software dependencies
‘Perfect 10’ Apple Supply Chain Bug — Millions of Apps at Risk of CocoaPods RCE
Richi Jennings | | App Sec & Supply Chain Security, Apple, Apple iOS, AppSec & Supply Chain Security, CocoaPods, CVE-2024-38366, CVE-2024-38368, dependencies, dependency injection, Dependency Management, macos, macOS Security, Modern Software Supply Chains, Open Source and Software Supply Chain Risks, open source software supply chain, open source software supply chain security, SB Blogwatch, software dependencies, Supply-Chain Insecurity, third-party dependencies, trust dependencies
Tim looks grim: 10 year old vulnerabilities in widely used dev tool include a CVSS 10.0 remote code execution bug ...
Security Boulevard
VFCFinder Highlights Security Patches in Open Source Software
Nathan Eddy | | north Carolina state university, open source, security patches, software dependencies, vfc, vfcfinder, vulnerability, Vulnerability Fixing Commits
VFCFinder analyzes commit histories to pinpoint the most likely commits associated with vulnerability fixes ...
Security Boulevard
Why an SBOM is Essential for Software Compliance
rezilion | | Compliance, SBOM, software bill of materials, software dependencies, software licenses, Uncategorized, Vulnerability Management
A software bill of materials (SBOM) can be a powerful tool for enhancing security through improved vulnerability management. It can also help organizations meet their software licensing compliance requirements—no small consideration given ...