FOSSA logo
Platform
FOSSA Platform
The Modern Open Source Risk Management Platform
FOSSA Platform
Product
Vulnerability Management
License Compliance
Solutions
SBOM Management
Continuous Compliance
Due Diligence
Shift Code Security Left
Generative AI Risk Management
Resources
Getting Started with FOSSA
Documentation
Blog
Resource Library
Events
tl;drLegal
Company
About FOSSA
Customers
Careers
Partners
Press
Contact Us
For Developers
Pricing
Log In
|
Start for Free
Schedule Demo
Log In
|
Sign Up
|
  • Vulnerability Management
  • License Compliance
  • Open Source in the News
  • Software Composition Analysis
  • Developers
FOSSA Editorial Team

FOSSA Editorial Team

FOSSA's Editorial Team creates content on the wonderful world of open source software.

86 posts •
Open Source Licenses 101: SIL Open Font License (OFL)
Open Source License Compliance

Open Source Licenses 101: SIL Open Font License (OFL)

The SIL Open Font License is an open source license designed for fonts and related software. Explore the license's notable requirements and provisions.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Understanding and Preventing Dependency Confusion Attacks
Open Source Vulnerability Management

Understanding and Preventing Dependency Confusion Attacks

Dependency confusion exploits rely on a quirk in certain package managers. See how these attacks can happen, and get guidance on preventing them.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management
Software Composition Analysis

Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management

See key themes and insights from NIST SP 800-161r1: “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.”

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
The Massive Implications of Software Freedom Conservancy vs. Vizio
Open Source in the News

The Massive Implications of Software Freedom Conservancy vs. Vizio

The Software Freedom Conservancy's lawsuit against Vizio for alleged GPL violations could have significant ramifications for OSS license enforcement.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
Open Source Licenses 101: Boost Software License
Open Source License Compliance

Open Source Licenses 101: Boost Software License

Get an overview of the Boost Software License, including key requirements and permissions, and see how it compares to other permissive licenses.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Open Source Licenses 101: The CDDL (Common Development and Distribution License)
Open Source License Compliance

Open Source Licenses 101: The CDDL (Common Development and Distribution License)

Get an overview of the CDDL (Common Development and Distribution License), including requirements and comparisons to other weak copyleft licenses.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
4 Reasons Rancher Labs Chose FOSSA
Software Composition Analysis

4 Reasons Rancher Labs Chose FOSSA

See why Kubernetes management company Rancher Labs (part of SUSE) chose FOSSA to reduce open source license compliance and vulnerability risk.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
An Overview of Spring RCE Vulnerabilities
Open Source Vulnerability Management

An Overview of Spring RCE Vulnerabilities

A pair of critical remote code execution vulnerabilities impacting Spring were disclosed this week.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
How FOSSA Addresses Challenges Scanning C/C++ Code
Software Composition Analysis

How FOSSA Addresses Challenges Scanning C/C++ Code

Get an overview of challenges with scanning and identifying dependencies in C/C++ code, and see how FOSSA addresses these issues.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
Overriding Dependency Versions and Using Version Ranges in Maven
Developer Perspectives

Overriding Dependency Versions and Using Version Ranges in Maven

Get step-by-step guidance on managing dependencies in Maven: declaring dependencies, overriding dependency versions, and using version ranges.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing
Open Source in the News

5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing

The U.S. Senate's hearing on Log4Shell brought to light new information on the Log4J vulnerability and industry's response to it.

  • FOSSA Editorial Team
    FOSSA Editorial Team
7 min read
6 Takeaways from the Linux Foundation's SBOM Report
Open Source in the News

6 Takeaways from the Linux Foundation's SBOM Report

A new report from the Linux Foundation contains a treasure trove of data on industry attitudes toward SBOMs and software supply chain security.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
5 Must-Have DevSecOps Tools
Software Composition Analysis

5 Must-Have DevSecOps Tools

Software composition analysis, static application security testing, and issue tracking software are examples of mission-critical DevSecOps tools.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
Open Source Developer Sabotages npm Libraries ‘Colors,’ ‘Faker’
Open Source in the News

Open Source Developer Sabotages npm Libraries ‘Colors,’ ‘Faker’

The developer behind popular npm libraries "Colors" and "Faker" intentionally sabotaged both packages. Here's what to do if your application is impacted.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
Q and A: Heather Meeker on AGPL, Truth Social, OSS License Compliance
Open Source License Compliance

Q and A: Heather Meeker on AGPL, Truth Social, OSS License Compliance

Heather Meeker, one of the world's leading OSS license compliance experts, shares insight on the AGPL and the Truth Social license compliance controversy.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
Does TikTok Live Studio Violate GPL v2?
Open Source in the News

Does TikTok Live Studio Violate GPL v2?

TikTok recently released a limited test of a new live streaming service, TikTok Live Studio, that may be in violation of the GPL v2 open source software license.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
FOSSA Partners with OpenChain to Promote Open Source Management
Inside FOSSA

FOSSA Partners with OpenChain to Promote Open Source Management

FOSSA has partnered with OpenChain to help organizations build and maintain successful open source software license compliance programs.

  • FOSSA Editorial Team
    FOSSA Editorial Team
2 min read
FOSSA Product Updates: Announcing Our New and Improved CLI
Inside FOSSA

FOSSA Product Updates: Announcing Our New and Improved CLI

Our upgraded CLI will make FOSSA integrations easier to deploy by reducing the amount of configuration needed by users.

  • FOSSA Editorial Team
    FOSSA Editorial Team
2 min read
DevSecOps 101: Understanding and Implementing DevSecOps Principles
Open Source Vulnerability Management

DevSecOps 101: Understanding and Implementing DevSecOps Principles

See how DevSecOps principles can make software development more secure, and discover strategies for an effective DevSecOps implementation.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Open Source Software Licenses 101: The Eclipse Public License
Open Source License Compliance

Open Source Software Licenses 101: The Eclipse Public License

Get an overview of the Eclipse Public License, including key requirements and how it compares to other weak copyleft open source licenses.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
4 Key Elements of Technical Due Diligence
Software Composition Analysis

4 Key Elements of Technical Due Diligence

Explore key areas of conducting technical due diligence, including auditing third-party software usage and evaluating protections on intellectual property.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
Q and A: Software Bill of Materials and FOSSA
Software Composition Analysis

Q and A: Software Bill of Materials and FOSSA

Get answers to frequently asked questions about using FOSSA to generate a software bill of materials.

  • FOSSA Editorial Team
    FOSSA Editorial Team
6 min read
bouk/monkey and the Importance of Knowing Your Dependencies
Open Source in the News

bouk/monkey and the Importance of Knowing Your Dependencies

A recent news item involving the bouk/monkey open source program shows why it's so important for organizations to have visibility into their dependencies.

  • FOSSA Editorial Team
    FOSSA Editorial Team
4 min read
Role-Based Access Control (RBAC), Zero Trust, and FOSSA
Inside FOSSA

Role-Based Access Control (RBAC), Zero Trust, and FOSSA

Get an overview of FOSSA's role-based access control (RBAC), and see how it can help improve your organization's security posture.

  • FOSSA Editorial Team
    FOSSA Editorial Team
3 min read
3 Best Practices for OSS Management in the Automotive Industry
Software Composition Analysis

3 Best Practices for OSS Management in the Automotive Industry

Experts share tips and strategies to help automotive organizations improve their open source management programs.

  • FOSSA Editorial Team
    FOSSA Editorial Team
5 min read
  • For the Love of Open Source © 2024 FOSSA, Inc.
  • Privacy Policy
  • Terms & Conditions