programs We Love

Celebrate Pride with Mend's favorite LGBTQ+ open source projects and programs. Join the movement for equality & inclusivity in tech comunity

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - maven vulnerability blog 1

Research Shows Over 100,000 Libraries Affected By Maven Vulnerability CVE-2021-26291

Research reveals over 100,000 libraries affected by Maven vulnerability CVE-2021-26291. Learn about the risks, fixes, and implications.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - docker encryption

How To Secure Docker Images With Encryption Through Containers

Learn how to secure Docker images with encryption through Containerd. Encrypt your Docker containers to protect sensitive data.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - the source series

Supply Chain Security — 10 Tips That Won’t Slow Development Down

Learn how to protect your software development process from supply chain attacks with these 10 tips that won't slow down your development.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - i love security 1

5 Steps to Get Your Developers to Care More About Security

Learn how to bridge the gap between developers and security with these 5 steps. Make security a top priority.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - python

How To Manage Python Dependencies

Master Python dependency management with pip & explore alternatives like Pipenv and Poetry. Ensure secure, stable, and performant Python apps.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - itemeditorimage 5b21100e36577

9 Best DevSecOps Tools To Integrate Throughout The DevOps Pipeline

Discover the 9 best DevSecOps tools to integrate into your DevOps pipeline. Learn how these tools can help you automate security, & more.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - docker vs kubernetes detailed comparison blog

Docker Vs. Kubernetes: A Detailed Comparison

A detailed comparison of Docker vs. Kubernetes, explaining their differences and similarities. Learn how they complement each other.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - docker in 1

Best Practices For Managing Docker Dependencies

Learn best practices for managing Docker dependencies to ensure reliable, consistent application performance.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - technical due diligence checklist

Top Tips for Technical Due Diligence Process

Review our top tips for technical due diligence process including architecture, people, processes, IP, and roadmap.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love -

Open Source License Comparison: Connecting and Contrasting The Dots

Delve into the world of open source license comparison. Learn about permissive vs. copyleft licenses, limitations, permissions, and more.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - supply chian executive order

Biden’s Cybersecurity Executive Order Focuses on Supply Chain Attacks

Learn about Biden's Cybersecurity Executive Order focused on supply chain attacks & how Mend can help developers create more secure software.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - dependencies blin spot

Why Open Source Dependencies Are Your Blind Spot?

Discover why open source dependencies can be a blind spot for developers. Learn how to gain control and visibility over your dependencies.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - artboard 1 copy

Reducing Enterprise AppSec Risks: Ponemon Report Key Takeaways

Reduce Enterprise AppSec risks with key takeaways from the Ponemon Report. Learn why application layer security is crucial and more.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzviyzcyymqyymzhnmyuanbnjnzlcnnpb249mdawmczzawc9owmwogvlodvjmdcymju2oti0m2m3ytlmnjrhyjdjodk

Open Source Vulnerabilities Overview: Apache Struts vs. Spring

Learn about the open source vulnerabilities in Apache Struts and Spring frameworks, their handling of security issues, and how to manage them.

Read More Read More
Celebrating pride: lgbtq+ open source projects and programs we love - the source series

Three New Supply Chain Attack Methods You Should Be Aware Of

Learn about Imposter Library, Brandjacking, and Security Research Smokescreen methods. Stay informed on the latest supply chain attack methods.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.