Developers Need Smarter SCA Tools to Fight Software Supply Chain Attacksby@andrejc
318 reads

Developers Need Smarter SCA Tools to Fight Software Supply Chain Attacks

tldt arrow
Read on Terminal Reader
Read this story w/o Javascript

Too Long; Didn't Read

Software composition analysis (SCA) tools render too many false positives. SCA based on code matching will only find components integrated into a software stack without modification. Pattern recognition and intelligent analysis is needed for components that have been modified in irregular ways. The Apona platform claims to utilize intelligent pattern recognition and deep scanning across file, component, and function levels, detecting OSS with near 100% accuracy.
featured image - Developers Need Smarter SCA Tools to Fight Software Supply Chain Attacks
Andrej HackerNoon profile picture

@andrejc

Andrej


Receive Stories from @andrejc


Credibility

react to story with heart
Andrej HackerNoon profile picture
by Andrej @andrejc.Andrej Černý: CS student from Czechoslovakia. I study the intersection between malware and media.
Read my stories

RELATED STORIES

L O A D I N G
. . . comments & more!
Hackernoon hq - po box 2206, edwards, colorado 81632, usa