Learn About the New SBOM Capabilities in Veracode Software Composition Analysis Our recent State of Software Security report unveiled that organizations are increasingly leveraging open-source libraries and containers to speed up time to market. While open-source adoption cuts application development time, it also introduces external dependencies on code libraries with many unknowns. To reduce open-source risk, the Biden administration released an Executive Order on Cyber Security that requires vendors selling software to the U.S. government to include a software bill of materials (SBOM) for open-source libraries to ensure that known vulnerabilities are disclosed and trackable. We are happy to report that you can generate SBOMs using our software composition analysis (SCA) tool to help identify vulnerabilities or license risks that may affect your organization. Veracode's REST APIs will be extended to produce a CycloneDX export, making it easy to integrate SBOM Exports into the software development lifecycle. Check out our infosheet to learn more. Best, Brian Roche Chief Product Officer, Veracode |
No comments:
Post a Comment