WhiteSource Develops SBOM Solution to Help Developers Protect Software Supply Chain, Meet New Governmental Regulations

WhiteSource SBOM provides unrivaled visibility into software components and presents a path to remediation for vulnerabilities

TEL AVIV AND BOSTON โ€“ Nov. 9, 2021 โ€“ย In an effort to help developers meet new governmental regulations for protecting the software supply chain,ย WhiteSource, the leader in open source security and management, today releasedย WhiteSource SBOM, a new tool that quickly and easily creates a software bill of materials (SBOM) and uniquely provides a path to remediation when vulnerabilities are identified.

The software supply chain has come under increasing scrutiny since the SolarWinds attack in late 2020, which exposed data from more than 18,000 companies and governmental agencies. In response, theย White House issued an executive orderย that aims to improve the nationโ€™s cybersecurity in order to protect governmental agencies and vital infrastructure from software supply chain attacks. A key part of those efforts is the need for all software to contain SBOMs, a formal, machine-readable inventory of software components and dependencies used to track their supply chain relationships, dependencies, and hierarchical relationships.

WhiteSource SBOM identifies open source libraries, tracks and documents components, and automatically updates when changes are made, providing deep inspection and insight that make it possible to identify unintentional or malicious content being installed during application builds. When vulnerabilities are identified, WhiteSource SBOM provides a path to remediation that ensures updates wonโ€™t break the build.

โ€œAttacks against the software supply chain increased more than 600 percent in the past year, and in two-thirds of those attacks, cyberattackers used code from suppliers to expand the attack,โ€ said Rami Sass, Co-Founder and CEO of WhiteSource. โ€œOrganizations can now leverage WhiteSource SBOM to detect and remediate vulnerabilities, significantly reducing the risk of successful attacks.โ€

To learn more about WhiteSource SBOM and create a trial SBOM, visitย https://www.mend.io/sbom

Mend Develops SBOM Solution to Help Developers Protect Software Supply Chain, Meet New Governmental Regulations - news announcment

About Mend.io

Mend.io is built for every risk, across AI and AppSec. By securing the code layer and the AI layerโ€”and the interactions between them, where modern application risk now livesโ€”Mend.io extends proven AppSec workflows to the models, prompts, and agents inside today’s applications, delivering continuous protection across the entire AI application lifecycle.