
The call for funding of open-source platforms
Funding of the OSS ecosystem has reached a crisis as threat actors increasingly target weaknesses in infrastructure.

Funding of the OSS ecosystem has reached a crisis as threat actors increasingly target weaknesses in infrastructure.

If you train ML models, they can learn to write more secure code. But the quality of the training data is only as good as your AppSec tooling.

Developer Productivity Engineering provides a framework to boost code production and creativity — and can help to improve application security.

Researchers at Black Hat discussed how these tools can leave development teams vulnerable to hacks like remote-code execution.

Leading firms are using DevEx to achieve application security gains at speed. Here's how it works — and how to get started.

Here's why your organization should consider using SaaSBOMs, key challenges — and how to put CycloneDX's xBOM standard into action.

Here's what's holding DevSecOps back — and why modernizing your application security tooling is critical in the software supply chain security era.

Combined with cloud service providers' CLIs, continuous delivery/continuous integration can pose a threat. Here's why — and how to keep a lid on your secrets.

Memory safety is one of the most stubborn and dangerous software weaknesses. Here are key insights and takeaways from a new Google report on the issue.

When using AI tools including GitHub Copilot, your security team must be aware of — and protect against — certain risks. Here are the top considerations.

Don't neutralize CI/CD business gains by failing to account for risk. Here are best practices to ensure that your software development pipeline is secure.

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.

What’s to come for the security of open source software? ConversingLabs caught up with Mikaël Barbero of the Eclipse Foundation to answer that question. Watch (or listen) and learn.

"Shift left" is giving way to up-front software risk assessments, and companies are increasingly tapping external support for third-party compliance. Learn more from application security peers.

These leading app sec experts provide a steady flow of security knowledge to keep you up to speed.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial