WhiteSource Partners With GitHub to Help Developers Code More Securely

WhiteSource, the leader in open source security and license compliance management, announced today a partnership with GitHub, the leading software development platform, to help developers more easily detect open source vulnerabilities in their GitHub repositories.

GitHub launched security alerts in late 2017 to notify developers about vulnerable dependencies in their public and private repositories and identify relevant fixes for JavaScript, Ruby, Java, .NET, and Python.

GitHub is now expanding the offering by partnering with WhiteSource to help broaden the coverage of potential security vulnerabilities in open source projects. WhiteSourceโ€™s vulnerability data aggregates information from the National Vulnerability Database (NVD), security advisories and open source projectsโ€™ issue trackers.

โ€œWe are thrilled to announce this partnership with GitHub, making it easier than ever for developers to detect open source components with known vulnerabilities in their products,โ€ says WhiteSourceโ€™s CEOย Rami Sass. โ€œTogether we will continue to empower developers to harness the power of open source without compromising on security or agility by simplifying the process of finding and fixing open source vulnerabilities.โ€

โ€œOver the past year alone, weโ€™ve sent nearly 27 million security vulnerability alerts to our users,โ€ said Shanku Niyogi, GitHubโ€™s Senior Vice President of Product. โ€œThrough our data partnership with WhiteSource, weโ€™ll be able to further enhance our security vulnerability alerts, providing our customers with the continued security features they need to build secure software.โ€

Mend Partners With GitHub to Help Developers Code More Securely -

About Mend.io

Mend.io is a leading application security solution that helps organizations fix less and reduce risk faster. Built for both AI-driven and modern development workflows, Mend.io gives teams visibility into all code โ€“ human-written, AI-generated, open source, third-party and container components โ€“ and helps them prioritize and remediate the risks that matter most.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.