Blog

From the Kusari team.

Research, product launches, and field notes on software supply-chain security from the Kusari team.

Stick a Pin in It: Managing Dependencies for Supply Chain Security

Stick a Pin in It: Managing Dependencies for Supply Chain Security

Managing software dependencies is an important part of software supply chain security. Here are three approaches you can take to pin your dependencies to known-good versions.

Software Supply Chain Security Predictions for 2025

Software Supply Chain Security Predictions for 2025

This year, we focus on the evolving role of AI, pressing software security concerns, and emerging regulations.

AI Alone Won’t Fix Your Supply Chain

AI Alone Won’t Fix Your Supply Chain

Properly integrating AI into your processes can help identify risks and offer proactive insights, but the final decisions must always remain in human hands.

Software Supply Chain Security Predictions: Hits & Misses from 2024

Software Supply Chain Security Predictions: Hits & Misses from 2024

As 2025 approaches, it’s time to revisit our 2024 software supply chain security predictions to see how they held up.

Solving the “Bottom Turtle” Problem in Supply Chain Security

Solving the “Bottom Turtle” Problem in Supply Chain Security

Software supply chain security is like a stack of turtles—each layer depends on the integrity of the one below it. Continuous vigilance is key to maintaining security all the way down.

Threat Modeling in the Software Development Life Cycle

Threat Modeling in the Software Development Life Cycle

What are you defending against? From upstream dependencies to code repositories, threat modeling ensures you're prepared to mitigate risks, reduce vulnerabilities, and avoid costly compromises.

Rust Won’t Fix Everything: Moving Toward a Memory-Safe Future

Rust Won’t Fix Everything: Moving Toward a Memory-Safe Future

Rust is promising for addressing memory safety issues. Improving existing C/C++ toolchains will take time, but these steps help set a realistic path forward.

The Best Way to Secure Your Open Source Supply Chain is to Participate

The Best Way to Secure Your Open Source Supply Chain is to Participate

Open source software powers 96% of modern applications, but it comes with challenges. Companies can secure their supply chains by actively participating in the open source projects they rely on.

Is the Internet on Fire? The State of Open Source Security

Is the Internet on Fire? The State of Open Source Security

Amid the flurry of innovation and collaboration at last week's KubeCon North America, a critical theme emerged: the precarious state of open source security.

The Path to Zero CVEs: Vanquishing Cyber Threats

The Path to Zero CVEs: Vanquishing Cyber Threats

Addressing Common Vulnerabilities and Exposures (CVEs) is no longer optional—aiming to eliminate them is a critical priority for securing modern systems.

Is Your Supply Chain Haunted by CVEs?

Is Your Supply Chain Haunted by CVEs?

Secure development starts with developers: bring forth the code masters

Introducing the Kusari Platform—know your software

Introducing the Kusari Platform—know your software

Navigating modern software development is a complex challenge. Kusari’s aim is to make it easier.

You Can’t Fix Issues if You Can’t Find Them

You Can’t Fix Issues if You Can’t Find Them

Organizations often struggle to identify vulnerabilities and risks hidden within the layers of dependencies. Address it by using a holistic approach to software security.

Understanding Prevalence is the First Step

Understanding Prevalence is the First Step

The White House commits $11 million to enhance our collective understanding of the challenges surrounding open source software.

GUAC Boosts License Transparency

GUAC Boosts License Transparency

v0.8.0 features new integration with ClearlyDefined

Hack-Proof Artificial Intelligence Supply Chains Using Open Source Security

Hack-Proof Artificial Intelligence Supply Chains Using Open Source Security

Practical ways to protect against AI software attacks

Why Software Cannot Be Secured by SBOMs Alone

Why Software Cannot Be Secured by SBOMs Alone

Actionable insights come from SBOMs plus additional information

Announcing GUAC v0.8.0 Enhancements

Announcing GUAC v0.8.0 Enhancements

GUAC v0.8.0 brings support for license information, running vuln scans upon SBOM ingestion, node deletion, and many other improvements.

Achieving Wisdom with GUAC Visualizer

Achieving Wisdom with GUAC Visualizer

It's not enough to just have the data, you need to be able to see it.

Meeting Federal Software Supply Chain Mandates

Meeting Federal Software Supply Chain Mandates

Only two months left until the Secure Software Development Attestation Form deadline

To Fork or Not to Fork

To Fork or Not to Fork

How you handle your dependencies will change how you secure your software supply chain

Kusari Signs the Secure by Design Pledge

Kusari Signs the Secure by Design Pledge

The Secure By Design Pledge is a great starting point, but it can’t be the end.

Counting CVEs Was Never Enough

Counting CVEs Was Never Enough

CVE IDs don't tell you much, but somehow we started using them as a proxy for security

Another Turn of the Page: GUAC v0.7.0 Released

Another Turn of the Page: GUAC v0.7.0 Released

Improving performance with pagination and more