Endor Labs stories

GitHub Action compromise affects over 23,000 repositories
Thu, 20th Mar 2025
#
endor labs
A malicious commit in the tj-actions/changed-files GitHub Action, used in over 23,000 repositories, threatens software security across numerous CI pipelines.

Open-source AI Foundation launched to boost transparency
Tue, 25th Feb 2025
#
endor labs
The Open-Source AI Foundation has launched to promote transparency in AI systems for government agencies, coinciding with DeepSeek's commitment to open source its AI models.

GitHub partners with Endor Labs to boost security features
Fri, 14th Feb 2025
#
endor labs
GitHub has partnered with Endor Labs, integrating advanced security software to help developers swiftly identify and manage critical vulnerabilities within the platform.

Opengrep launched by Endor Labs to boost open-source SAST
Fri, 31st Jan 2025
#
endor labs
Endor Labs has unveiled Opengrep, a new venture dedicated to maintaining the open-source integrity of static code analysis tools in application security.

Endor Labs unveils AI open source model discovery tool
Fri, 31st Jan 2025
#
endor labs
Endor Labs has launched AI Model Discovery, a feature helping businesses identify and manage open source AI models, enhancing application security.

Open source software challenges predicted to continue in 2025
Sun, 5th Jan 2025
#
endor labs
Chris Hughes predicts that open source software adoption will grow in 2025, alongside sophisticated attacks and challenges in governance and security.

Microsoft integrates Endor Labs' solution into Defender
Thu, 21st Nov 2024
#
endor labs
Microsoft has integrated Endor Labs' Software Composition Analysis into Defender for Cloud, enabling unified security from code development to runtime.

Endor Labs launches AI model scoring system for security
Fri, 25th Oct 2024
#
endor labs
Endor Labs launches Endor Scores for AI Models, enabling developers to evaluate the security and quality of open source AI models on Hugging Face.

Endor Labs appoints cybersecurity veteran Karl Mattson as CISO
Wed, 25th Sep 2024
#
endor labs
Endor Labs has appointed Karl Mattson, a 25-year cybersecurity veteran, as its first Chief Information Security Officer to bolster software supply chain security.

75% of security patches break software, analysis says
Thu, 19th Sep 2024
#
endor labs
Endor Labs' 2024 Dependency Management Report reveals that 75% of security patches risk breaking software, complicating open source vulnerability management.

Endor Labs unveils tools to enhance OSS security efforts
Tue, 20th Aug 2024
#
endor labs
Endor Labs unveiled Upgrade Impact Analysis and Endor Magic Patches at Black Hat, offering new tools to tackle OSS security risks and accelerate vulnerability remediation.

Endor Labs secures strategic investment from Citi Ventures
Thu, 18th Jul 2024
#
endor labs
Endor Labs secures strategic investment from Citi Ventures, boosting its mission to protect software supply chains for major financial institutions.

Endor Labs warns of critical vulnerabilities in CocoaPods
Wed, 10th Jul 2024
#
endor labs
Endor Labs reveals major security flaws in CocoaPods, threatening apps like Instagram and Uber. Critical CVEs could impact Swift and Objective-C supply chains.

Report reveals reliance on memory-unsafe languages in OSS projects
Tue, 2nd Jul 2024
#
endor labs
A new cybersecurity report reveals that 52% of critical open-source projects rely on memory-unsafe programming languages, posing significant security risks.

Endor Labs forecasts AI & supply chain security hurdles in 2024
Thu, 28th Dec 2023
#
endor labs
Endor Labs warns of anticipated security challenges in artificial intelligence, supply chains, and open source domains for 2024.

Endor Labs releases report on state of open source security
Tue, 13th Dec 2022
#
endor labs
Endor Labs exposes the dangers of unchecked open source software reuse in application development, with 95% of vulnerabilities found in indirect dependencies.