Software Composition Analysis SCA vs. SAST: Comparing Security Tools SCA and SAST both support security use cases, but there there are some significant differences between the tools.
Inside FOSSA FOSSA Product Updates: August 2023 Get an overview of additions and improvements to the FOSSA platform, including Jira enhancements and auto-ignore rules.
Software Composition Analysis An Early Look at SPDX 3.0 See what to expect with the upcoming release of SPDX v3.0, such as the introduction of use case-specific profiles and increased flexibility.
Inside FOSSA The FOSSA Podcast: Product Management from Startup to Enterprise The FOSSA Podcast covers engineering-product team collaboration (and friction), product management tools, when to hire your first PM, and more.
Open Source in the News Generative AI and Software Development: Copyright Law and License Compliance See important copyright law and open source license compliance considerations when using generative AI in software development.
Developer Perspectives The FOSSA Podcast: Managing Engineering Projects This episode of The FOSSA Podcast discusses managing engineering projects, including scaling teams, measuring success, and delegating work.
Inside FOSSA Picking the Right FOSSA Deployment Model FOSSA customers can choose from a range of SaaS and on-premises deployment models. See which one is the best fit for your organization.
Software Composition Analysis The FOSSA Podcast: SCA Purchasing and Implementation Trends Episode 4 of The FOSSA Podcast discusses how organizations are evaluating SCA tools along with important factors in a successful implementation.
Software Composition Analysis A Framework for Evaluating SBOM Tools Customizability, ease of use, and support for CycloneDX and SPDX are among the most important features of a best-in-class SBOM tool.
Inside FOSSA The FOSSA Podcast: Structuring and Growing a Customer Success Team This episode of The FOSSA Podcast offers guidance on structuring customer success teams and building a company-wide customer-success mindset.
Open Source License Compliance Containers and Open Source License Compliance There are many open source components in the container ecosystem, which means container users must be mindful of license compliance obligations.
Inside FOSSA The FOSSA Podcast: Early-Stage Technology Decisions and Regrets The second episode of The FOSSA Podcast covers early-stage start-up technology choices, including picking programming languages and databases.
Open Source in the News 2023 Open Source Management Trends, Predictions, and Observations In 2023, we expect organizations to prioritize using SBOM data, automating open source license compliance, and maintaining visibility into software composition.
The FOSSA Podcast: Adopting Haskell into an Existing Codebase Episode One of the FOSSA Podcast covers our team adopted Haskell, characteristics of the language, and pros and cons for teams considering it.
Inside FOSSA How to Use 1Password to Authenticate the FOSSA CLI 1Password has released a shell plugin that will enable FOSSA users to authenticate with a simple fingerprint scan. Here's how to use it.
Software Composition Analysis How Applause Makes Open Source Management Work for Developers See how Applause has built developer-friendly open source license compliance and security programs with a significant assist from FOSSA.
Open Source Vulnerability Management OpenSSL Vulnerability 2022: Details and Fixes Two new high-severity vulnerabilities impacting OpenSSL have been disclosed. Here's what we know about the issues and how to address them.
Open Source in the News CVE-2022-42889 Text4Shell Vulnerability: Impact and Fixes See important details on the Text4Shell vulnerability, including affected versions, how it compares to Log4Shell, and how to identify and remediate it.
Open Source License Compliance Open Source Licenses 101: Microsoft Public License (Ms-PL) Get an overview of the Microsoft Public License (Ms-PL), including key provisions and how it compares to the Microsoft Reciprocal License (Ms-RL).
Open Source in the News Analyzing the Securing Open Source Software Act A new piece of proposed legislation would direct the U.S. federal government to create a framework for assessing security risks in open source software.
Open Source Vulnerability Management U.S. Government Memo Requires Self-Attestation to Secure Development Practices U.S. government agencies must now require software suppliers to self-attest that they have adhered to NIST Guidance for secure software development.
Open Source License Compliance Q and A: Heather Meeker on Hot Topics in OSS License Compliance IP attorney Heather Meeker tackles several hot topics in OSS license compliance, including SBOMs, the AGPL, triggers for distribution, and more.
Inside FOSSA FOSSA Earns Great Place To Work Certification FOSSA has earned the Great Place to Work Certification, which reflects our strong company culture and workplace environment.
Open Source License Compliance Customer Q&A: Collibra's Journey to Scaling OSS License Compliance Amanda Weare, Collibra’s VP and Deputy General Counsel, discusses her experience managing Collibra's open source license compliance program.
Open Source Vulnerability Management How to Implement the CSRB’s Log4j Security Recommendations See guidance for implementing the security recommendations in the CSRB's recent report on the Log4j vulnerability.