The big, gaping hole in software supply chain security
If software supply chains consisted solely of open source code, securing them would be easy. Effective tools and methodologies exist for discovering and remediating software supply chain security risks that arise from open source components. But supply chains also can, and typically do, contain closed-source code derived from third-party sources. Securing this part of the…

