No Result
View All Result
  • Login
Thursday, December 4, 2025
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Market Analysis

Software Composition Analysis Is The AppSec Hero We Deserve AND Need

by FeeOnlyNews.com
7 months ago
in Market Analysis
Reading Time: 3 mins read
A A
0
Software Composition Analysis Is The AppSec Hero We Deserve AND Need
Share on FacebookShare on TwitterShare on LInkedIn


Software composition analysis (SCA) stepped out from behind the long shadow of static application security testing (SAST)/dynamic application security testing to prove its worth years ago. And thanks to ambitious bad actors, the complex software supply chain, and generative AI (genAI) coding assistants accelerating overall code volume, SCA solutions are essential to clean up the supply chain and bolster application security.

SCA is also an application security (AppSec) darling for its ability to generate a software bill of materials (SBOM). With the EU’s Cyber Resilience Act finalized, the proposed US Department of Defense Software Fast Track Initiative requiring SBOMs, and governments such as Australia releasing guidelines for software development that include SBOMs, more software suppliers around the world will need to provide SBOMs to win and maintain business. Advanced SCA tools go beyond just generating an SBOM; they continuously monitor for newly disclosed vulnerabilities for proactive alerts and will ingest third-party SBOMs to identify the risk of incorporating a third-party component.

Opportunistic attacks that take advantage of newly introduced vulnerabilities and unpatched software require patience and timing. But attackers can be proactive by directly poisoning open-source and third-party components. These types of attacks, such as dependency confusion and typo squatting, were already on the rise. But now, “slopsquatting” happens when AI hallucinates package names that developers must add. Additionally, bad actors willing to play the long game, typically affiliated with nation states, will bully their way into maintaining obscure but widely used open-source software dependencies such as XZ Utils to bury malicious code and target downstream recipients. SCA solutions provide insight into open-source component health during selection and actively block malicious packages from being downloaded. Clearly, SCA is the AppSec hero we need.

Enterprises have been eager to embed and utilize AI in the customer-facing applications that they build. In Forrester’s 2024 survey of business and technology professionals, 33% reported using genAI in production applications. This means a whole new world of application dependencies consisting of AI models, third-party APIs, and open-source dependencies. Python is a popular language for AI applications, as is the PyPI package manager for open-source dependencies. Bad actors did not waste any time in uploading legitimate-looking but malicious packages that were downloaded hundreds of times by developers building AI applications. Poisoned AI models could be pulled down from Hugging Face and other public repositories. At the time of The Forrester Wave™: Software Composition Analysis Software, Q4 2024 evaluation, only a few SCA vendors were scanning AI models or creating AI bills of materials, but this functionality is needed broadly and quickly.

When thinking about purchasing or upgrading your SCA software, consider key insights we gathered from talking with SCA vendor customers to get the tool you not only deserve but also need:

Evaluate more than one vendor. This may seem obvious, but SCA software differs in functionality and the quality of output. Some software is primarily focused on open-source components, while others go beyond and assess third-party components and even inner-source components (those shared components written by your organization). The quality of the results also differs based on language and ability to detect vulnerabilities in transitive dependencies. Most reference customers evaluated three vendors’ software as part of the purchasing process (see figure below).
Don’t settle. You’re going to be in it for the long haul. Customer references have been with their vendor on average for over 3.5 years. And they are happy! Twenty-two of 28 references rate their vendor at a nine or 10. If you have an SCA solution and you are not satisfied, it’s worth your time to revisit this at the next renewal period.
Keep an eye out for the extras. SCA software vendors have expanded their offering to cover more of the software supply chain, such as offering malicious package detection and package firewall protection, infrastructure as code and container image scanning, and secrets detection. Depending on the vendor and its pricing and packaging model, these capabilities could be add-ons to the base price. Static reachability (the ability to determine whether the vulnerable function is called by the first-party code) should be table stakes for SCA solutions, but some vendors require you to also purchase their static SAST solution to get this level of insight.

 

Be your company’s hero and select an SCA software solution that helps secure your software supply chain by utilizing Forrester’s Buyer’s Guide: Software Composition Analysis Software, 2025, and The Forrester Wave™: Software Composition Analysis Software, Q4 2024. For more insights, schedule a guidance session or inquiry with me. Protecting your brand, your customers’ data, and your revenue is worth the effort.



Source link

Tags: AnalysisAppSecCompositiondeserveHeroSoftware
ShareTweetShare
Previous Post

15 Counties With the Most Housing Growth in the Past 10 Years

Next Post

National Streaming Day Offers You Can Score {Just in Time for Summer Break!}

Related Posts

Holiday Retail Trends 2025: Unwrapping Global Shopping Trends

Holiday Retail Trends 2025: Unwrapping Global Shopping Trends

by FeeOnlyNews.com
December 4, 2025
0

As we look toward the 2025 holiday season, the retail landscape presents a mixed but evolving picture. While economic uncertainty...

9 High-Dividend Real Estate Stocks to Buy and Hold as Fed Prepares to Cut Rates

9 High-Dividend Real Estate Stocks to Buy and Hold as Fed Prepares to Cut Rates

by FeeOnlyNews.com
December 4, 2025
0

Yesterday’s on private-sector job creation disappointed significantly, showing a loss of 32,000 jobs versus the consensus forecast of a 5,000...

Announcing Our Evaluation Of The Agent Control Plane Market

Announcing Our Evaluation Of The Agent Control Plane Market

by FeeOnlyNews.com
December 4, 2025
0

The choice of agentic AI technology for enterprise leaders is best understood as an ecosystem of tech vendors that align...

Bolster Your B2C Marketing Operations Function With This Step-By-Step Blueprint

Bolster Your B2C Marketing Operations Function With This Step-By-Step Blueprint

by FeeOnlyNews.com
December 3, 2025
0

Increasing consumer marketing complexity, especially in the age of AI, demands more marketing operational discipline. B2C marketing operations requires holistic...

Channel Power Marketing

Channel Power Marketing

by FeeOnlyNews.com
December 3, 2025
0

Computer Market Research (CMR): The Ultimate Channel Management Compendium PART 1 Table of Contents for Part 1 Introduction to Channel...

Bitcoin: A Clean Breakout Above K Could Open the Path Toward K

Bitcoin: A Clean Breakout Above $93K Could Open the Path Toward $99K

by FeeOnlyNews.com
December 3, 2025
0

The fourth quarter of this year has been a tough period for . Since the start of October, the world’s...

Next Post
National Streaming Day Offers You Can Score {Just in Time for Summer Break!}

National Streaming Day Offers You Can Score {Just in Time for Summer Break!}

Middle East investment promises balloon to  trillion as Trump keeps jacking up the number

Middle East investment promises balloon to $7 trillion as Trump keeps jacking up the number

  • Trending
  • Comments
  • Latest
Newsom, DeSantis join forces to blast ‘idiotic’ push to allow oil drilling off coasts of California, Florida

Newsom, DeSantis join forces to blast ‘idiotic’ push to allow oil drilling off coasts of California, Florida

November 23, 2025
Israeli housing rental platform Venn raises m

Israeli housing rental platform Venn raises $52m

November 18, 2025
What is a credit card spending limit — and what to know

What is a credit card spending limit — and what to know

August 4, 2025
Trump Insider Deals Nosediving Alongside His Polling Numbers

Trump Insider Deals Nosediving Alongside His Polling Numbers

December 3, 2025
Why Black Friday Is the Best Time to Join AARP

Why Black Friday Is the Best Time to Join AARP

November 25, 2025
Why IT Finance Leaders Must Act Now

Why IT Finance Leaders Must Act Now

November 21, 2025
Finance Minister on 2026 budget: Banks will be taxed

Finance Minister on 2026 budget: Banks will be taxed

0
5 Hidden Network Changes That Could Disrupt Your Medicare Coverage This Year

5 Hidden Network Changes That Could Disrupt Your Medicare Coverage This Year

0
The Disasters of Government Enterprise

The Disasters of Government Enterprise

0
Bitcoin May Have Already Bottomed as Grayscale Projects New Highs

Bitcoin May Have Already Bottomed as Grayscale Projects New Highs

0
American Eagle Rallies On Beat-And-Raise Report, Hiked Analyst Views

American Eagle Rallies On Beat-And-Raise Report, Hiked Analyst Views

0
SoFi stock drops on .5 billion stock offering

SoFi stock drops on $1.5 billion stock offering

0
Bitcoin May Have Already Bottomed as Grayscale Projects New Highs

Bitcoin May Have Already Bottomed as Grayscale Projects New Highs

December 4, 2025
BAT to offload ITC Hotels shares worth Rs 2,948 crore via a block deal

BAT to offload ITC Hotels shares worth Rs 2,948 crore via a block deal

December 4, 2025
Smith & Wesson projects Q3 sales growth of 8%–10% amid inventory reduction and robust new product momentum (NASDAQ:SWBI)

Smith & Wesson projects Q3 sales growth of 8%–10% amid inventory reduction and robust new product momentum (NASDAQ:SWBI)

December 4, 2025
SoFi stock drops on .5 billion stock offering

SoFi stock drops on $1.5 billion stock offering

December 4, 2025
6 January COLA Realities Every Retiree Should Know

6 January COLA Realities Every Retiree Should Know

December 4, 2025
AT&T promised the government it won’t pursue DEI

AT&T promised the government it won’t pursue DEI

December 4, 2025
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Bitcoin May Have Already Bottomed as Grayscale Projects New Highs
  • BAT to offload ITC Hotels shares worth Rs 2,948 crore via a block deal
  • Smith & Wesson projects Q3 sales growth of 8%–10% amid inventory reduction and robust new product momentum (NASDAQ:SWBI)
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.