Latest AI and tech news
Learn about the Cyber Resilience Act (CRA) reporting requirements that take effect on 11 September, 2026.
FOSSA has teamed up with leading Nordic solutions provider Nohau to provide tools for managing security, license compliance, and regulatory compliance to their customers.
FOSSA's first Hack House created created significant improvements to the documentation experience for our customers.
How the EU Cyber Resilience Act classifies products with digital elements (Default, Important Class I and II, and Critical), with the full Annex III and Annex IV product lists and what each tier means for self-assessment, third-party conformity assessment, and CE marking.
The EU Cyber Resilience Act compliance timeline explained: entry into force in December 2024, the September 11, 2026 vulnerability reporting deadline, and full conformity with CE marking by December 11, 2027, plus what to prioritize at each stage.
CISA, the U.S. government's Cybersecurity and Infrastructure Security Agency, released an update to its Minimum Elements for a Software Bill of Materials publication.
See what's new with FOSSA's reporting capabilities, including saved report settings and cleaner attribution formatting.
Learn about an under-the-radar IP risk from the use of AI coding assistants.
Leading software supply chain security expert Allan Friedman shares concrete strategies for software producers and consumers to get value from VEX.
See technical details of the latest mini-Shai-Hulud supply-chain attack, including affected packages and remediation strategies.
See analysis of one of the overlooked impacts of recent developments in AI vulnerability discovery and exploitation.
FOSSA CEO Aaron Williams shares his insights on Project Glasswing the new AI-enabled vulnerability exploitation landscape.
fossabot now supports all tiers of GitHub and GitLab for strategic dependency upgrades.
Check out new features available to FOSSA customers, including malware detection, custom risk scores, and more.
fossabot now supports Java ecosystems, including Maven, Gradle and Kotlin codebases.
Get practical guidance for navigating each step of the SBOM management lifecycle.
Leading SBOM and software supply chain expert Allan Friedman analyzes several major SBOM regulations, including PCI DSS and the CRA.
Learn about FOSSA's new malware detection feature, including its benefits and how to use it.
Leading SBOM and software supply chain expert Allan Friedman shares recommendations for SBOM programs at various stages of maturity.
See highlights from ENISA's SBOM implementation guide, including the planning, execution, and monitoring phases of an SBOM program.
fossabot's stategic updates adapt your app code to upstream library changes, now with an enhanced planner and improved CI signals
See technical details and important themes from Germany's influential BSI SBOM guidelines.
Learn about the new features and improvements in CycloneDX 1.7, including new patent-related fields and expanded cryptography support.
Organizations are successfully generating SBOMs for security, regulatory compliance, and business reasons, but struggle with their distribution.
FOSSA's new license concluded feature simplifies the process of analyzing multiple declared and discovered licenses associated with a single dependency.
Learn about Common Platform Enumeration (CPE), including its importance to software transparency and the SBOM ecosystem.
Leading IP attorney and OSS license compliance expert Heather Meeker discuss the license compliance implications of using AI coding assistants.
Dr. Allan Friedman, a globally recognized leader of the SBOM movement, has officially joined FOSSA as a Senior Advisor.
Learn about the two primary techniques OSS license scanners use to detect open source licenses.
Learn about SBOM (software bill of materials) requirements in the FedRAMP Rev5 and the new FedRAMP 20x.
Announcing fossabot, a new AI Agent for making strategic dependency updates, backed by a comprehensive accuracy, consistency, and correctness framework.
FOSSA's path to automated updates and the importance of new technology to accomplish these challenging engineering tasks.
FOSSA has acquired EdgeBit, which pioneered automated dependency updates using a world-class static analysis engine.
Learn why the Shai-Hulud malware is a significant threat to the npm ecosystem, and see how FOSSA's Impact Assessment Tool can help mitigate the risk.
Semantic versioning is a core pillar of responsible open source publishing, but what happens when it's incorrectly used?
FOSSA's new Snippet Scanning product helps organizations manage IP legal risks associated with AI coding tools.
See four methods for generating an SBOM — from source code, from an ecosystem-specific tool, from a container, and from a binary file.
Learn about new SBOM (software bill of materials) requirements from SEBI, India's securities and commodities market regulator.
Learn about five lawsuits that have helped shape global enforcement of open source software licenses.
See five important factors to consider when evaluating SBOM tools for your organization in this buyer's guide.
Learn how FOSSA's Dynamic SBOM Sharing feature facilitates the secure exchange of SBOMs between SBOM distributors and consumers.
Learn about FOSSA's Time-Based Ignore Rules, which help teams implement temporary exceptions to security, license compliance, and quality policies.