FOSSA logo
Platform
FOSSA Platform
The Modern Open Source Risk Management Platform
FOSSA Platform
Product
Vulnerability Management
License Compliance
Solutions
SBOM Management
Continuous Compliance
Due Diligence
Shift Code Security Left
Generative AI Risk Management
Resources
Getting Started with FOSSA
Documentation
Blog
Resource Library
Events
tl;drLegal
Company
About FOSSA
Customers
Careers
Partners
Press
Contact Us
For Developers
Pricing
Log In
|
Start for Free
Schedule Demo
Log In
|
Sign Up
|
  • Vulnerability Management
  • License Compliance
  • Open Source in the News
  • Software Composition Analysis
  • Developers

Open Source in the News

A collection of 42 posts

4 Takeaways from the ESF’s OSS and SBOM Management Recommendations
Open Source in the News

4 Takeaways from the ESF’s OSS and SBOM Management Recommendations

A new publication from the Enduring Security Framework (ESF) working group includes recommendations to help organizations manage SBOMs and OSS-related risks.

  • Cortez Frazier Jr.
    Cortez Frazier Jr.
5 min read
Curl Vulnerabilities: Impact and Fixes (Curl 8.4.0)
Open Source Vulnerability Management

Curl Vulnerabilities: Impact and Fixes (Curl 8.4.0)

New vulnerabilities impacting the popular Curl command line tool and library were disclosed on Oct. 11. See details and fixes.

  • Sara Beaudet
3 min read
5 Ways to Reduce GitHub Copilot Security and Legal Risks
Open Source License Compliance

5 Ways to Reduce GitHub Copilot Security and Legal Risks

See how to manage the potential security, legal, privacy, and maintainability risks that can come with using AI coding tools.

  • Jessica Black
    Jessica Black
6 min read
Business Source License (BSL 1.1): Requirements, Provisions, and History
Open Source License Compliance

Business Source License (BSL 1.1): Requirements, Provisions, and History

See key requirements and provisions in the Business Source License (BSL), a middle ground of sorts between open source and end-user licenses.

  • Manuel Harnisch
    Manuel  Harnisch
5 min read
An Early Look at SPDX 3.0
Software Composition Analysis

An Early Look at SPDX 3.0

See what to expect with the upcoming release of SPDX v3.0, such as the introduction of use case-specific profiles and increased flexibility.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
What’s New in CycloneDX 1.5?
Software Composition Analysis

What’s New in CycloneDX 1.5?

A new version of the CycloneDX bill of materials specification has been released. See what's new in CycloneDX v1.5.

  • Tom Alrich
    Tom Alrich
7 min read
Generative AI and Software Development: Copyright Law and License Compliance
Open Source in the News

Generative AI and Software Development: Copyright Law and License Compliance

See important copyright law and open source license compliance considerations when using generative AI in software development.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
Start-up tech company | Photo via Israel Andrade
Inside FOSSA

The FOSSA Podcast: Early-Stage Technology Decisions and Regrets

The second episode of The FOSSA Podcast covers early-stage start-up technology choices, including picking programming languages and databases.

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
2023 Open Source Management Trends, Predictions, and Observations
Open Source in the News

2023 Open Source Management Trends, Predictions, and Observations

In 2023, we expect organizations to prioritize using SBOM data, automating open source license compliance, and maintaining visibility into software composition.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Complying with GPL v3’s User Product Clause
Open Source License Compliance

Complying with GPL v3’s User Product Clause

Explore strategies for complying with the GPL v3 software license's User Product clause.

  • Chris Stevenson
    Chris Stevenson
5 min read
OpenSSL Vulnerability 2022: Details and Fixes
Open Source Vulnerability Management

OpenSSL Vulnerability 2022: Details and Fixes

Two new high-severity vulnerabilities impacting OpenSSL have been disclosed. Here's what we know about the issues and how to address them.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
CVE-2022-42889 Text4Shell Vulnerability: Impact and Fixes
Open Source in the News

CVE-2022-42889 Text4Shell Vulnerability: Impact and Fixes

See important details on the Text4Shell vulnerability, including affected versions, how it compares to Log4Shell, and how to identify and remediate it.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
Analyzing the Securing Open Source Software Act
Open Source in the News

Analyzing the Securing Open Source Software Act

A new piece of proposed legislation would direct the U.S. federal government to create a framework for assessing security risks in open source software.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
U.S. Government Memo Requires Self-Attestation to Secure Development Practices
Open Source Vulnerability Management

U.S. Government Memo Requires Self-Attestation to Secure Development Practices

U.S. government agencies must now require software suppliers to self-attest that they have adhered to NIST Guidance for secure software development.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
How to Implement the CSRB’s Log4j Security Recommendations
Open Source Vulnerability Management

How to Implement the CSRB’s Log4j Security Recommendations

See guidance for implementing the security recommendations in the CSRB's recent report on the Log4j vulnerability.

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
Why Open Source is ESG
Open Source in the News

Why Open Source is ESG

Leading IP attorney and open source software license compliance expert Heather Meeker explores the connection between ESG investing and OSS.

  • Heather Meeker
    Heather Meeker
5 min read
Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management
Software Composition Analysis

Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management

See key themes and insights from NIST SP 800-161r1: “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.”

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
The Massive Implications of Software Freedom Conservancy vs. Vizio
Open Source in the News

The Massive Implications of Software Freedom Conservancy vs. Vizio

The Software Freedom Conservancy's lawsuit against Vizio for alleged GPL violations could have significant ramifications for OSS license enforcement.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
An Overview of Spring RCE Vulnerabilities
Open Source Vulnerability Management

An Overview of Spring RCE Vulnerabilities

A pair of critical remote code execution vulnerabilities impacting Spring were disclosed this week.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
Building a Sustainable Software Supply Chain
Software Composition Analysis

Building a Sustainable Software Supply Chain

OpenChain GM Shane Coughlan discusses indicators of sustainable software and specific steps your organization can take to improve security.

  • Shane Coughlan
10 min read
5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing
Open Source in the News

5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing

The U.S. Senate's hearing on Log4Shell brought to light new information on the Log4J vulnerability and industry's response to it.

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
6 Takeaways from the Linux Foundation's SBOM Report
Open Source in the News

6 Takeaways from the Linux Foundation's SBOM Report

A new report from the Linux Foundation contains a treasure trove of data on industry attitudes toward SBOMs and software supply chain security.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Open Source Developer Sabotages npm Libraries ‘Colors,’ ‘Faker’
Open Source in the News

Open Source Developer Sabotages npm Libraries ‘Colors,’ ‘Faker’

The developer behind popular npm libraries "Colors" and "Faker" intentionally sabotaged both packages. Here's what to do if your application is impacted.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
Q and A: Heather Meeker on AGPL, Truth Social, OSS License Compliance
Open Source License Compliance

Q and A: Heather Meeker on AGPL, Truth Social, OSS License Compliance

Heather Meeker, one of the world's leading OSS license compliance experts, shares insight on the AGPL and the Truth Social license compliance controversy.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
Does TikTok Live Studio Violate GPL v2?
Open Source in the News

Does TikTok Live Studio Violate GPL v2?

TikTok recently released a limited test of a new live streaming service, TikTok Live Studio, that may be in violation of the GPL v2 open source software license.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
  • For the Love of Open Source © 2024 FOSSA, Inc.
  • Privacy Policy
  • Terms & Conditions