ESG Analyst Report on Checkmarx Supply Chain Security
To hunt these threats in open source software supply chains, new techniques must look at the health and wellness of open source projects, the reputation of contributors, anomalous activity such as sudden changes in package publishing routines, as well as performing static and dynamic analysis of package behavior. Performing, consolidating, and analyzing all of this (and more) information beyond the expertise of the vast majority of organizations. In conclusion, Application Security Tools, specifically Software Composition Analysis, must incorporate new techniques to meet modern security challenges in the use of open source software. Read the full ESG Showcase, “Comprehensive Open Source Supply Chain Security: Going Beyond SCA and SBOMs”
Please login to continue
Report Snap Shot
- Open Source Software is an established part of modern application development
- Supply Chain Security presents challenges which Application Security Testing must address
- Solutions include new techniques which go beyond generating Software Bills of Materials
Solution Categories

Cybersecurity Software
Cybersecurity software refers to a specialized type of software designed to protect computer systems...

Network Security Software
Network security software refers to a set of tools and solutions designed to protect computer networ...

Vulnerability Management Software
Vulnerability Management Software refers to a specialized tool or software solution designed to help...

Computer Security Software
Computer security software refers to a suite of programs designed to protect computers and devices f...

Email Security Software
Email security software refers to a specialized tool or program designed to protect email systems an...

Container Security Software
Container security software refers to specialized software tools and solutions designed to protect a...