13 days agoGovernment Responds to Rising Software Supply Chain Threats
Recent attacks on npm and PyPI ecosystems have highlighted vulnerabilities in software supply chains. Government and industry professionals are urged to enhance security measures to comply with emerging cybersecurity mandates, particularly affecting vendors and developers within the **Indian market**.
16 days agoGovernments Embrace Open-Source Procurement Strategies for Digital Infrastructure
The U.S. Federal Government and Singapore's GovTech are prioritizing open-source software in procurement strategies. This shift aims to enhance maintainability, accessibility, and reduce vendor lock-in, ultimately fostering public value and diverse vendor engagement.
76 days agoSocket Secures $60M to Bolster Software Supply Chain Security
Socket has closed a $60 million Series C funding round to enhance its software supply chain security capabilities. This funding reflects the urgent need for government agencies and contractors to secure open source software and mitigate rising cybersecurity risks, particularly as AI advances in software development.
99 days agoSupply Chain Attack Exposes Vulnerabilities in GitHub and PyPI Packages
A supply chain attack exploited a GitHub Actions vulnerability, leading to a malicious release of the elementary-data package on PyPI. This incident highlights critical procurement implications for government agencies and contractors regarding software supply chain security and dependency management.
106 days agoAgent-bom Unveils AI Supply Chain Scanner for Enhanced Security Management
Agent-bom has launched version 0.80.1 of its open-source AI supply chain security scanner. This tool addresses growing procurement needs for strengthening security across complex environments, particularly in federal sectors looking to enhance compliance and remediation strategies.