FOSSA logo
Platform
FOSSA Platform
The Modern Open Source Risk Management Platform
FOSSA Platform
Product
Vulnerability Management
License Compliance
Solutions
SBOM Management
Continuous Compliance
Due Diligence
Shift Code Security Left
Generative AI Risk Management
Resources
Getting Started with FOSSA
Documentation
Blog
Resource Library
Events
tl;drLegal
Company
About FOSSA
Customers
Careers
Partners
Press
Contact Us
For Developers
Pricing
Log In
|
Start for Free
Schedule Demo
Log In
|
Sign Up
|

Dependency Heaven

Open source, dependencies, and licensing by the people at FOSSA.

  • Vulnerability Management
  • License Compliance
  • Open Source in the News
  • Software Composition Analysis
  • Developers
FOSSA Earns Great Place To Work Certification
Inside FOSSA

FOSSA Earns Great Place To Work Certification

FOSSA has earned the Great Place to Work Certification, which reflects our strong company culture and workplace environment.

  • FOSSA Editorial Team
    FOSSA Editorial Team
2 min read
Customer Q&A: Collibra's Journey to Scaling OSS License Compliance
Open Source License Compliance

Customer Q&A: Collibra's Journey to Scaling OSS License Compliance

Amanda Weare, Collibra’s VP and Deputy General Counsel, discusses her experience managing Collibra's open source license compliance program.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
A Practical Guide to the SLSA Framework
Open Source Vulnerability Management

A Practical Guide to the SLSA Framework

SLSA is a Google-created framework designed to help organizations improve the integrity of their software supply chains.

  • John Speed Meyers (Chainguard) and Andy Drukarev (FOSSA)
    John Speed Meyers (Chainguard) and Andy Drukarev (FOSSA)
7 min read
How to Implement the CSRB’s Log4j Security Recommendations
Open Source Vulnerability Management

How to Implement the CSRB’s Log4j Security Recommendations

See guidance for implementing the security recommendations in the CSRB's recent report on the Log4j vulnerability.

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
Rust: How to Transform a Byte Stream for Fun and Profit
Developer Perspectives

Rust: How to Transform a Byte Stream for Fun and Profit

Here's one way to think about Rust readers that plays nicely with the way Rust programmers naturally think about streaming values.

  • Jessica Black
    Jessica Black
4 min read
Why Open Source is ESG
Open Source in the News

Why Open Source is ESG

Leading IP attorney and open source software license compliance expert Heather Meeker explores the connection between ESG investing and OSS.

  • Heather Meeker
    Heather Meeker
5 min read
Announcing the Private Beta of FOSSA Risk Intelligence
Inside FOSSA

Announcing the Private Beta of FOSSA Risk Intelligence

We're excited to announce the private beta of FOSSA Risk Intelligence, which will help users harden their software supply chains.

  • Gauthami Polasani
    Gauthami Polasani
2 min read
Open Source Licenses 101: SIL Open Font License (OFL)
Open Source License Compliance

Open Source Licenses 101: SIL Open Font License (OFL)

The SIL Open Font License is an open source license designed for fonts and related software. Explore the license's notable requirements and provisions.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
How to Build an Open Source License Compliance Program, Featuring Jim Markwith
Open Source License Compliance

How to Build an Open Source License Compliance Program, Featuring Jim Markwith

Technology and transactions attorney Jim Markwith (JD/MBA) lists several key ingredients of a successful open source license compliance program.

  • Jim Markwith
    Jim Markwith
5 min read
Understanding and Preventing Dependency Confusion Attacks
Open Source Vulnerability Management

Understanding and Preventing Dependency Confusion Attacks

Dependency confusion exploits rely on a quirk in certain package managers. See how these attacks can happen, and get guidance on preventing them.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management
Software Composition Analysis

Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management

See key themes and insights from NIST SP 800-161r1: “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.”

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
The Massive Implications of Software Freedom Conservancy vs. Vizio
Open Source in the News

The Massive Implications of Software Freedom Conservancy vs. Vizio

The Software Freedom Conservancy's lawsuit against Vizio for alleged GPL violations could have significant ramifications for OSS license enforcement.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
Open Source Licenses 101: Boost Software License
Open Source License Compliance

Open Source Licenses 101: Boost Software License

Get an overview of the Boost Software License, including key requirements and permissions, and see how it compares to other permissive licenses.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Open Source Licenses 101: The CDDL (Common Development and Distribution License)
Open Source License Compliance

Open Source Licenses 101: The CDDL (Common Development and Distribution License)

Get an overview of the CDDL (Common Development and Distribution License), including requirements and comparisons to other weak copyleft licenses.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Best Practices for Implementing Software Composition Analysis, Featuring Rancher Labs
Software Composition Analysis

Best Practices for Implementing Software Composition Analysis, Featuring Rancher Labs

Rancher Labs Senior Engineering Manager Hayden Barnes shares four strategies to help ensure a successful software composition analysis implementation.

  • Hayden Barnes
5 min read
4 Reasons Rancher Labs Chose FOSSA
Software Composition Analysis

4 Reasons Rancher Labs Chose FOSSA

See why Kubernetes management company Rancher Labs (part of SUSE) chose FOSSA to reduce open source license compliance and vulnerability risk.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
An Overview of Spring RCE Vulnerabilities
Open Source Vulnerability Management

An Overview of Spring RCE Vulnerabilities

A pair of critical remote code execution vulnerabilities impacting Spring were disclosed this week.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
Building a Sustainable Software Supply Chain
Software Composition Analysis

Building a Sustainable Software Supply Chain

OpenChain GM Shane Coughlan discusses indicators of sustainable software and specific steps your organization can take to improve security.

  • Shane Coughlan
10 min read
Announcing New Support for C/C++ Scanning, SBOMs
Inside FOSSA

Announcing New Support for C/C++ Scanning, SBOMs

FOSSA has released new features that enable C/C++ dependency scanning and make it easier for organizations to generate SBOMs.

  • Gauthami Polasani
    Gauthami Polasani
2 min read
How FOSSA Addresses Challenges Scanning C/C++ Code
Software Composition Analysis

How FOSSA Addresses Challenges Scanning C/C++ Code

Get an overview of challenges with scanning and identifying dependencies in C/C++ code, and see how FOSSA addresses these issues.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
The Three Pillars of Reproducible Builds
Developer Perspectives

The Three Pillars of Reproducible Builds

Explore three key principles of designing reproducible builds: repeatable builds, immutable environments, and source availability.

  • Jessica Black
    Jessica Black
7 min read
Overriding Dependency Versions and Using Version Ranges in Maven
Developer Perspectives

Overriding Dependency Versions and Using Version Ranges in Maven

Get step-by-step guidance on managing dependencies in Maven: declaring dependencies, overriding dependency versions, and using version ranges.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing
Open Source in the News

5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing

The U.S. Senate's hearing on Log4Shell brought to light new information on the Log4J vulnerability and industry's response to it.

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
6 Takeaways from the Linux Foundation's SBOM Report
Open Source in the News

6 Takeaways from the Linux Foundation's SBOM Report

A new report from the Linux Foundation contains a treasure trove of data on industry attitudes toward SBOMs and software supply chain security.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
React Security: How to Fix Common Vulnerabilities
Open Source Vulnerability Management

React Security: How to Fix Common Vulnerabilities

Explore several common vulnerabilities that impact React component libraries and see how to remediate them.

  • Gaya Dissanayake
    Gaya Dissanayake
4 min read
  • For the Love of Open Source © 2024 FOSSA, Inc.
  • Privacy Policy
  • Terms & Conditions