Mend.io Blog

Poisoned axios: npm account takeover, 50 million downloads, and a rat that vanishes after install

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

LATEST
Learn more

Filter & Search

Sometimes a vulnerability isn’t so vulnerable - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvjmzmyyzhjyjqyzmquanbnjnzlcnnpb249mdawmczzawc9mtbhnthjzjy0otk4m2rkngm3ymnknjzkyjm0yme2zta

Sometimes A Vulnerability Isn’t So Vulnerable

Discover how sometimes a vulnerability isn't as big of a threat as you may think. Learn about effective vs ineffective vulnerabilities.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvjmwy3ztzmyjhjymuuanbnjnzlcnnpb249mdawmczzawc9mjhkmtk0zjnhzjy3otjmzjnimtg3ogu3odvmzwjkmwu

Who’s been naughty or nice in the Open Source-verse over 2018?

Reflect on the naughty and nice in the Open Source-verse in 2018 with the top vulnerabilities and cool projects.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable -

The National Vulnerability Database Explained

Learn about the National Vulnerability Database (NVD), the largest database of known vulnerabilities. Find out how it differs from the CVE.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - circle

Automating CIRCLECI ORB Updates

Automate CIRCLECI ORB updates with Renovate for low-risk, predictable versioning. Learn how to easily manage dependencies and stay up to date.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - 5 female pioneers of software development blog

5 Female Pioneers of Software Development We’re Grateful For This Thanksgiving

Learn about 5 female pioneers of software development we're grateful for. From Ada Lovelace to Barbara Liskov.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - devsecops 3 1

3 DevOps Security Challenges and How to Overcome Them

Learn how to overcome 3 DevOps security challenges, and how to integrate security into the DevOps pipeline.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - go ina

Automating GO Module Dependency Updates

Learn how to automate GO module dependency updates to save time & ensure consistency with Renovate, an open-source tool.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable -

Creating Your Open Source Policy Template: 3 Points You Don’t Want to Overlook

Learn how to create an effective open source policy template with 3 key points to ensure compliance and enforcement.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable -

Top Open Source Projects To Use For Junior Developers

Discover the top open source projects for junior developers to hone their coding skills. From Apache Commons to Google Guava, & more.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable -

Equifax Breach Year in Review: Vulnerabilities in Apache Struts Still Going Strong

Equifax breach review reveals vulnerabilities in Apache Struts are still unpatched by many companies. Learn why remediation is crucial.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - bitbucket

Automated Dependency Updates For Bitbucket Cloud

Learn how to use Renovate to keep your repositories up-to-date. Self-hosting instructions provided. Beta support available.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - itemeditorimage 5b7538bb4eb42

Zombies: Top 5 Open Source Vulnerabilities That Refuse To Die

Discover the top 5 open source vulnerabilities that still haunt developers. Learn how to protect your applications from security threats.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - itemeditorimage 5b72dd5a76231

The Next Generation of DevOps Adds Security into the Blend

DevOps and DevSecOps are a generation apart from each other, representing a natural evolution to the integration of automated security into the DevOps movement.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvinjk3n2rkntflotquanbnjnzlcnnpb249mdawmczzawc9zmq4y2jiztnln2fhndczyjczytcyn2e5nza2owi0ytk

Dual Licensing for Open Source Components: Yeah or Meh?

Explore the pros & cons of dual licensing for open source components. Learn how it works, its benefits, challenges, & compliance requirements.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable - kubernetes ina

Automated Dependency Updates For Kubernetes Manifests

Learn how to configure file matching with Renovate to keep Docker dependencies up-to-date in manifests.

Read More Read More
Sometimes a vulnerability isn’t so vulnerable -

8 Startup Due Diligence Questions You want to Be Asking

Discover the top 8 due diligence questions to prepare your startup for investment. From technology roadmaps to scalability.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.