WhiteSource Partners With GitHub to Help Developers Code More Securely
WhiteSource, the leader in open source security and license compliance management, announced today a partnership with GitHub, the leading software development platform, to help developers more easily detect open source vulnerabilities in their GitHub repositories.
GitHub launched security alerts in late 2017 to notify developers about vulnerable dependencies in their public and private repositories and identify relevant fixes for JavaScript, Ruby, Java, .NET, and Python.
GitHub is now expanding the offering by partnering with WhiteSource to help broaden the coverage of potential security vulnerabilities in open source projects. WhiteSourceโs vulnerability data aggregates information from the National Vulnerability Database (NVD), security advisories and open source projectsโ issue trackers.
โWe are thrilled to announce this partnership with GitHub, making it easier than ever for developers to detect open source components with known vulnerabilities in their products,โ says WhiteSourceโs CEOย Rami Sass. โTogether we will continue to empower developers to harness the power of open source without compromising on security or agility by simplifying the process of finding and fixing open source vulnerabilities.โ
โOver the past year alone, weโve sent nearly 27 million security vulnerability alerts to our users,โ said Shanku Niyogi, GitHubโs Senior Vice President of Product. โThrough our data partnership with WhiteSource, weโll be able to further enhance our security vulnerability alerts, providing our customers with the continued security features they need to build secure software.โ
About Mend.io
Mend.io is a leading application security solution that helps organizations fix less and reduce risk faster. Built for both AI-driven and modern development workflows, Mend.io gives teams visibility into all code โ human-written, AI-generated, open source, third-party and container components โ and helps them prioritize and remediate the risks that matter most.