---
title: "FOSSA Blog — OSS and SBOM Perspectives | FOSSA"
description: "Learn best practices and stay on top of new developments in open source license compliance, vulnerability management, and SBOM management."
canonical_url: "https://fossa.com/blog/"
markdown_url: "https://fossa.com/blog.md"
language: "en"
author: "FOSSA"
organization: "FOSSA"
---

# FOSSA Blog — OSS and SBOM Perspectives | FOSSA

> Learn best practices and stay on top of new developments in open source license compliance, vulnerability management, and SBOM management.

[All](https://fossa.com/blog.md)[Announcements](https://fossa.com/blog/tag/fossa/)[SBOM](https://fossa.com/blog/tag/sbom/)[Security](https://fossa.com/blog/tag/security/)[Licensing](https://fossa.com/blog/tag/licensing/)[Open Source](https://fossa.com/blog/tag/open-source/)[Press](https://fossa.com/press.md)

## Dependency Heaven

### Latest Articles

[![CISA Releases the 2026 SBOM Minimum Elements](https://fossa.com/_next/image/?url=%2Fcisa-2026-min-elements-feature-image.png&w=3840&q=75)

Jul 30, 2026

9 min

#### CISA Releases the 2026 SBOM Minimum Elements

CISA, the U.S. government's Cybersecurity and Infrastructure Security Agency, released an update to its Minimum Elements for a Software Bill of Materials publication.

CISA, SBOM

Read Article](https://fossa.com/blog/cisa-releases-2026-minimum-sbom-elements.md)

[![Summer 2026 Product Updates: Enhanced Reports](https://fossa.com/_next/image/?url=%2Freports-rewrite-blog-feature-image.png&w=3840&q=75)

Jul 20, 2026

4 min

#### Summer 2026 Product Updates: Enhanced Reports

See what's new with FOSSA's reporting capabilities, including saved report settings and cleaner attribution formatting.

FOSSA

Read Article](https://fossa.com/blog/summer-2026-product-updates-enhanced-reports.md)

[![The Underappreciated OSS License Compliance Risk from AI Coding Tools](https://fossa.com/_next/image/?url=%2Funderappreciated-license-risk-feature-image.png&w=3840&q=75)

Jul 2, 2026

7 min

#### The Underappreciated OSS License Compliance Risk from AI Coding Tools

Learn about an under-the-radar IP risk from the use of AI coding assistants.

AI, Snippet Scanning, AI Guardrails

Read Article](https://fossa.com/blog/underappreciated-oss-license-risk-ai-coding-tools.md)

[![Allan Friedman: Practical Guidance for Managing VEX Workflows](https://fossa.com/_next/image/?url=%2Fallan-friedman-vex-blog-feature-image.png&w=3840&q=75)

Jun 26, 2026

10 min

#### Allan Friedman: Practical Guidance for Managing VEX Workflows

Leading software supply chain security expert Allan Friedman shares concrete strategies for software producers and consumers to get value from VEX.

SBOM, Software Security, VEX

Read Article](https://fossa.com/blog/allan-friedman-practical-guidance-managing-vex-workflows.md)

[![Responding to the Latest Mini-Shai-Hulud Supply Chain Attack](https://fossa.com/_next/image/?url=%2Fmini-shai-hulud-blog-feature-image.png&w=3840&q=75)

May 14, 2026

5 min

#### Responding to the Latest Mini-Shai-Hulud Supply Chain Attack

See technical details of the latest mini-Shai-Hulud supply-chain attack, including affected packages and remediation strategies.

Shai Hulud, Malware, Security

Read Article](https://fossa.com/blog/responding-latest-mini-shai-hulud-supply-chain-attack.md)

[![Project Glasswing and the AI Vulnerability Math Problem](https://fossa.com/_next/image/?url=%2Fglasswing-ai-math-feature-image.png&w=3840&q=75)

Apr 23, 2026

5 min

#### Project Glasswing and the AI Vulnerability Math Problem

See analysis of one of the overlooked impacts of recent developments in AI vulnerability discovery and exploitation.

AI, fossabot, FOSSA

Read Article](https://fossa.com/blog/project-glasswing-ai-vulnerability-math-problem.md)

[![Project Glasswing and Vulnerability Exploitation Velocity](https://fossa.com/_next/image/?url=%2Fglasswing-ceo-blog-feature-image.jpg&w=3840&q=75)

Apr 16, 2026

6 min

#### Project Glasswing and Vulnerability Exploitation Velocity

FOSSA CEO Aaron Williams shares his insights on Project Glasswing the new AI-enabled vulnerability exploitation landscape.

AI, fossabot, FOSSA'

Read Article](https://fossa.com/blog/project-glasswing-vulnerability-exploitation-velocity.md)

[![fossabot expands to all GitHub and GitLab tiers](https://fossa.com/_next/image/?url=%2Ffossabot-vcs-providers.png&w=3840&q=75)

Apr 15, 2026

2 min

#### fossabot expands to all GitHub and GitLab tiers

fossabot now supports all tiers of GitHub and GitLab for strategic dependency upgrades.

FOSSA, fossabot, github, gitlab

Read Article](https://fossa.com/blog/fossabot-expands-github-gitlab.md)

[![Spring 2026 FOSSA Product Updates](https://fossa.com/_next/image/?url=%2F2-updated-spring-fossa-product-updates-feature-image.png&w=3840&q=75)

Apr 14, 2026

3 min

#### Spring 2026 FOSSA Product Updates

Check out new features available to FOSSA customers, including malware detection, custom risk scores, and more.

FOSSA

Read Article](https://fossa.com/blog/spring-2026-fossa-product-updates.md)

[![Java ecosystem support comes to fossabot](https://fossa.com/_next/image/?url=%2Ffossabot-java.png&w=3840&q=75)

Apr 7, 2026

3 min

#### Java ecosystem support comes to fossabot

fossabot now supports Java ecosystems, including Maven, Gradle and Kotlin codebases.

FOSSA, fossabot, java, gradle, kotlin, maven

Read Article](https://fossa.com/blog/fossabot-supports-java-ecosystems/)

[![A Roadmap for Automating the SBOM Management Lifecycle](https://fossa.com/_next/image/?url=%2Fsbom-automation-blog-feature-image.png&w=3840&q=75)

Apr 2, 2026

8 min

#### A Roadmap for Automating the SBOM Management Lifecycle

Get practical guidance for navigating each step of the SBOM management lifecycle.

SBOM, Security

Read Article](https://fossa.com/blog/roadmap-automating-sbom-management-lifecycle.md)

[![Allan Friedman on SBOM Regulations](https://fossa.com/_next/image/?url=%2Fallan-sbom-management-feature-image.png&w=3840&q=75)

Mar 10, 2026

11 min

#### Allan Friedman on SBOM Regulations

Leading SBOM and software supply chain expert Allan Friedman analyzes several major SBOM regulations, including PCI DSS and the CRA.

SBOM, Software Security

Read Article](https://fossa.com/blog/allan-friedman-sbom-regulations.md)

[![Introducing Automated Malware Detection in FOSSA](https://fossa.com/_next/image/?url=%2Ffossa-malware-detection-blog-image.jpg&w=3840&q=75)

Mar 5, 2026

5 min

#### Introducing Automated Malware Detection in FOSSA

Learn about FOSSA's new malware detection feature, including its benefits and how to use it.

Malware, Security, FOSSA

Read Article](https://fossa.com/blog/introducing-automated-malware-detection-fossa.md)

[![Allan Friedman on 4 Stages of SBOM Management](https://fossa.com/_next/image/?url=%2Fallan-sbom-management-feature-image.png&w=3840&q=75)

Feb 23, 2026

7 min

#### Allan Friedman on 4 Stages of SBOM Management

Leading SBOM and software supply chain expert Allan Friedman shares recommendations for SBOM programs at various stages of maturity.

SBOM, Software Security

Read Article](https://fossa.com/blog/allan-friedman-4-stages-sbom-management.md)

[![Highlights from ENISA's SBOM Implementation Guide](https://fossa.com/_next/image/?url=%2Fenisa-blog-feature-image.png&w=3840&q=75)

Feb 5, 2026

10 min

#### Highlights from ENISA's SBOM Implementation Guide

See highlights from ENISA's SBOM implementation guide, including the planning, execution, and monitoring phases of an SBOM program.

ENISA, SBOM, CRA

Read Article](https://fossa.com/blog/highlights-enisa-sbom-implementation-guide.md)

[![fossabot’s Strategic Updates Keep Getting Smarter](https://fossa.com/_next/image/?url=%2Ffossabot-ttm.png&w=3840&q=75)

Jan 9, 2026

8 min

#### fossabot’s Strategic Updates Keep Getting Smarter

fossabot's stategic updates adapt your app code to upstream library changes, now with an enhanced planner and improved CI signals

FOSSA

Read Article](https://fossa.com/blog/autofix-enhanced-dependency-upgrades.md)

[![Germany’s BSI SBOM Guidelines: What You Need to Know](https://fossa.com/_next/image/?url=%2Fgerman-bsi-blog-feature-image.jpg&w=3840&q=75)

Jan 7, 2026

7 min

#### Germany’s BSI SBOM Guidelines: What You Need to Know

See technical details and important themes from Germany's influential BSI SBOM guidelines.

SBOM, Software Security

Read Article](https://fossa.com/blog/germany-bsi-sbom-guidelines.md)

[![What’s New in CycloneDX 1.7](https://fossa.com/_next/image/?url=%2Fcyclone.png&w=3840&q=75)

Dec 10, 2025

3 min

#### What’s New in CycloneDX 1.7

Learn about the new features and improvements in CycloneDX 1.7, including new patent-related fields and expanded cryptography support.

CycloneDX, SBOM, Software Security

Read Article](https://fossa.com/blog/whats-new-cyclone-dx-1-7.md)

[![Comparing Declared and Discovered OSS Licenses](https://fossa.com/_next/image/?url=%2Fdeclared-discovered-feature-image.png&w=3840&q=75)

Nov 25, 2025

4 min

#### Comparing Declared and Discovered OSS Licenses

Organizations are successfully generating SBOMs for security, regulatory compliance, and business reasons, but struggle with their distribution.

OSS, Licenses

Read Article](https://fossa.com/blog/comparing-declared-discovered-oss-licenses.md)

[![Simplifying OSS License Analysis with FOSSA License Concluded](https://fossa.com/_next/image/?url=%2Flicense-concluded-launch-blog-feature-image.png&w=3840&q=75)

Nov 18, 2025

7 min

#### Simplifying OSS License Analysis with FOSSA License Concluded

FOSSA's new license concluded feature simplifies the process of analyzing multiple declared and discovered licenses associated with a single dependency.

Open Source, Licenses, FOSSA

Read Article](https://fossa.com/blog/simplifying-oss-license-analysis-fossa-license-concluded.md)

[![A Practical Guide to Common Platform Enumeration (CPE)](https://fossa.com/_next/image/?url=%2Fcpe-blog-updated-feature-image.png&w=3840&q=75)

Nov 12, 2025

16 min

#### A Practical Guide to Common Platform Enumeration (CPE)

Learn about Common Platform Enumeration (CPE), including its importance to software transparency and the SBOM ecosystem.

CPE, Software Supply Chain

Read Article](https://fossa.com/blog/practical-guide-common-platform-enumeration-cpe.md)

[![Heather Meeker on AI Coding Assistants and OSS License Compliance](https://fossa.com/_next/image/?url=%2Fheather-meeker-ai-blog-feature-image.png&w=3840&q=75)

Oct 31, 2025

7 min

#### Heather Meeker on AI Coding Assistants and OSS License Compliance

Leading IP attorney and OSS license compliance expert Heather Meeker discuss the license compliance implications of using AI coding assistants.

AI, Snippet Scanning, FOSSA

Read Article](https://fossa.com/blog/heather-meeker-ai-coding-assistants-oss-license-compliance.md)

[![FOSSA Welcomes SBOM Pioneer Allan Friedman as a Senior Advisor](https://fossa.com/_next/image/?url=%2Fallan-friedman-blog-feature-image.png&w=3840&q=75)

Oct 29, 2025

4 min

#### FOSSA Welcomes SBOM Pioneer Allan Friedman as a Senior Advisor

Dr. Allan Friedman, a globally recognized leader of the SBOM movement, has officially joined FOSSA as a Senior Advisor.

FOSSA, SBOM

Read Article](https://fossa.com/blog/fossa-welcomes-sbom-pioneer-allan-friedman-senior-advisor.md)

[![How Open Source License Scanners Work](https://fossa.com/_next/image/?url=%2Flicense-scanner-blog-feature-image.png&w=3840&q=75)

Oct 24, 2025

6 min

#### How Open Source License Scanners Work

Learn about the two primary techniques OSS license scanners use to detect open source licenses.

open source, licenses, compliance

Read Article](https://fossa.com/blog/how-open-source-license-scanners-work.md)

[![The Guide to SBOMs and FedRAMP Compliance](https://fossa.com/_next/image/?url=%2Ffedramp-blog-feature-image.png&w=3840&q=75)

Oct 14, 2025

5 min

#### The Guide to SBOMs and FedRAMP Compliance

Learn about SBOM (software bill of materials) requirements in the FedRAMP Rev5 and the new FedRAMP 20x.

SBOM, FedRAMP

Read Article](https://fossa.com/blog/guide-sbom-fedramp-compliance.md)

[![Announcing fossabot: AI Agent for Strategic Dependency Updates](https://fossa.com/_next/image/?url=%2Ffossabot-announcement.png&w=3840&q=75)

Oct 1, 2025

9 min

#### Announcing fossabot: AI Agent for Strategic Dependency Updates

Announcing fossabot, a new AI Agent for making strategic dependency updates, backed by a comprehensive accuracy, consistency, and correctness framework.

FOSSA, fossabot

Read Article](https://fossa.com/blog/fossabot-dependency-upgrade-ai-agent/)

[![Automating Dependency Updates at FOSSA](https://fossa.com/_next/image/?url=%2Ffossabot-tech-pov.png&w=3840&q=75)

Sep 30, 2025

4 min

#### Automating Dependency Updates at FOSSA

FOSSA's path to automated updates and the importance of new technology to accomplish these challenging engineering tasks.

FOSSA

Read Article](https://fossa.com/blog/automating-dependency-updates.md)

[![FOSSA Acquires EdgeBit: From Scanning to Updating](https://fossa.com/_next/image/?url=%2Fedgebit-fossa-large.png&w=3840&q=75)

Sep 29, 2025

4 min

#### FOSSA Acquires EdgeBit: From Scanning to Updating

FOSSA has acquired EdgeBit, which pioneered automated dependency updates using a world-class static analysis engine.

FOSSA

Read Article](https://fossa.com/blog/fossa-acquires-edgebit.md)

[![Shai-Hulud Malware and FOSSA's Impact Assessment Tool](https://fossa.com/_next/image/?url=%2Fshai-hulud-blog-feature-image.png&w=3840&q=75)

Sep 23, 2025

3 min

#### Shai-Hulud Malware and FOSSA's Impact Assessment Tool

Learn why the Shai-Hulud malware is a significant threat to the npm ecosystem, and see how FOSSA's Impact Assessment Tool can help mitigate the risk.

malware, npm, security

Read Article](https://fossa.com/blog/shai-hulud-malware-fossa-impact-assessment-tool.md)

[![Rewriting an NPM Package's Semver Based on Breaking Changes](https://fossa.com/_next/image/?url=%2Fresemver-lodash.png&w=3840&q=75)

Sep 18, 2025

4 min

#### Rewriting an NPM Package's Semver Based on Breaking Changes

Semantic versioning is a core pillar of responsible open source publishing, but what happens when it's incorrectly used?

npm, open source

Read Article](https://fossa.com/blog/breaking-changes-rewriting-semantic-version.md)

[![Manage AI Coding Tool Risks with FOSSA Snippet Scanning](https://fossa.com/_next/image/?url=%2Fsnippet-product-announcement-blog-feature-image-2.png&w=3840&q=75)

Sep 3, 2025

6 min

#### Manage AI Coding Tool Risks with FOSSA Snippet Scanning

FOSSA's new Snippet Scanning product helps organizations manage IP legal risks associated with AI coding tools.

Snippet Scanning, AI, FOSSA

Read Article](https://fossa.com/blog/ai-coding-tool-risks-fossa-snippet-scanning.md)

[![4 Ways to Generate an SBOM](https://fossa.com/_next/image/?url=%2Fgenerate-sbom-blog-feature-image.png&w=3840&q=75)

Aug 19, 2025

7 min

#### 4 Ways to Generate an SBOM

See four methods for generating an SBOM — from source code, from an ecosystem-specific tool, from a container, and from a binary file.

SBOM, Tools

Read Article](https://fossa.com/blog/4-ways-generate-sbom.md)

[![Complying with SEBI SBOM Requirements](https://fossa.com/_next/image/?url=%2Fnaveed-ahmed-9Dt4WutvwDs-unsplash--1-.jpg&w=3840&q=75)

Aug 11, 2025

8 min

#### Complying with SEBI SBOM Requirements

Learn about new SBOM (software bill of materials) requirements from SEBI, India's securities and commodities market regulator.

SBOM, India, SEBI

Read Article](https://fossa.com/blog/complying-sebi-sbom-requirements.md)

[![Analyzing 5 Major OSS License Compliance Lawsuits](https://fossa.com/_next/image/?url=%2Foss-lawsuits-feature-image.png&w=3840&q=75)

Jul 29, 2025

7 min

#### Analyzing 5 Major OSS License Compliance Lawsuits

Learn about five lawsuits that have helped shape global enforcement of open source software licenses.

open-source, licenses

Read Article](https://fossa.com/blog/analyzing-5-major-oss-license-compliance-lawsuits.md)

[![The SBOM Tool Buyer's Guide](https://fossa.com/_next/image/?url=%2Fsbom-buyer-guide-feature-image.png&w=3840&q=75)

Jul 24, 2025

9 min

#### The SBOM Tool Buyer's Guide

See five important factors to consider when evaluating SBOM tools for your organization in this buyer's guide.

SBOM, Tools

Read Article](https://fossa.com/blog/sbom-tool-buyer-guide.md)

[![Introducing Dynamic SBOM Sharing in FOSSA](https://fossa.com/_next/image/?url=%2Fsbom-blog-feature-image.png&w=3840&q=75)

Jul 9, 2025

7 min

#### Introducing Dynamic SBOM Sharing in FOSSA

Learn how FOSSA's Dynamic SBOM Sharing feature facilitates the secure exchange of SBOMs between SBOM distributors and consumers.

SBOM, FOSSA

Read Article](https://fossa.com/blog/introducing-dynamic-sbom-sharing-fossa.md)

[![Operationalizing Exceptions with Time-Based Ignore Rules](https://fossa.com/_next/image/?url=%2Ftime-based-ignore-blog-feature.png&w=3840&q=75)

Jun 24, 2025

4 min

#### Operationalizing Exceptions with Time-Based Ignore Rules

Learn about FOSSA's Time-Based Ignore Rules, which help teams implement temporary exceptions to security, license compliance, and quality policies.

Vulnerability Management, FOSSA, Compliance

Read Article](https://fossa.com/blog/operationalizing-exceptions-time-based-ignore-rules.md)

[![FOSSA Issue Diffs: Understanding Your Evolving Risk Posture](https://fossa.com/_next/image/?url=%2Fissue-diffs-blog-feature-image.png&w=3840&q=75)

Jun 10, 2025

5 min

#### FOSSA Issue Diffs: Understanding Your Evolving Risk Posture

Learn about FOSSA's new Issue Diffs feature, which makes it easy to compare licensing, security, and quality issues between software versions.

product updates, fossa

Read Article](https://fossa.com/blog/issue-diffs-understanding-evolving-risk-posture.md)

[![Understanding the PURL Specification (Package URL)](https://fossa.com/_next/image/?url=%2Fpurl-blog-feature-image.png&w=3840&q=75)

Jun 4, 2025

9 min

#### Understanding the PURL Specification (Package URL)

Learn about PURL — the Package URL Specification — including its utility for SBOM management and how it compares to other unique identifiers.

PURL, SBOM

Read Article](https://fossa.com/blog/understanding-purl-specification-package-url.md)

[![A VP of Engineering’s Perspective on FOSSA’s AI Journey](https://fossa.com/_next/image/?url=%2Fdave-bortz-feature-image.png&w=3840&q=75)

May 28, 2025

8 min

#### A VP of Engineering’s Perspective on FOSSA’s AI Journey

FOSSA's VP of Engineering Dave Bortz shares insight into the FOSSA engineering team's AI coding philosophy.

AI, engineering

Read Article](https://fossa.com/blog/a-vp-engineering-perspective-fossa-ai-journey.md)

[![When Builds Bite Back: The Surprising Pitfalls of Maven Environments and Reproducibility](https://fossa.com/_next/image/?url=%2Fmaven-blog-logo.png&w=3840&q=75)

May 19, 2025

4 min

#### When Builds Bite Back: The Surprising Pitfalls of Maven Environments and Reproducibility

Learn how Maven build environments can introduce non-determinism, and get guidance for managing Maven dependencies with FOSSA.

Maven, builds

Read Article](https://fossa.com/blog/surprising-pitfalls-maven-environments-reproducibility.md)

[![Revisiting FOSSA Hack Week and Its Customer Impact](https://fossa.com/_next/image/?url=%2Fhack-week-feature-image.png&w=3840&q=75)

May 12, 2025

6 min

#### Revisiting FOSSA Hack Week and Its Customer Impact

See how FOSSA's hack week projects are already making a difference for our customers.

FOSSA

Read Article](https://fossa.com/blog/revisiting-fossa-hack-week-customer-impact.md)

[![May 2025 FOSSA Product Updates](https://fossa.com/_next/image/?url=%2FFOSSA%20Product%20Updates.png&w=3840&q=75)

May 5, 2025

3 min

#### May 2025 FOSSA Product Updates

Learn about several recent FOSSA product updates, including container scanning and CycloneDX report improvements.

open-source, product updates

Read Article](https://fossa.com/blog/may-2025-product-updates.md)

[![Annotate Dependencies with Context: Introducing Package Labels in FOSSA](https://fossa.com/_next/image/?url=%2FPackage%20Labels2.png&w=3840&q=75)

Apr 25, 2025

5 min

#### Annotate Dependencies with Context: Introducing Package Labels in FOSSA

Introducing FOSSA Package Labels - a powerful way to annotate packages with contextual metadata, enabling more efficient and insightful reporting and filtering.

dependency management, package labels, open-source

Read Article](https://fossa.com/blog/annotate-dependencies-context-introducing-package-labels.md)

[![Slopsquatting: AI Hallucinations and the New Software Supply Chain Risk](https://fossa.com/_next/image/?url=%2Fslopsquatting-al-blog.jpg&w=3840&q=75)

Apr 21, 2025

8 min

#### Slopsquatting: AI Hallucinations and the New Software Supply Chain Risk

Learn about slopsquatting, an emerging category of software supply chain risk that can stem from AI coding tools.

Software Supply Chain Security, Slopsquatting, AI Coding

Read Article](https://fossa.com/blog/slopsquatting-ai-hallucinations-new-software-supply-chain-risk.md)

[![Introducing FOSSA Binary Composition Analysis (BCA)](https://fossa.com/_next/image/?url=%2Fbca-blog-feature-image.png&w=3840&q=75)

Apr 10, 2025

7 min

#### Introducing FOSSA Binary Composition Analysis (BCA)

FOSSA's new Binary Composition Analysis (BCA) product enables organizations to mange security, license compliance, and SBOMs for binary files.

Binaries, BCA

Read Article](https://fossa.com/blog/introducing-fossa-binary-composition-analysis-bca.md)

[![SBOMs in India: Analyzing CERT-In Guidelines](https://fossa.com/_next/image/?url=%2Fnaveed-ahmed-9Dt4WutvwDs-unsplash--1-.jpg&w=3840&q=75)

Feb 25, 2025

8 min

#### SBOMs in India: Analyzing CERT-In Guidelines

An analysis of the CERT-In guidelines for building and managing an SBOM program, recommended data fields, automation support, and best practices.

SBOM, India, Guidelines

Read Article](https://fossa.com/blog/sboms-india-analyzing-cert-in-guidelines.md)

[![The Role of SBOMs in Managing DORA Compliance](https://fossa.com/_next/image/?url=%2FDORA-Compliance-1.png&w=3840&q=75)

Jan 23, 2025

7 min

#### The Role of SBOMs in Managing DORA Compliance

An exploration of the importance of SBOMs in complying with the EU's Digital Operational Resilience Act (DORA), focusing on software tracking and monitoring requirements for financial entities.

DORA, SBOM

Read Article](https://fossa.com/blog/role-sboms-managing-dora-compliance.md)

[![Winter 2025 FOSSA Product Updates](https://fossa.com/_next/image/?url=%2FFOSSA-Product-Updates.png&w=3840&q=75)

Dec 19, 2024

4 min

#### Winter 2025 FOSSA Product Updates

Explore the new functionalities of FOSSA for managing SBOMs, vulnerabilities, and open source license compliance, including automated NOTICE file recreation and FDA compliance support.

FOSSA, SBOM, License Compliance

Read Article](https://fossa.com/blog/winter-2024-fossa-product-updates.md)

[![License Compliance, SBOM, and Vulnerability Management for Smaller Teams: FOSSA Business Tier](https://fossa.com/_next/image/?url=%2FFOSSA-Business-Tier-texture.png&w=3840&q=75)

Dec 5, 2024

4 min

#### License Compliance, SBOM, and Vulnerability Management for Smaller Teams: FOSSA Business Tier

FOSSA introduces a new business tier tailored for smaller teams, offering flexible pricing and comprehensive features for SBOM, vulnerability management, and license compliance.

SBOM, open-source

Read Article](https://fossa.com/blog/fossa-business-tier.md)

[![New Relic and FOSSA Upgrade Supply Chain Security with Connected Build-Time and Run-Time Vulnerability Management](https://fossa.com/_next/image/?url=%2Fimage--14-.png&w=3840&q=75)

Dec 2, 2024

4 min

#### New Relic and FOSSA Upgrade Supply Chain Security with Connected Build-Time and Run-Time Vulnerability Management

New integration between FOSSA and New Relic provides end-to-end visibility and actionable insights for developers to manage software supply chain security efficiently.

Security, Integration

Read Article](https://fossa.com/blog/new-relic-fossa-vulnerability-management.md)

[![Introducing SBOM Policies in FOSSA](https://fossa.com/_next/image/?url=%2FSBOM-Policy.png&w=3840&q=75)

Nov 21, 2024

5 min

#### Introducing SBOM Policies in FOSSA

Learn about FOSSA's new SBOM policy feature that helps enforce SBOM standards for compliance and security.

SBOM, FOSSA, Compliance

Read Article](https://fossa.com/blog/introducing-sbom-policies-fossa.md)

[![Understanding CVSS: The Common Vulnerability Scoring System](https://fossa.com/_next/image/?url=%2Fcvss-photo-1.jpg&w=3840&q=75)

Nov 8, 2024

9 min

#### Understanding CVSS: The Common Vulnerability Scoring System

An in-depth look at the Common Vulnerability Scoring System (CVSS), its evolution, scoring methods, and its importance in prioritizing vulnerabilities.

CVSS, vulnerability

Read Article](https://fossa.com/blog/understanding-cvss-common-vulnerability-scoring-system.md)

[![Fall 2024 Software Licensing Roundup](https://fossa.com/_next/image/?url=%2Ffall-licensing-roundup.jpg&w=3840&q=75)

Oct 23, 2024

8 min

#### Fall 2024 Software Licensing Roundup

Explore the significant licensing stories of fall 2024, including Elastics return to open source, the new fair source licensing model, and the PearAI controversy.

elastic, licensing, open-source

Read Article](https://fossa.com/blog/fall-2024-software-licensing-roundup.md)

[![A Proposal for the Future of SBOM Minimum Elements](https://fossa.com/_next/image/?url=%2Fsbom-1.png&w=3840&q=75)

Oct 17, 2024

11 min

#### A Proposal for the Future of SBOM Minimum Elements

Exploring the next steps for improving SBOM usability across the ecosystem with new data requirements and considerations for vulnerability management.

SBOM, Cybersecurity

Read Article](https://fossa.com/blog/proposal-future-sbom-minimum-elements.md)

[![Snippet Scanning, Explained](https://fossa.com/_next/image/?url=%2Fsnippet-scanning-feature.png&w=3840&q=75)

Sep 30, 2024

7 min

#### Snippet Scanning, Explained

An in-depth look at snippet scanning tools, their methodologies, and their impact on open source license compliance.

open-source, snippet scanning

Read Article](https://fossa.com/blog/snippet-scanning-explained.md)

[![CUPS Vulnerabilities: Impact and Fixes](https://fossa.com/_next/image/?url=%2FFOSSA-Security-Image.png&w=3840&q=75)

Sep 27, 2024

7 min

#### CUPS Vulnerabilities: Impact and Fixes

Explore the newly discovered vulnerabilities in OpenPrinting's CUPS and their potential impact on UNIX-like operating systems, with guidance on remediation.

CUPS, Vulnerabilities

Read Article](https://fossa.com/blog/cups-vulnerabilities-impact-fixes.md)

[![U.S. Army Announces New SBOM Requirements](https://fossa.com/_next/image/?url=%2FUS%20Army%20SBOM.jpg&w=3840&q=75)

Sep 13, 2024

5 min

#### U.S. Army Announces New SBOM Requirements

The U.S. Army has announced new SBOM requirements for contractors and subcontractors to improve software supply chain security. Learn about the implementation timeline, scope, and how to prepare.

SBOM, U.S. Army

Read Article](https://fossa.com/blog/us-army-announces-new-sbom-requirements.md)

[![SBOM Requirements in the EU’s CRA (Cyber Resilience Act)](https://fossa.com/_next/image/?url=%2FCyber-Resilience-Act.png&w=3840&q=75)

Sep 10, 2024

20 min

#### SBOM Requirements in the EU’s CRA (Cyber Resilience Act)

An overview of the Cyber Resilience Act (CRA) and its implications for SBOM requirements, diving into its standards and comparisons to global initiatives.

SBOM, Cyber Resilience Act, EU Regulations

Read Article](https://fossa.com/blog/sbom-requirements-cra-cyber-resilience-act.md)

[![4 Considerations for Effective SBOM Sharing](https://fossa.com/_next/image/?url=%2FSBOM-Suppliers--1-.png&w=3840&q=75)

Sep 4, 2024

6 min

#### 4 Considerations for Effective SBOM Sharing

Organizations are successfully generating SBOMs for security, regulatory compliance, and business reasons, but struggle with their distribution.

SBOM, Security

Read Article](https://fossa.com/blog/4-considerations-effective-sbom-sharing.md)

[![Actioning the Stakeholder-Specific Vulnerability Categorization (SSVC) Model](https://fossa.com/_next/image/?url=%2FSSVC-Model-1.png&w=3840&q=75)

Aug 14, 2024

23 min

#### Actioning the Stakeholder-Specific Vulnerability Categorization (SSVC) Model

An overview of the CISA Stakeholder-Specific Vulnerability Categorization (SSVC) model, focusing on its decision-making framework to categorize and prioritize vulnerabilities based on unique organizational risk profiles.

vulnerability, security

Read Article](https://fossa.com/blog/actioning-stakeholder-specific-vulnerability-categorization-ssvc-model.md)

[![Automate Regulatory Compliance With FOSSA's New SBOM Management Add-On](https://fossa.com/_next/image/?url=%2FFOSSA-regulations.png&w=3840&q=75)

Aug 8, 2024

14 min

#### Automate Regulatory Compliance With FOSSA's New SBOM Management Add-On

Introducing FOSSAs new SBOM Management add-on to simplify software inventory and compliance processes.

compliance, SBOM

Read Article](https://fossa.com/blog/introducing-fossas-new-sbom-management-add-on.md)

[![FOSSA Acquires StackShare to Enhance Developer Tools Management and Security](https://fossa.com/_next/image/?url=%2Ffossa_stackshare_acqusition_announcement--1-.png&w=3840&q=75)

Aug 1, 2024

4 min

#### FOSSA Acquires StackShare to Enhance Developer Tools Management and Security

FOSSA has acquired StackShare to improve developer tools management and enhance security visibility for enterprises.

Company News, technology, acquisition

Read Article](https://fossa.com/blog/fossa-acquires-stackshare-enhance-developer-tools-management-security.md)

[![Understanding SBOM Requirements in PCI DSS](https://fossa.com/_next/image/?url=%2FPCI-blog-image.png&w=3840&q=75)

Jul 24, 2024

11 min

#### Understanding SBOM Requirements in PCI DSS

This blog post explores the introduction of SBOM requirements in PCI DSS 4.0, detailing the specific requirements and timelines, and suggesting steps for organizations to prepare for the March 2025 enforcement date.

SBOM, PCI DSS, Security

Read Article](https://fossa.com/blog/understanding-sbom-requirements-pci-dss.md)

[![Secure Open Source for All: FOSSA's Free Plan Just Got Better](https://fossa.com/_next/image/?url=%2Ffree-tier-banner.png&w=3840&q=75)

Jul 14, 2024

7 min

#### Secure Open Source for All: FOSSA's Free Plan Just Got Better

FOSSA's free plan now includes security, license compliance, and SBOM management for up to 25 developers and 5 projects.

open-source, security

Read Article](https://fossa.com/blog/secure-open-source-fossa-upgraded-free-plan.md)

[![Polyfill Supply Chain Attack: Details and Fixes](https://fossa.com/_next/image/?url=%2Fmarkus-spiske-FXFz-sW0uwo-unsplash--1-.jpg&w=3840&q=75)

Jul 10, 2024

6 min

#### Polyfill Supply Chain Attack: Details and Fixes

An overview of a significant supply chain attack on the Polyfill CDN service, including its background, impact, and mitigation strategies.

supply chain attack, security

Read Article](https://fossa.com/blog/polyfill-supply-chain-attack-details-fixes.md)

[![Using the CISA Kev Catalog](https://fossa.com/_next/image/?url=%2FCISA-1.png&w=3840&q=75)

Jul 2, 2024

9 min

#### Using the CISA Kev Catalog

Explore how the CISA KEV Catalog aids organizations in vulnerability prioritization and learn about its evaluation process.

vulnerability, security

Read Article](https://fossa.com/blog/using-cisa-kev-catalog.md)

[![Defining SBOM Requirements for Software Suppliers](https://fossa.com/_next/image/?url=%2FSBOM-Suppliers.png&w=3840&q=75)

Jun 11, 2024

11 min

#### Defining SBOM Requirements for Software Suppliers

Explore how to effectively define SBOM requirements for software suppliers to ensure transparency and compliance in procurement processes.

SBOM, Software Suppliers

Read Article](https://fossa.com/blog/defining-sbom-requirements-software-suppliers.md)

[![FOSSA Joins Forces with New Relic in the Secure Developer Alliance](https://fossa.com/_next/image/?url=%2Fnew-relic-fossa--3-.png&w=3840&q=75)

May 7, 2024

3 min

#### FOSSA Joins Forces with New Relic in the Secure Developer Alliance

FOSSA partners with New Relic in the Secure Developer Alliance to enhance vulnerability management with cutting-edge resources and collaborations.

vulnerability management, secure developer alliance

Read Article](https://fossa.com/blog/fossa-joins-forces-new-relic-secure-developer-alliance.md)

[![How Sentry Manages Software License Compliance](https://fossa.com/_next/image/?url=%2Fsentry-wordmark-dark-2400x1200.png&w=3840&q=75)

May 2, 2024

5 min

#### How Sentry Manages Software License Compliance

Discover how Sentry manages software license compliance through policies, processes, and automation using FOSSA's open source management platform.

software licensing, compliance

Read Article](https://fossa.com/blog/sentry-manages-software-license-compliance.md)

[![SPDX 3.0 Is Released](https://fossa.com/_next/image/?url=%2Fsbom-1.png&w=3840&q=75)

Apr 17, 2024

8 min

#### SPDX 3.0 Is Released

SPDX 3.0 introduces new profiles for better use case targeting and flexibility. Major upgrades include changes in document structure, profiles, relationships, and creator information.

SPDX, SBOM

Read Article](https://fossa.com/blog/spdx-3-0.md)

[![What’s New in CycloneDX 1.6?](https://fossa.com/_next/image/?url=%2Fcyclone.png&w=3840&q=75)

Apr 12, 2024

5 min

#### What’s New in CycloneDX 1.6?

Learn about the new features and improvements in CycloneDX 1.6, including Cryptographic BOM, Attestation support, and Machine Learning BOM enhancements.

CycloneDX, SBOM, Software Security

Read Article](https://fossa.com/blog/whats-new-cyclonedx-1-6.md)

[![CVE-2024-3094: New Vulnerability Impacts XZ Utils](https://fossa.com/_next/image/?url=%2Fjj-ying-PDxYfXVlK2M-unsplash--1-.jpg&w=3840&q=75)

Apr 3, 2024

6 min

#### CVE-2024-3094: New Vulnerability Impacts XZ Utils

A new vulnerability, impacting XZ Utils with CVSS severity score of 10, brings potential remote code execution risks.

security, linux, vulnerability

Read Article](https://fossa.com/blog/cve-2024-3094-new-vulnerability-impacts-xz-utils.md)

[![FOSSA Product Updates: Spring 2024](https://fossa.com/_next/image/?url=%2Fimage5-2.gif&w=3840&q=75)

Mar 29, 2024

4 min

#### FOSSA Product Updates: Spring 2024

Explore new features from FOSSA designed to enhance software transparency and mitigate open source risks across your organization.

FOSSA, Product Updates

Read Article](https://fossa.com/blog/fossa-product-updates-march-2024.md)

[![SBOM Formats Explained and Compared](https://fossa.com/_next/image/?url=%2FSBOM-Formats-image-1.png&w=3840&q=75)

Mar 26, 2024

15 min

#### SBOM Formats Explained and Compared

Explore different SBOM formats like SPDX and CycloneDX, their specifications, and their implications for software transparency and cybersecurity.

SBOM, Software Transparency

Read Article](https://fossa.com/blog/sbom-formats-compared-explained.md)

[![Enhancing Risk Observability with FOSSA's Issue Overview Dashboard](https://fossa.com/_next/image/?url=%2Fimage2-1.png&w=3840&q=75)

Mar 21, 2024

4 min

#### Enhancing Risk Observability with FOSSA's Issue Overview Dashboard

Explore FOSSA's Issue Overview Dashboard to enhance your software's risk observability with insights into security, licensing, and quality issues.

risk management, FOSSA

Read Article](https://fossa.com/blog/enhancing-risk-observability-fossas-issue-overview-dashboard.md)

[![Beyond Vulnerabilities: Understanding Package Health with FOSSA Quality](https://fossa.com/_next/image/?url=%2FPackage%20Health%20Image.png&w=3840&q=75)

Mar 12, 2024

4 min

#### Beyond Vulnerabilities: Understanding Package Health with FOSSA Quality

Explore FOSSA Quality's tools for assessing and improving the health of your software's open source components.

FOSSA, Open Source

Read Article](https://fossa.com/blog/understanding-package-health-fossa-quality.md)

[![Complying with the FDA’s SBOM Requirements](https://fossa.com/_next/image/?url=%2FFDA-blog-image.png&w=3840&q=75)

Mar 8, 2024

11 min

#### Complying with the FDA’s SBOM Requirements

Explore the FDA's new SBOM requirements for medical devices, detailing the scope, structure, and support information needed for compliance.

FDA, SBOM, Cybersecurity

Read Article](https://fossa.com/blog/complying-fdas-sbom-requirements.md)

[![Enable Global Visibility and Swift Remediation with Package Index](https://fossa.com/_next/image/?url=%2Fimage4.gif&w=3840&q=75)

Feb 2, 2024

4 min

#### Enable Global Visibility and Swift Remediation with Package Index

Explore how FOSSA’s Package Index enhances software supply chain visibility, enabling swift vulnerability detection and remediation.

Package Index, Security, Software

Read Article](https://fossa.com/blog/enable-global-visibility-swift-remediation-package-index.md)

[![4 Takeaways from the ESF's OSS and SBOM Management Recommendations](https://fossa.com/_next/image/?url=%2FESF%20Takeaways%20Image.png&w=3840&q=75)

Jan 26, 2024

7 min

#### 4 Takeaways from the ESF's OSS and SBOM Management Recommendations

A summary of the key insights from the ESF's latest recommendations on OSS and SBOM management.

ESF, SBOM, Open Source Software

Read Article](https://fossa.com/blog/takeaways-esf-oss-sbom-recommendations.md)

[![Reduce Alert Fatigue with FOSSA’s Auto-Ignore Rules](https://fossa.com/_next/image/?url=%2Fauto-ignore-v2.png&w=3840&q=75)

Jan 9, 2024

4 min

#### Reduce Alert Fatigue with FOSSA’s Auto-Ignore Rules

Learn how FOSSA’s auto-ignore rules streamline license compliance and vulnerability remediation by minimizing redundant alerts.

FOSSA, Auto-Ignore, Open Source

Read Article](https://fossa.com/blog/reduce-alert-fatigue-auto-ignore-rules.md)

[![Terrapin (CVE-2023-48795): New Attack Impacts the SSH Protocol](https://fossa.com/_next/image/?url=%2FPhoto-ssh.jpg&w=3840&q=75)

Dec 22, 2023

4 min

#### Terrapin (CVE-2023-48795): New Attack Impacts the SSH Protocol

Researchers from Ruhr University Bochum have uncovered Terrapin, a new SSH vulnerability (CVE-2023-48795) allowing man-in-the-middle attacks, affecting widely used SSH applications.

Cybersecurity, SSH

Read Article](https://fossa.com/blog/terrapin-cve-2023-48795-new-attack-ssh-protocol.md)

[![SCA vs. SAST: Comparing Security Tools](https://fossa.com/_next/image/?url=%2FSCA-SAST.png&w=3840&q=75)

Dec 20, 2023

11 min

#### SCA vs. SAST: Comparing Security Tools

A detailed comparison of SCA and SAST security tools, highlighting their differences and combined use for enhanced security.

security, SCA

Read Article](https://fossa.com/blog/sca-vs-sast-comparing-security-tools.md)

[![Dual-Licensing Models Explained, Featuring Heather Meeker](https://fossa.com/_next/image/?url=%2FDual-Licensing--1-.png&w=3840&q=75)

Dec 13, 2023

6 min

#### Dual-Licensing Models Explained, Featuring Heather Meeker

Understanding dual licensing with insights from Heather Meeker, covering scenarios for choice-of-license and multi-license models, and managing associated risks.

licensing, open-source

Read Article](https://fossa.com/blog/dual-licensing-models-explained.md)

[![A Comprehensive Guide to Source-Available Software Licenses, Featuring Heather Meeker](https://fossa.com/_next/image/?url=%2FSource%20Available%20Image.png&w=3840&q=75)

Dec 5, 2023

12 min

#### A Comprehensive Guide to Source-Available Software Licenses, Featuring Heather Meeker

Explore the intricacies of source-available software licenses, contrasting them with open-source and proprietary licenses.

software licenses, open-source, source-available

Read Article](https://fossa.com/blog/comprehensive-guide-source-available-software-licenses.md)

[![Understanding and Using the EPSS Scoring System](https://fossa.com/_next/image/?url=%2FEPSS%20Blog%20Image.png&w=3840&q=75)

Nov 17, 2023

7 min

#### Understanding and Using the EPSS Scoring System

Explore the EPSS scoring system and how it helps prioritize vulnerability exploitability.

EPSS, Scoring System

Read Article](https://fossa.com/blog/understanding-using-epss-scoring-system.md)

[![Best Practices for Generating High-Quality SBOMs](https://fossa.com/_next/image/?url=%2FGenerate%20SBOM%20Image.png&w=3840&q=75)

Oct 26, 2023

10 min

#### Best Practices for Generating High-Quality SBOMs

Explore crucial elements for creating high-quality SBOMs including tooling, integration strategies, configuration, and data fields in compliance with licensing and security requirements.

software, SBOM

Read Article](https://fossa.com/blog/best-practices-generating-high-quality-sboms.md)

[![Curl Vulnerabilities: Impact and Fixes (Curl 8.4.0)](https://fossa.com/_next/image/?url=%2Fcurl.png&w=3840&q=75)

Oct 13, 2023

4 min

#### Curl Vulnerabilities: Impact and Fixes (Curl 8.4.0)

Curl 8.4.0 addresses two critical vulnerabilities; learn the impacts and recommended fixes.

curl, vulnerabilities

Read Article](https://fossa.com/blog/curl-vulnerabilities-impact-fixes-curl-8-4-0.md)

[![5 Ways to Reduce GitHub Copilot Security and Legal Risks](https://fossa.com/_next/image/?url=%2FAI-tools-scaled.png&w=3840&q=75)

Oct 6, 2023

8 min

#### 5 Ways to Reduce GitHub Copilot Security and Legal Risks

Explore strategies to mitigate security and legal risks associated with GitHub Copilot and similar AI tools.

AI, GitHub Copilot

Read Article](https://fossa.com/blog/5-ways-to-reduce-github-copilot-security-and-legal-risks.md)

[![SBOM Examples, Explained](https://fossa.com/_next/image/?url=%2FSBOM-Examples.png&w=3840&q=75)

Sep 26, 2023

10 min

#### SBOM Examples, Explained

Explore the world of Software Bill of Materials (SBOMs) with examples and explanations of popular formats like SPDX and CycloneDX.

SBOM, SPDX, CycloneDX

Read Article](https://fossa.com/blog/sbom-examples-explained.md)

[![Understanding and Using SPDX License Identifiers and License Expressions](https://fossa.com/_next/image/?url=%2Fspdx.png&w=3840&q=75)

Sep 11, 2023

7 min

#### Understanding and Using SPDX License Identifiers and License Expressions

An overview of SPDX License Identifiers and Expressions and how they streamline open source licensing communication.

SPDX, Licensing

Read Article](https://fossa.com/blog/understanding-using-spdx-license-identifiers-license-expressions.md)

[![Business Source License (BSL 1.1): Requirements, Provisions, and History](https://fossa.com/_next/image/?url=%2Fbuisness-source-license.png&w=3840&q=75)

Aug 23, 2023

11 min

#### Business Source License (BSL 1.1): Requirements, Provisions, and History

The Business Source License (BSL) is a hybrid between open source and end-user licenses, providing a unique balance of access and restrictions. Learn about its requirements, provisions, and history in this comprehensive guide.

BSL, software-licensing

Read Article](https://fossa.com/blog/business-source-license-requirements-provisions-history.md)

[![5 Ways an SBOM Can Strengthen Security](https://fossa.com/_next/image/?url=%2FSBOM-Security.png&w=3840&q=75)

Aug 18, 2023

6 min

#### 5 Ways an SBOM Can Strengthen Security

Explore how a software bill of materials (SBOM) can enhance your organization's security by providing visibility into open source vulnerabilities, improving software supply chain transparency, enabling VEX, supporting vulnerability remediation, and flagging high-risk components.

SBOM, Security

Read Article](https://fossa.com/blog/5-ways-sboms-can-strengthen-security.md)

[![FOSSA Product Updates: August 2023](https://fossa.com/_next/image/?url=%2FUntitled-Artwork--2-.jpg&w=3840&q=75)

Aug 10, 2023

4 min

#### FOSSA Product Updates: August 2023

Discover the latest enhancements and features introduced by FOSSA, designed to improve your experience with our platform.

FOSSA, Product Updates

Read Article](https://fossa.com/blog/product-updates-august-2023.md)

[![Direct Dependencies vs. Transitive Dependencies](https://fossa.com/_next/image/?url=%2Fcarbon.png&w=3840&q=75)

Aug 3, 2023

3 min

#### Direct Dependencies vs. Transitive Dependencies

Explore the differences between direct and transitive dependencies, and how they impact your project's development and maintenance.

dependencies, programming

Read Article](https://fossa.com/blog/direct-dependencies-vs-transitive-dependencies.md)

[![Vulnerability Remediation Tactics](https://fossa.com/_next/image/?url=%2Fdependencies-2.png&w=3840&q=75)

Jul 12, 2023

11 min

#### Vulnerability Remediation Tactics

Explore strategies for addressing vulnerabilities in third-party components, including patching and upgrading methods.

security, dependencies

Read Article](https://fossa.com/blog/vulnerability-remediation-tactics.md)

[![What’s New in CycloneDX 1.5?](https://fossa.com/_next/image/?url=%2FCycloneDX-1.5.png&w=3840&q=75)

Jun 29, 2023

9 min

#### What’s New in CycloneDX 1.5?

The CycloneDX team released version 1.5, building on existing capabilities and introducing enhancements such as the Authoritative Guide to SBOM.

CycloneDX, SBOM, software

Read Article](https://fossa.com/blog/whats-new-cyclonedx-1-5.md)

[![VEX (Vulnerability Exploitability eXchange): Purpose and Use Cases](https://fossa.com/_next/image/?url=%2Ffossa-security-6-23.jpg&w=3840&q=75)

Jun 8, 2023

14 min

#### VEX (Vulnerability Exploitability eXchange): Purpose and Use Cases

Explore the purpose and significance of VEX (Vulnerability Exploitability eXchange) in managing software vulnerabilities, detailing its necessity, applications, and future implications for suppliers and users.

cybersecurity, risk management

Read Article](https://fossa.com/blog/vulnerability-exploitability-exchange-vex-purpose-use-cases.md)

[![The FOSSA Podcast: Product Management from Startup to Enterprise](https://fossa.com/_next/image/?url=%2FUntitled-design--3-.png&w=3840&q=75)

May 24, 2023

12 min

#### The FOSSA Podcast: Product Management from Startup to Enterprise

In this episode of The FOSSA Podcast, our senior product manager and a longtime engineer discuss product development's evolution as companies grow, including collaboration, management tools, and growth vs. retention strategies.

product management, start-up, enterprise

Read Article](https://fossa.com/blog/fossa-podcast-product-management-startup-to-enterprise.md)

[![Generative AI and Software Development: Copyright Law and License Compliance](https://fossa.com/_next/image/?url=%2Fmaximalfocus-0n4jhVGS4zs-unsplash--1-.jpg&w=3840&q=75)

May 16, 2023

8 min

#### Generative AI and Software Development: Copyright Law and License Compliance

Explores the impact of recent U.S. Copyright Office decisions on generative AI, potential risks from open source licensing, and strategies to mitigate IP risk in software development.

AI, software development, snippet scanning

Read Article](https://fossa.com/blog/generative-ai-and-software-development-copyright-law-and-license-compliance.md)

[![The FOSSA Podcast: Managing Engineering Projects](https://fossa.com/_next/image/?url=%2Fjoshua-reddekopp-SyYmXSDnJ54-unsplash--1-.jpg&w=3840&q=75)

Apr 28, 2023

7 min

#### The FOSSA Podcast: Managing Engineering Projects

The fifth episode of The FOSSA Podcast discusses managing engineering projects with insights from FOSSA’s VP of Engineering and a senior developer.

engineering, project management

Read Article](https://fossa.com/blog/fossa-podcast-managing-engineering-projects.md)

[![Heather Meeker on Open Source License Compliance Policies](https://fossa.com/_next/image/?url=%2Fheather-oss-tools2.png&w=3840&q=75)

Apr 26, 2023

11 min

#### Heather Meeker on Open Source License Compliance Policies

Discussion on tailoring open source license compliance policies for different deployment models, including strategies for SaaS, mobile apps, and embedded systems.

Open Source, License Compliance

Read Article](https://fossa.com/blog/heather-meeker-open-source-license-compliance-policies.md)

[![Picking the Right FOSSA Deployment Model](https://fossa.com/_next/image/?url=%2FFOSSA-Deployment.png&w=3840&q=75)

Apr 24, 2023

5 min

#### Picking the Right FOSSA Deployment Model

Explore the differences between FOSSA's deployment models and find the best option for your organization.

deployment, FOSSA

Read Article](https://fossa.com/blog/picking-the-right-fossa-deployment-model.md)

[![The FOSSA Podcast: SCA Purchasing and Implementation Trends](https://fossa.com/_next/image/?url=%2FUntitled-design--2-.png&w=3840&q=75)

Apr 4, 2023

4 min

#### The FOSSA Podcast: SCA Purchasing and Implementation Trends

A discussion on open source usage and software composition analysis tools to manage OSS license compliance and security risks.

open-source, security

Read Article](https://fossa.com/blog/fossa-podcast-sca-purchasing-implementation-trends.md)

[![How to Find the Best SBOM Tool for Your Organization](https://fossa.com/_next/image/?url=%2FSBOM-tools-framework2.png&w=3840&q=75)

Mar 29, 2023

12 min

#### How to Find the Best SBOM Tool for Your Organization

See important criterial for evaluating SBOM tools and picking the best one for your organization.

SBOM, Tools

Read Article](https://fossa.com/blog/framework-evaluating-sbom-tools/)

[![The FOSSA Podcast: Structuring and Growing a Customer Success Team](https://fossa.com/_next/image/?url=%2Frineshkumar-ghirao-UdDjFekHQuk-unsplash--1-.jpg&w=3840&q=75)

Mar 9, 2023

8 min

#### The FOSSA Podcast: Structuring and Growing a Customer Success Team

The third episode of The FOSSA Podcast discusses managing strategic customer relationships, offering guidance on structuring customer success teams and building a company-wide customer-success mindset.

customer success, podcast

Read Article](https://fossa.com/blog/fossa-podcast-structuring-growing-customer-success-team.md)

[![Containers and Open Source License Compliance](https://fossa.com/_next/image/?url=%2Fcontainer-security-2.png&w=3840&q=75)

Mar 2, 2023

12 min

#### Containers and Open Source License Compliance

An exploration of open source license compliance in the container ecosystem, discussing key components and compliance strategies.

open-source, license compliance

Read Article](https://fossa.com/blog/containers-open-source-license-compliance.md)

[![The FOSSA Podcast: Early-Stage Technology Decisions and Regrets](https://fossa.com/_next/image/?url=%2Fisrael-andrade-YI_9SivVt_s-unsplash--1-.jpg&w=3840&q=75)

Feb 21, 2023

10 min

#### The FOSSA Podcast: Early-Stage Technology Decisions and Regrets

In the second episode of the FOSSA Engineering Podcast, engineers reflect on early-stage technology choices and offer guidance for developers facing similar decisions.

technology decisions, podcast

Read Article](https://fossa.com/blog/fossa-podcast-early-stage-technology-decisions-and-regrets.md)

[![2023 Open Source Management Trends, Predictions, and Observations](https://fossa.com/_next/image/?url=%2F0SS-Trends.png&w=3840&q=75)

Feb 16, 2023

7 min

#### 2023 Open Source Management Trends, Predictions, and Observations

Explore trends, predictions, and observations on mission-critical open source management, including SBOM data usage, license compliance automation, and more.

open-source, software management

Read Article](https://fossa.com/blog/2023-open-source-management-trends-predictions-observations.md)

[![The FOSSA Podcast: Adopting Haskell into an Existing Codebase](https://fossa.com/_next/image/?url=%2FUntitled-design.png&w=3840&q=75)

Feb 3, 2023

12 min

#### The FOSSA Podcast: Adopting Haskell into an Existing Codebase

FOSSA's podcast explores the adoption of Haskell into its codebase, discussing the reasons and benefits of the functional programming language.

Haskell, Programming, Podcast

Read Article](https://fossa.com/blog/fossa-podcast-adopting-haskell.md)

[![How to Operationalize SBOMs Throughout the SDLC](https://fossa.com/_next/image/?url=%2FOperationalize-SBOM.jpg&w=3840&q=75)

Jan 26, 2023

6 min

#### How to Operationalize SBOMs Throughout the SDLC

Discover how businesses can leverage software bill of materials (SBOMs) throughout the software development lifecycle (SDLC) to manage risks including software supply chain security and open-source license compliance.

SBOM, SDLC

Read Article](https://fossa.com/blog/how-operationalize-sboms-throughout-sdlc.md)

[![Announcing Support for CycloneDX and SBOM Import](https://fossa.com/_next/image/?url=%2Fcyclonedx-sbom-import-image.png&w=3840&q=75)

Jan 11, 2023

3 min

#### Announcing Support for CycloneDX and SBOM Import

Discover FOSSA's latest updates enhancing SBOM management and new support for the CycloneDX SBOM standard.

SBOM, CycloneDX

Read Article](https://fossa.com/blog/announcing-support-cyclonedx-sbom-import.md)

[![How to Use 1Password to Authenticate the FOSSA CLI](https://fossa.com/_next/image/?url=%2F1pw-blog-feature-image.png&w=3840&q=75)

Jan 4, 2023

4 min

#### How to Use 1Password to Authenticate the FOSSA CLI

Learn how to authenticate the FOSSA CLI using 1Password's shell plugin for secure and easy integration.

FOSSA, 1Password

Read Article](https://fossa.com/blog/use-1password-authenticate-fossa-cli.md)

[![How Applause Makes Open Source Management Work for Developers](https://fossa.com/_next/image/?url=%2Fapplause-final.png&w=3840&q=75)

Dec 13, 2022

8 min

#### How Applause Makes Open Source Management Work for Developers

Discover how Applause, led by CTO Rob Mason, leverages FOSSA to optimize open source management, reducing burdens on developers.

open-source, software management

Read Article](https://fossa.com/blog/how-applause-makes-open-source-management-work-for-developers.md)

[![Complying with GPL v3’s User Product Clause](https://fossa.com/_next/image/?url=%2Ftv2.jpeg&w=3840&q=75)

Nov 30, 2022

8 min

#### Complying with GPL v3’s User Product Clause

Explore the GPL v3's 'User Product' clause and strategies for compliance, addressing challenges faced by manufacturers while protecting user freedom.

GPL v3, open-source, User Product

Read Article](https://fossa.com/blog/complying-gpl-v3s-user-product-clause.md)

[![Managing OSS License Compliance Risks in Commercial Software Licensing Agreements, Featuring Jim Markwith](https://fossa.com/_next/image/?url=%2Fjim-9.png&w=3840&q=75)

Nov 17, 2022

9 min

#### Managing OSS License Compliance Risks in Commercial Software Licensing Agreements, Featuring Jim Markwith

Explore the evolution of open source software license compliance risks and best practices in commercial software agreements.

OSS, License Compliance

Read Article](https://fossa.com/blog/managing-oss-license-compliance-risks-commercial-software-licensing-agreements.md)

[![Announcing the GA of C and C++ Security and License Scanning](https://fossa.com/_next/image/?url=%2FCC--.png&w=3840&q=75)

Nov 1, 2022

3 min

#### Announcing the GA of C and C++ Security and License Scanning

FOSSA announces the general availability of its security and license scanning for C and C++ projects, offering tailored solutions for dependency identification.

C++, Security

Read Article](https://fossa.com/blog/announcing-c-security-license-scanning-ga.md)

[![November 2022 FOSSA Product Updates](https://fossa.com/_next/image/?url=%2FProduct-updates--2-.png&w=3840&q=75)

Nov 1, 2022

3 min

#### November 2022 FOSSA Product Updates

Enhancements to FOSSA's platform with new C/C++ support, issue resolution updates, container scanning improvements, and Azure integration.

software updates, C/C++, Azure

Read Article](https://fossa.com/blog/november-2022-fossa-product-updates.md)

[![OpenSSL Vulnerability 2022: Details and Fixes](https://fossa.com/_next/image/?url=%2Fopenssl.png&w=3840&q=75)

Oct 31, 2022

4 min

#### OpenSSL Vulnerability 2022: Details and Fixes

This post discusses two high-severity vulnerabilities impacting OpenSSL versions 3.0 and later, including details on how to find and fix them.

OpenSSL, Security

Read Article](https://fossa.com/blog/openssl-vulnerability-2022-details-fixes.md)

[![CVE-2022-42889 Text4Shell Vulnerability: Impact and Fixes](https://fossa.com/_next/image/?url=%2FUntitled-design--7-.png&w=3840&q=75)

Oct 26, 2022

4 min

#### CVE-2022-42889 Text4Shell Vulnerability: Impact and Fixes

A critical remote code execution vulnerability called Text4Shell impacting the Apache Commons Text library.

vulnerability, security

Read Article](https://fossa.com/blog/cve-2022-42889-text4shell-vulnerability-impact-fixes.md)

[![Open Source Licenses 101: Microsoft Public License (Ms-PL)](https://fossa.com/_next/image/?url=%2Fmicrosoft-oss.png&w=3840&q=75)

Oct 22, 2022

5 min

#### Open Source Licenses 101: Microsoft Public License (Ms-PL)

Explore the Microsoft Public License (Ms-PL), often used in .NET projects, known for its unique place in the open source licensing landscape.

open-source, licenses

Read Article](https://fossa.com/blog/open-source-licenses-101-microsoft-public-license-ms-pl.md)

[![Analyzing the Securing Open Source Software Act](https://fossa.com/_next/image/?url=%2Fobi-pixel6propix-YUonZoCUAOk-unsplash--1-.jpg&w=3840&q=75)

Sep 29, 2022

6 min

#### Analyzing the Securing Open Source Software Act

An overview of the Securing Open Source Software Act, its implications for federal agencies, and potential effects on the private sector.

open-source, security

Read Article](https://fossa.com/blog/analyzing-securing-open-source-software-act.md)

[![U.S. Government Memo Requires Self-Attestation to Secure Development Practices](https://fossa.com/_next/image/?url=%2FOMB-Memo.jpg&w=3840&q=75)

Sep 21, 2022

7 min

#### U.S. Government Memo Requires Self-Attestation to Secure Development Practices

The U.S. federal government’s Office of Management and Budget published a memo requiring software suppliers to self-attest to secure development practices, impacting government and private sector software supply chains.

software security, government policy

Read Article](https://fossa.com/blog/omb-memo-requires-self-attestation-secure-development-practices.md)

[![Heather Meeker on Open Source License Compliance Tools](https://fossa.com/_next/image/?url=%2Fheather-oss-tools.png&w=3840&q=75)

Sep 16, 2022

12 min

#### Heather Meeker on Open Source License Compliance Tools

A detailed exploration into the evolution and current trends of compliance tools for open source software licenses, with insights from Heather Meeker.

open-source, license compliance

Read Article](https://fossa.com/blog/heather-meeker-open-source-license-compliance-tools.md)

[![Q and A: Heather Meeker on Hot Topics in OSS License Compliance](https://fossa.com/_next/image/?url=%2Fqa.png&w=3840&q=75)

Aug 30, 2022

13 min

#### Q and A: Heather Meeker on Hot Topics in OSS License Compliance

A discussion with Heather Meeker on pressing issues related to open source software license compliance, featuring key Q and A highlights from a recent webinar.

OSS, license compliance

Read Article](https://fossa.com/blog/q-a-heather-meeker-hot-topics-oss-license-compliance.md)

[![FOSSA Earns Great Place To Work Certification](https://fossa.com/_next/image/?url=%2FGreat-Place-to-Work-Certified-2022.png&w=3840&q=75)

Aug 22, 2022

3 min

#### FOSSA Earns Great Place To Work Certification

FOSSA has achieved the Great Place to Work Certification™, showcasing its commitment to a supportive and inclusive work environment.

Workplace Culture, Certification

Read Article](https://fossa.com/blog/fossa-earns-great-place-work-certification.md)

[![Customer Q&A: Collibra's Journey to Scaling OSS License Compliance](https://fossa.com/_next/image/?url=%2FUntitled-design--5-.png&w=3840&q=75)

Aug 17, 2022

8 min

#### Customer Q&A: Collibra's Journey to Scaling OSS License Compliance

An insightful interview with Amanda Weare, Collibra's VP and Deputy General Counsel, discussing their approach to open source license compliance.

license compliance, open source, Collibra

Read Article](https://fossa.com/blog/customer-q-a-collibra-oss-license-compliance.md)

[![A Practical Guide to the SLSA Framework](https://fossa.com/_next/image/?url=%2FSLSA-Blog.jpg&w=3840&q=75)

Aug 12, 2022

9 min

#### A Practical Guide to the SLSA Framework

A guide to understanding and implementing the SLSA framework for improving software supply chain security across organizations.

SLSA, Software Supply Chain

Read Article](https://fossa.com/blog/practical-guide-slsa-framework.md)

[![How to Implement the CSRB’s Log4j Security Recommendations](https://fossa.com/_next/image/?url=%2FUntitled-design--3-.png&w=3840&q=75)

Jul 27, 2022

10 min

#### How to Implement the CSRB’s Log4j Security Recommendations

Recommendations from the CSRB to improve software security concerning the Log4j vulnerability, with a focus on private enterprises.

security, log4j, csrb

Read Article](https://fossa.com/blog/how-implement-csrbs-log4j-security-recommendations.md)

[![Rust: How to Transform a Byte Stream for Fun and Profit](https://fossa.com/_next/image/?url=%2FRust.png&w=3840&q=75)

Jul 21, 2022

5 min

#### Rust: How to Transform a Byte Stream for Fun and Profit

A guide on transforming byte streams in Rust by using iterators to create powerful modifications.

Rust, Programming

Read Article](https://fossa.com/blog/rust-how-transform-byte-stream.md)

[![Why Open Source is ESG](https://fossa.com/_next/image/?url=%2Fesg-image.jpg&w=3840&q=75)

Jul 13, 2022

6 min

#### Why Open Source is ESG

Exploring how open source software can align with ESG principles, serving both as a risk and an investment opportunity.

ESG, investing

Read Article](https://fossa.com/blog/why-open-source-is-esg.md)

[![Announcing the Private Beta of FOSSA Risk Intelligence](https://fossa.com/_next/image/?url=%2FRisk-Intel-add-on.png&w=3840&q=75)

Jul 6, 2022

3 min

#### Announcing the Private Beta of FOSSA Risk Intelligence

Introducing FOSSA Risk Intelligence, a private beta add-on to enhance software supply chain security by addressing risks like stale packages, abandonware, and more.

open-source, security, risk management

Read Article](https://fossa.com/blog/announcing-private-beta-risk-intelligence.md)

[![Open Source Licenses 101: SIL Open Font License (OFL)](https://fossa.com/_next/image/?url=%2FSIL.png&w=3840&q=75)

Jun 24, 2022

6 min

#### Open Source Licenses 101: SIL Open Font License (OFL)

An overview of the SIL Open Font License (OFL), its versions, and provisions for font software use, modification, and redistribution.

Open Source, Licenses, Fonts

Read Article](https://fossa.com/blog/open-source-licenses-101-sil-open-font-license-ofl.md)

[![How to Build an Open Source License Compliance Program, Featuring Jim Markwith](https://fossa.com/_next/image/?url=%2FUntitled-design--2-.png&w=3840&q=75)

Jun 7, 2022

7 min

#### How to Build an Open Source License Compliance Program, Featuring Jim Markwith

Explore the importance and elements of building a successful open source license compliance program, as discussed by Jim Markwith, a technology and transactions attorney.

open-source, license compliance

Read Article](https://fossa.com/blog/best-practices-building-open-source-license-compliance-program.md)

[![Understanding and Preventing Dependency Confusion Attacks](https://fossa.com/_next/image/?url=%2FHow-to-Defend3.png&w=3840&q=75)

Jun 2, 2022

5 min

#### Understanding and Preventing Dependency Confusion Attacks

Explore the concept of dependency confusion attacks, how they work, and strategies to prevent them from affecting software supply chains.

cybersecurity, supply chain attacks

Read Article](https://fossa.com/blog/dependency-confusion-understanding-preventing-attacks.md)

[![Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management](https://fossa.com/_next/image/?url=%2FNIST.png&w=3840&q=75)

May 19, 2022

9 min

#### Highlights from NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management

An overview of NIST's updated recommendations for managing cybersecurity risks across supply chains, featuring frameworks and templates for organizations.

cybersecurity, risk management

Read Article](https://fossa.com/blog/highlights-nist-sp-800-161r1-cybersecurity-supply-chain-risk-management.md)

[![The Massive Implications of Software Freedom Conservancy vs. Vizio](https://fossa.com/_next/image/?url=%2Fandres-jasso-kAxq92OhMJM-unsplash--1-.jpg&w=3840&q=75)

May 13, 2022

9 min

#### The Massive Implications of Software Freedom Conservancy vs. Vizio

Exploration of Software Freedom Conservancy's lawsuit against Vizio and its potential impact on open source license enforcement.

open-source, software

Read Article](https://fossa.com/blog/massive-implications-software-freedom-conservancy-vs-vizio.md)

[![Open Source Licenses 101: Boost Software License](https://fossa.com/_next/image/?url=%2FMIT-breakdown2.jpg&w=3840&q=75)

May 10, 2022

7 min

#### Open Source Licenses 101: Boost Software License

A thorough examination of the Boost Software License, showcasing its similarities to and differences from other permissive licenses.

open-source, software license

Read Article](https://fossa.com/blog/open-source-licenses-101-boost-software-license.md)

[![Open Source Licenses 101: The CDDL (Common Development and Distribution License)](https://fossa.com/_next/image/?url=%2FCDDL.png&w=3840&q=75)

Apr 26, 2022

7 min

#### Open Source Licenses 101: The CDDL (Common Development and Distribution License)

The CDDL — short for Common Development and Distribution License — is a weak copyleft open source software license initially published by Sun Microsystems.

open-source, licenses

Read Article](https://fossa.com/blog/open-source-licenses-101-cddl-common-development-distribution-license.md)

[![Best Practices for Implementing Software Composition Analysis, Featuring Rancher Labs](https://fossa.com/_next/image/?url=%2FBest-Practices-for-Implementing-SCA--1-.png&w=3840&q=75)

Apr 13, 2022

7 min

#### Best Practices for Implementing Software Composition Analysis, Featuring Rancher Labs

Explore the successful implementation of Software Composition Analysis (SCA) at Rancher Labs, focusing on simplicity, CI/CD integration, barrier removal, and addressing tech debt.

software, SCA

Read Article](https://fossa.com/blog/best-practices-implementing-software-composition-analysis.md)

[![4 Reasons Rancher Labs Chose FOSSA](https://fossa.com/_next/image/?url=%2FWhy-Rancher-Picked-FOSSA.png&w=3840&q=75)

Apr 7, 2022

7 min

#### 4 Reasons Rancher Labs Chose FOSSA

Explore why Rancher Labs selected FOSSA for open source management, enhancing their development efficiency and security posture.

Rancher, FOSSA, Open Source Management

Read Article](https://fossa.com/blog/4-reasons-rancher-labs-chose-fossa.md)

[![An Overview of Spring RCE Vulnerabilities](https://fossa.com/_next/image/?url=%2FspringScreen-Shot-2022-04-01-at-7.22.09-PM.jpg&w=3840&q=75)

Apr 2, 2022

4 min

#### An Overview of Spring RCE Vulnerabilities

A review of critical remote code execution vulnerabilities in Spring, highlighting CVE-2022-22965 and CVE-2022-22963, their impact, and mitigation strategies.

Spring, RCE, Security

Read Article](https://fossa.com/blog/overview-spring-rce-vulnerabilities.md)

[![Building a Sustainable Software Supply Chain](https://fossa.com/_next/image/?url=%2FHow-to-Defend--1-.png&w=3840&q=75)

Mar 30, 2022

9 min

#### Building a Sustainable Software Supply Chain

Exploring strategies to enhance software supply chain security through sustainability practices.

software, security

Read Article](https://fossa.com/blog/building-sustainable-software-supply-chain.md)

[![Announcing New Support for C/C++ Scanning, SBOMs](https://fossa.com/_next/image/?url=%2FScreen-Shot-2022-03-21-at-4.29.52-PM.png&w=3840&q=75)

Mar 22, 2022

3 min

#### Announcing New Support for C/C++ Scanning, SBOMs

FOSSA introduces support for C/C++ scanning and SBOM generation, enhancing software supply chain security.

FOSSA, C/C++, SBOM

Read Article](https://fossa.com/blog/announcing-new-support-c-scanning-sboms.md)

[![How FOSSA Addresses Challenges Scanning C/C++ Code](https://fossa.com/_next/image/?url=%2FScreen-Shot-2022-03-15-at-8.05.58-AM.png&w=3840&q=75)

Mar 18, 2022

7 min

#### How FOSSA Addresses Challenges Scanning C/C++ Code

Exploring the challenges of scanning C and C++ code and how FOSSA addresses these challenges with their code scanning technology.

C/C++, Code Scanning

Read Article](https://fossa.com/blog/how-fossa-addresses-challenges-scanning-c-and-c-code.md)

[![The Three Pillars of Reproducible Builds](https://fossa.com/_next/image/?url=%2Fjoshua-reddekopp-SyYmXSDnJ54-unsplash--1-.jpg&w=3840&q=75)

Mar 8, 2022

9 min

#### The Three Pillars of Reproducible Builds

Exploring the guiding principles of reproducible builds to strengthen software supply chain security.

software, security, builds

Read Article](https://fossa.com/blog/three-pillars-reproducible-builds.md)

[![Overriding Dependency Versions and Using Version Ranges in Maven](https://fossa.com/_next/image/?url=%2Fmaven.png&w=3840&q=75)

Feb 25, 2022

2 min

#### Overriding Dependency Versions and Using Version Ranges in Maven

Explore how Maven handles dependency versions, including declaring dependencies, overriding them, and utilizing version ranges.

Java, Maven

Read Article](https://fossa.com/blog/overriding-dependency-versions-using-version-ranges-maven.md)

[![5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing](https://fossa.com/_next/image/?url=%2Fus-capitol.jpg&w=3840&q=75)

Feb 15, 2022

9 min

#### 5 Highlights from the U.S. Senate’s Log4J Vulnerability Hearing

An overview of the U.S. Senate's hearing on the Log4J vulnerability, highlighting key discussions on software security.

software security, cybersecurity

Read Article](https://fossa.com/blog/5-highlights-us-senates-log4j-vulnerability-hearing.md)

[![6 Takeaways from the Linux Foundation's SBOM Report](https://fossa.com/_next/image/?url=%2Flinux--1-.png&w=3840&q=75)

Feb 7, 2022

6 min

#### 6 Takeaways from the Linux Foundation's SBOM Report

A detailed analysis of the Linux Foundation's SBOM report, outlining key insights into software supply chain security.

SBOM, Cybersecurity

Read Article](https://fossa.com/blog/6-takeaways-linux-foundations-sbom-report.md)

[![React Security: How to Fix Common Vulnerabilities](https://fossa.com/_next/image/?url=%2Freact.png&w=3840&q=75)

Feb 4, 2022

6 min

#### React Security: How to Fix Common Vulnerabilities

Learn about the common security vulnerabilities in React and best practices to prevent them.

React, Security, Vulnerabilities

Read Article](https://fossa.com/blog/react-security-how-fix-common-vulnerabilities.md)

[![OSS License Compliance Expert Heather Meeker on the AGPL](https://fossa.com/_next/image/?url=%2FHeather%20AGPL%20Image.png&w=3840&q=75)

Jan 25, 2022

8 min

#### OSS License Compliance Expert Heather Meeker on the AGPL

An exploration of the AGPL's implications, how it compares to the GPL family, and its inception.

Open Source, AGPL

Read Article](https://fossa.com/blog/oss-license-compliance-expert-heather-meeker-agpl.md)

[![5 Must-Have DevSecOps Tools](https://fossa.com/_next/image/?url=%2FDevSecOps-Tools.png&w=3840&q=75)

Jan 18, 2022

6 min

#### 5 Must-Have DevSecOps Tools

A discussion on essential DevSecOps tools that help automate software testing and management, enhancing security throughout the software development lifecycle.

DevSecOps, tools

Read Article](https://fossa.com/blog/must-have-devsecops-tools.md)

[![Open Source Developer Sabotages npm Libraries 'Colors,' 'Faker'](https://fossa.com/_next/image/?url=%2Fnpm.png&w=3840&q=75)

Jan 11, 2022

4 min

#### Open Source Developer Sabotages npm Libraries 'Colors,' 'Faker'

The developer behind 'colors.js' and 'faker.js' sabotages his own npm libraries, causing widespread disruption.

npm, open source, sabotage

Read Article](https://fossa.com/blog/npm-packages-colors-faker-corrupted.md)

[![Dependency Management
in Visual Studio: NuGet and Beyond](https://fossa.com/_next/image/?url=%2Fvisual-studio.png&w=3840&q=75)

Jan 6, 2022

15 min

#### Dependency Management in Visual Studio: NuGet and Beyond

A comprehensive guide to managing dependencies in Visual Studio using NuGet, exploring .NET projects, project dependencies, and alternative tools for effective dependency management.

Visual Studio, NuGet

Read Article](https://fossa.com/blog/dependency-management-visual-studio-nuget-beyond.md)

[![Does TikTok Live Studio Violate GPL v2?](https://fossa.com/_next/image/?url=%2Flogo-TikTok.jpg&w=3840&q=75)

Dec 22, 2021

5 min

#### Does TikTok Live Studio Violate GPL v2?

Exploring the license compliance concerns surrounding TikTok Live Studio's use of GPL v2-licensed OBS Studio.

GPL, license compliance

Read Article](https://fossa.com/blog/does-tiktok-live-studio-violate-the-gpl-v2.md)

[![Q and A: Heather Meeker on AGPL, Truth Social, OSS License Compliance](https://fossa.com/_next/image/?url=%2FAGPL.png&w=3840&q=75)

Dec 22, 2021

6 min

#### Q and A: Heather Meeker on AGPL, Truth Social, OSS License Compliance

Highlights from a webinar with open source licensing expert Heather Meeker discussing AGPL, Truth Social's compliance issues, and Google's AGPL policy.

AGPL, Open Source, License Compliance

Read Article](https://fossa.com/blog/heather-meeker-agpl-truth-social-oss-license-compliance.md)

[![How to Quickly Find and Remediate Log4J Vulnerabilities (Log4Shell)](https://fossa.com/_next/image/?url=%2FScreen-Shot-2021-12-20-at-8.28.18-PM.jpg&w=3840&q=75)

Dec 21, 2021

3 min

#### How to Quickly Find and Remediate Log4J Vulnerabilities (Log4Shell)

Explore detection and remediation strategies for Log4J vulnerabilities, including Log4Shell, using FOSSA's CLI.

Log4J, security, vulnerability

Read Article](https://fossa.com/blog/quickly-find-remediate-log4j-vulnerabilities-log4shell.md)

[![How to Fix the New Log4J DoS Vulnerability: CVE-2021-45105](https://fossa.com/_next/image/?url=%2Flog4j.jpg&w=3840&q=75)

Dec 19, 2021

3 min

#### How to Fix the New Log4J DoS Vulnerability: CVE-2021-45105

A guide on addressing the newly discovered Log4J DoS vulnerability CVE-2021-45105 and recommended updates.

Log4J, Vulnerability

Read Article](https://fossa.com/blog/how-fix-new-log4j-dos-vulnerability-cve-2021-45105.md)

[![FOSSA Partners with OpenChain to Promote Open Source Management](https://fossa.com/_next/image/?url=%2Fopen-chain2.png&w=3840&q=75)

Dec 15, 2021

3 min

#### FOSSA Partners with OpenChain to Promote Open Source Management

FOSSA has partnered with OpenChain to support organizations in achieving OpenChain Conformance, promoting compliance with OSS licensing requirements.

Open Source, Compliance

Read Article](https://fossa.com/blog/fossa-partners-openchain-open-source-management.md)

[![Log4J "Log4Shell" Zero-Day Vulnerability: Impact and Fixes](https://fossa.com/_next/image/?url=%2FLog4Shell-Blog.png&w=3840&q=75)

Dec 10, 2021

4 min

#### Log4J "Log4Shell" Zero-Day Vulnerability: Impact and Fixes

Discover the critical CVE-2021-44228 vulnerability in Apache Log4J affecting many applications and how to mitigate it.

vulnerability, security

Read Article](https://fossa.com/blog/log4j-log4shell-zero-day-vulnerability-impact-fixes.md)

[![Introducing FOSSA's New License Scanner](https://fossa.com/_next/image/?url=%2Fv2.png&w=3840&q=75)

Nov 30, 2021

5 min

#### Introducing FOSSA's New License Scanner

Explore FOSSA's upgraded license scanner, featuring improved speed and accuracy, and learn how it benefits users with enhanced capabilities.

license scanning, software updates

Read Article](https://fossa.com/blog/introducing-fossas-new-license-scanner.md)

[![Managing Dependencies in .NET: .csproj, .packages.config, project.json, and More](https://fossa.com/_next/image/?url=%2Fnet.png&w=3840&q=75)

Nov 24, 2021

3 min

#### Managing Dependencies in .NET: .csproj, .packages.config, project.json, and More

An overview of dependency management in .NET including .csproj, .packages.config, project.json, and other related artifacts.

.NET, dependency management

Read Article](https://fossa.com/blog/managing-dependencies-net-csproj-packagesconfig.md)

[![FOSSA Product Updates: Announcing Our New and Improved CLI](https://fossa.com/_next/image/?url=%2FProduct-updates--1--1.png&w=3840&q=75)

Nov 15, 2021

3 min

#### FOSSA Product Updates: Announcing Our New and Improved CLI

Announcing FOSSA's revamped CLI that simplifies integrations with reduced configuration. Discover the new features and improvements.

CLI, FOSSA

Read Article](https://fossa.com/blog/product-updates-announcing-new-improved-cli.md)

[![DevSecOps 101: Understanding and Implementing DevSecOps Principles](https://fossa.com/_next/image/?url=%2Fdevsecops.png&w=3840&q=75)

Nov 12, 2021

7 min

#### DevSecOps 101: Understanding and Implementing DevSecOps Principles

Explore the principles of DevSecOps, a natural extension of DevOps, focusing on integrating security testing throughout the software development lifecycle.

DevSecOps, Security, Development

Read Article](https://fossa.com/blog/devsecops-101-understanding-implementing-devsecops-principles.md)

[![Embedded Malware in NPM: Coa, Rc, Ua-parser](https://fossa.com/_next/image/?url=%2Fmarkus-spiske-8OyKWQgBsKQ-unsplash--1-.jpg&w=3840&q=75)

Nov 8, 2021

5 min

#### Embedded Malware in NPM: Coa, Rc, Ua-parser

A significant rise in NPM packages with embedded malware has been reported, affecting popular packages like coa, rc, and ua-parser. This raises serious concerns over the ecosystem's security.

NPM, Security, Malware

Read Article](https://fossa.com/blog/embedded-malware-npm-coa-rc-ua-parser.md)

[![Open Source Software Licenses 101: The Eclipse Public License](https://fossa.com/_next/image/?url=%2Feclipse.png&w=3840&q=75)

Nov 2, 2021

8 min

#### Open Source Software Licenses 101: The Eclipse Public License

An overview of the Eclipse Public License, its key provisions, and its compatibility with other licenses.

eclipse, open-source, licenses

Read Article](https://fossa.com/blog/open-source-software-licenses-101-eclipse-public-license.md)

[![Best Practices for Testing in Go](https://fossa.com/_next/image/?url=%2FGo--1-.png&w=3840&q=75)

Oct 25, 2021

12 min

#### Best Practices for Testing in Go

An exploration of effective testing practices in Go, including strategies for choosing what to test and examples of making it work in applications.

Go, Testing

Read Article](https://fossa.com/blog/golang-best-practices-testing-go.md)

[![4 Key Elements of Technical Due Diligence](https://fossa.com/_next/image/?url=%2FTechnical-Due-Diligence.png&w=3840&q=75)

Oct 14, 2021

7 min

#### 4 Key Elements of Technical Due Diligence

Explore the essential aspects of technical due diligence, from third-party software usage to intellectual property protections.

technical due diligence, M&A

Read Article](https://fossa.com/blog/key-elements-technical-due-diligence.md)

[![Q and A: Software Bill of Materials and FOSSA](https://fossa.com/_next/image/?url=%2F2--1-.png&w=3840&q=75)

Oct 7, 2021

8 min

#### Q and A: Software Bill of Materials and FOSSA

Explore common questions related to FOSSA’s SBOM solution including its features, export formats, and security aspects.

Software, SBOM

Read Article](https://fossa.com/blog/q-and-a-software-bill-of-materials-fossa.md)

[![Anatomy of a Software Supply Chain Attack](https://fossa.com/_next/image/?url=%2FHow-to-Defend.png&w=3840&q=75)

Sep 30, 2021

8 min

#### Anatomy of a Software Supply Chain Attack

Understanding software supply chain attacks and strategies to defend against them.

cybersecurity, software security

Read Article](https://fossa.com/blog/defend-against-software-supply-chain-attacks.md)

[![How to Generate an SBOM with FOSSA](https://fossa.com/_next/image/?url=%2FReact-Screenshot-for-Blog-1.jpg&w=3840&q=75)

Sep 22, 2021

6 min

#### How to Generate an SBOM with FOSSA

Learn how to use FOSSA's SBOM tool to generate a software bill of materials easily and effectively.

SBOM, FOSSA

Read Article](https://fossa.com/blog/generate-software-bill-of-materials-fossa/)

[![bouk/monkey and the Importance of Knowing Your Dependencies](https://fossa.com/_next/image/?url=%2FRBAC2.png&w=3840&q=75)

Sep 15, 2021

6 min

#### bouk/monkey and the Importance of Knowing Your Dependencies

Exploring the significance of understanding software dependencies, licenses, and the unusual case of bouk/monkey's license.

open-source, license compliance

Read Article](https://fossa.com/blog/bouk-monkey-importance-knowing-your-dependencies.md)

[![Role-Based Access Control (RBAC), Zero Trust, and FOSSA](https://fossa.com/_next/image/?url=%2Frbac-blog-feature-image.png&w=3840&q=75)

Sep 9, 2021

4 min

#### Role-Based Access Control (RBAC), Zero Trust, and FOSSA

Exploring the implementation of Zero Trust through Role-Based Access Control (RBAC) with FOSSA.

cybersecurity, zero trust, access control

Read Article](https://fossa.com/blog/role-based-access-control-rbac-zero-trust-and-fossa.md)

[![3 Best Practices for OSS Management in the Automotive Industry](https://fossa.com/_next/image/?url=%2Fsamuele-errico-piccarini-FMbWFDiVRPs-unsplash--1-.jpg&w=3840&q=75)

Aug 30, 2021

7 min

#### 3 Best Practices for OSS Management in the Automotive Industry

Explore best practices for OSS management in the automotive industry to reduce license compliance, security, and quality risks.

open-source, automotive

Read Article](https://fossa.com/blog/best-practices-oss-management-automotive-industry.md)

[![FOSSA Product Updates: August 2021](https://fossa.com/_next/image/?url=%2FProduct-updates.png&w=3840&q=75)

Aug 27, 2021

3 min

#### FOSSA Product Updates: August 2021

Overview of several new features in FOSSA, including analysis target configuration, announcements banner for on-prem users, new language support, container scanning, audit logging, and the ability to manually add dependencies.

FOSSA, Product Updates

Read Article](https://fossa.com/blog/fossa-product-updates-august-2021.md)

[![FOSSA Receives Highest Scores Possible in License Risk Management, SBOM Criteria in Forrester Wave](https://fossa.com/_next/image/?url=%2FSCA-Post-Cover--1-.png&w=3840&q=75)

Aug 23, 2021

3 min

#### FOSSA Receives Highest Scores Possible in License Risk Management, SBOM Criteria in Forrester Wave

FOSSA is recognized as a significant SCA solution in The Forrester Wave™ report, achieving highest scores in license risk management and SBOM criteria.

SCA, FOSSA

Read Article](https://fossa.com/blog/fossa-receives-highest-scores-license-risk-management-sbom-forrester-wave.md)

[![Open Source Software Licenses 101: The LGPL License](https://fossa.com/_next/image/?url=%2FLGPL.png&w=3840&q=75)

Aug 20, 2021

7 min

#### Open Source Software Licenses 101: The LGPL License

An overview of the GNU Lesser General Public License (LGPL), its requirements, permissions, and its current usage in the open source software development community.

open source licenses, LGPL

Read Article](https://fossa.com/blog/open-source-software-licenses-101-lgpl-license.md)

[![Open Source Software Licenses 101: The AGPL License](https://fossa.com/_next/image/?url=%2FAGPL-1.png&w=3840&q=75)

Aug 13, 2021

12 min

#### Open Source Software Licenses 101: The AGPL License

Explore the intricacies of the GNU Affero General Public License (AGPL), its history, requirements, and its impact on the open-source software community.

open-source, AGPL, licenses

Read Article](https://fossa.com/blog/open-source-software-licenses-101-agpl-license.md)

[![Announcing FOSSA Container Scanning](https://fossa.com/_next/image/?url=%2FBase-Image.png&w=3840&q=75)

Aug 3, 2021

2 min

#### Announcing FOSSA Container Scanning

Announcing the availability of FOSSA Container Scanning, a tool that helps identify vulnerabilities and license risks in container images.

container scanning, security

Read Article](https://fossa.com/blog/announcing-fossa-container-scanning.md)

[![Stockfish vs. ChessBase and What it Means for GPL v3](https://fossa.com/_next/image/?url=%2Fhassan-pasha-7SjEuEF06Zw-unsplash--1-.jpg&w=3840&q=75)

Jul 28, 2021

6 min

#### Stockfish vs. ChessBase and What it Means for GPL v3

An exploration of the Stockfish lawsuit against ChessBase, testing the GPL v3 license regarding derivative works and license termination.

GPL, chess, open-source

Read Article](https://fossa.com/blog/stockfish-vs-chessbase-gpl-v3.md)

[![The Minimum Required Elements of an SBOM](https://fossa.com/_next/image/?url=%2FSBOM-Minimum.png&w=3840&q=75)

Jul 23, 2021

7 min

#### The Minimum Required Elements of an SBOM

An overview of the minimum required elements for a Software Bill of Materials (SBOM) as outlined by the U.S. Federal Government's NTIA.

SBOM, software, compliance

Read Article](https://fossa.com/blog/minimum-required-elements-software-bill-of-materials.md)

[![Analyzing the Legal Implications of GitHub Copilot](https://fossa.com/_next/image/?url=%2Fcopilot-2.png&w=3840&q=75)

Jul 14, 2021

7 min

#### Analyzing the Legal Implications of GitHub Copilot

Explore the potential legal challenges GitHub Copilot faces regarding copyright infringement and license compliance of its code suggestions.

GitHub, Legal, Copilot

Read Article](https://fossa.com/blog/analyzing-legal-implications-github-copilot.md)

[![Container Image Security and Vulnerability Scanning](https://fossa.com/_next/image/?url=%2Fcontainer-security-1.png&w=3840&q=75)

Jun 25, 2021

9 min

#### Container Image Security and Vulnerability Scanning

Explore today’s container image security landscape and learn strategies to fend off cyber threats like vulnerability scanning and digital signatures.

Container Security, Vulnerability Scanning

Read Article](https://fossa.com/blog/container-image-security-vulnerability-scanning.md)

[![All About CWE-79: Cross-Site Scripting](https://fossa.com/_next/image/?url=%2FCross-Site-Scripting-A.png&w=3840&q=75)

Jun 22, 2021

8 min

#### All About CWE-79: Cross-Site Scripting

An overview of CWE-79: Cross-Site Scripting, a common web vulnerability that allows attackers to inject malicious code into web applications.

XSS, security, web vulnerabilities

Read Article](https://fossa.com/blog/all-about-cwe-79-cross-site-scripting.md)

[![Copyleft Licenses and the Venture Capital Connection](https://fossa.com/_next/image/?url=%2Fventure-capital.png&w=3840&q=75)

Jun 8, 2021

8 min

#### Copyleft Licenses and the Venture Capital Connection

Explore the impact of copyleft licenses on venture capital investments, including insights from IP lawyer Kate Downing and the NVCA Stock Purchase Agreement Model Form.

open-source, venture capital

Read Article](https://fossa.com/blog/copyleft-licenses-venture-capital-connection.md)

[![All About Permissive Licenses](https://fossa.com/_next/image/?url=%2FPermissive-Licenses.png&w=3840&q=75)

Jun 3, 2021

14 min

#### All About Permissive Licenses

An exploration of permissive open source licenses, their history, and their role in the software community.

open-source, licenses

Read Article](https://fossa.com/blog/all-about-permissive-licenses.md)

[![Cybersecurity Executive Order and Software Supply Chain Security](https://fossa.com/_next/image/?url=%2Fwh_social-share-1100x740.png&w=3840&q=75)

May 26, 2021

8 min

#### Cybersecurity Executive Order and Software Supply Chain Security

An overview of the Biden Administration's executive order on cybersecurity and its impact on software supply chain security.

cybersecurity, software supply chain, security, executive order

Read Article](https://fossa.com/blog/cybersecurity-executive-order-software-supply-chain-security.md)

[![IT Central Station: What Makes for an Effective SCA Solution](https://fossa.com/_next/image/?url=%2FITCentral-Station.png&w=3840&q=75)

May 20, 2021

4 min

#### IT Central Station: What Makes for an Effective SCA Solution

Exploring the essential features of an effective Software Composition Analysis (SCA) solution through insights from IT Central Station members.

SCA, Software, Security

Read Article](https://fossa.com/blog/it-central-station-effective-sca-solution.md)

[![All About Copyleft Licenses](https://fossa.com/_next/image/?url=%2FCopyleft.png&w=3840&q=75)

May 10, 2021

12 min

#### All About Copyleft Licenses

An exploration of copyleft licenses, their history, differences from permissive licenses, and their role in the open source community.

open-source, licenses

Read Article](https://fossa.com/blog/all-about-copyleft-licenses.md)

[![Application Security for Developers: SCA, DAST, and GitHub Actions](https://fossa.com/_next/image/?url=%2FSCA--DAST--and-GitHub-Actions.png&w=3840&q=75)

Apr 29, 2021

9 min

#### Application Security for Developers: SCA, DAST, and GitHub Actions

Explore application security testing with SCA and DAST, and learn how to implement these tools using GitHub Actions for early bug detection and cost reduction.

application security, GitHub Actions

Read Article](https://fossa.com/blog/application-security-developers-sca-dast-github-actions.md)

[![Software Bill Of Materials (SBOM) Formats, Use Cases, and Specifications](https://fossa.com/_next/image/?url=%2Flarge-12.png&w=3840&q=75)

Apr 22, 2021

10 min

#### Software Bill Of Materials (SBOM) Formats, Use Cases, and Specifications

Explore the significance of Software Bill of Materials (SBOM), its formats, use cases, and essential elements crucial for compliance and security in the software supply chain.

SBOM, software

Read Article](https://fossa.com/blog/software-bill-of-materials-formats-use-cases-tools/)

[![How SCA Helps Manage OSS Vulnerabilities](https://fossa.com/_next/image/?url=%2FBP-Image-05-1-2.png&w=3840&q=75)

Apr 16, 2021

5 min

#### How SCA Helps Manage OSS Vulnerabilities

Explore how Software Composition Analysis (SCA) helps teams manage open source software vulnerabilities.

OSS, SCA, software

Read Article](https://fossa.com/blog/how-sca-helps-manage-oss-vulnerabilities.md)

[![Open Source Software Licenses 101: The ISC License](https://fossa.com/_next/image/?url=%2FOSS-103.png&w=3840&q=75)

Apr 12, 2021

10 min

#### Open Source Software Licenses 101: The ISC License

Explore the history, requirements, and key differences of the ISC License in open source software.

open-source, licenses

Read Article](https://fossa.com/blog/open-source-software-licenses-101-isc-license.md)

[![Open Source Software Licenses 101: Mozilla Public License 2.0](https://fossa.com/_next/image/?url=%2Fmozilla-101.png&w=3840&q=75)

Apr 6, 2021

12 min

#### Open Source Software Licenses 101: Mozilla Public License 2.0

An in-depth look at the Mozilla Public License 2.0, its requirements, comparisons with other licenses, and its use cases.

Open Source, Software Licensing

Read Article](https://fossa.com/blog/open-source-software-licenses-101-mozilla-public-license-2-0.md)

[![Top Build Systems for Monorepos](https://fossa.com/_next/image/?url=%2Fmonorepo.png&w=3840&q=75)

Mar 30, 2021

7 min

#### Top Build Systems for Monorepos

Explore various build systems suited for monorepos, detailing the difference between imperative and declarative systems, and providing insights into top choices such as Bazel, Buck, and Pants.

build systems, monorepos

Read Article](https://fossa.com/blog/top-build-systems-monorepos.md)

[![Open Source Software Licenses 101: The BSD 3-Clause License](https://fossa.com/_next/image/?url=%2FBSD.png&w=3840&q=75)

Mar 25, 2021

13 min

#### Open Source Software Licenses 101: The BSD 3-Clause License

An overview of the BSD 3-Clause License, its history, requirements, and how it compares to other permissive licenses.

open-source, software licenses

Read Article](https://fossa.com/blog/open-source-software-licenses-101-bsd-3-clause-license.md)

[![Software Supply Chain Security for Automotive Organizations](https://fossa.com/_next/image/?url=%2Fimage20.png&w=3840&q=75)

Mar 20, 2021

7 min

#### Software Supply Chain Security for Automotive Organizations

Exploring supply chain security risks in automotive industry and how software composition analysis can mitigate these threats.

software security, automotive industry

Read Article](https://fossa.com/blog/software-supply-chain-security-automotive-organizations.md)

[![How OSS Conquered the World: Insight from Veteran Developers](https://fossa.com/_next/image/?url=%2Fjonathan-farber-8xpTdO1R3dw-unsplash-2.jpg&w=3840&q=75)

Mar 12, 2021

3 min

#### How OSS Conquered the World: Insight from Veteran Developers

FOSSA staff engineer Konstantin Gredeskoul and Oxide Computer Company's co-founder Bryan Cantrill discuss the development and impact of open source software in an informative and entertaining podcast.

open-source, OSS

Read Article](https://fossa.com/blog/how-oss-conquered-world-insight-veteran-developers.md)

[![Building an Open Source Program Office (OSPO)](https://fossa.com/_next/image/?url=%2Fdomains-by-contributors.png&w=3840&q=75)

Mar 9, 2021

6 min

#### Building an Open Source Program Office (OSPO)

Explore the components and staffing necessary for establishing a successful Open Source Program Office to manage and strategize open source software use.

OSPO, open-source

Read Article](https://fossa.com/blog/building-open-source-program-office-ospo.md)

[![Open Source Software Licenses 101: GPL v3](https://fossa.com/_next/image/?url=%2FOSS-102.png&w=3840&q=75)

Mar 3, 2021

13 min

#### Open Source Software Licenses 101: GPL v3

Explore the differences between GPL v2 and GPL v3, understand the key features of GPL v3, and discover why it's a popular choice among developers and companies. Learn about its use cases, compatibility with Apache 2.0, and the future of GPL v3 in OSS projects.

open-source, licenses

Read Article](https://fossa.com/blog/open-source-software-licenses-101-gpl-v3.md)

[![Open Source Software Licenses 101: GPL v2](https://fossa.com/_next/image/?url=%2FGPL%202%20Image.png&w=3840&q=75)

Feb 24, 2021

11 min

#### Open Source Software Licenses 101: GPL v2

An informative guide on the GNU General Public License Version 2.0, highlighting its terms, conditions, and how it contrasts with other open source licenses.

open-source, GPL, license

Read Article](https://fossa.com/blog/open-source-software-licenses-101-gpl-v2.md)

[![How to Choose an Open Source Software License Compliance Tool](https://fossa.com/_next/image/?url=%2Fmarkus-winkler-afW1hht0NSs-unsplash-2.jpg&w=3840&q=75)

Feb 19, 2021

5 min

#### How to Choose an Open Source Software License Compliance Tool

Guidance on choosing the right open source software license compliance tool, covering aspects such as scanning, automation, integration, issue management, and reporting.

open-source, compliance

Read Article](https://fossa.com/blog/how-choose-open-source-software-license-compliance-tool.md)

[![4 Takeaways from the 2021 State of Open Source Vulnerabilities Report](https://fossa.com/_next/image/?url=%2FState-of-OSS-Vulns-in-2021.png&w=3840&q=75)

Feb 10, 2021

3 min

#### 4 Takeaways from the 2021 State of Open Source Vulnerabilities Report

An analysis of the 2021 State of Open Source Vulnerabilities report, highlighting frequent targets like Java and JavaScript, common issues such as poor input validation, and vulnerable libraries.

vulnerabilities, open-source, programming languages

Read Article](https://fossa.com/blog/takeaways-2021-state-open-source-vulnerabilities-report.md)

[![Open Source Licenses 101: Apache License 2.0](https://fossa.com/_next/image/?url=%2FApache-2.0-breakdown.png&w=3840&q=75)

Feb 6, 2021

10 min

#### Open Source Licenses 101: Apache License 2.0

An exploration of the Apache License 2.0, outlining its terms, use cases, and how it compares to other permissive licenses.

open-source, apache license, software licenses

Read Article](https://fossa.com/blog/open-source-licenses-101-apache-license-2-0.md)

[![How to Apply a License to Your Open Source Software Project](https://fossa.com/_next/image/?url=%2FApply%20License%20Image.png&w=3840&q=75)

Feb 1, 2021

16 min

#### How to Apply a License to Your Open Source Software Project

Explore how to effectively apply a license to your open source software project, addressing common challenges and scenarios.

open-source, license

Read Article](https://fossa.com/blog/apply-license-open-source-software-project.md)

[![Open Source Software Licenses 101: The MIT License](https://fossa.com/_next/image/?url=%2FMIT-breakdown.png&w=3840&q=75)

Jan 28, 2021

9 min

#### Open Source Software Licenses 101: The MIT License

Exploring the MIT License, a popular open source software license, its permissions, restrictions, and comparisons to other licenses.

open-source, licenses

Read Article](https://fossa.com/blog/open-source-licenses-101-mit-license.md)

[![Takeaways from OpenChain ISO/IEC 5230:2020](https://fossa.com/_next/image/?url=%2Fopen-chain.png&w=3840&q=75)

Jan 26, 2021

5 min

#### Takeaways from OpenChain ISO/IEC 5230:2020

Key insights from the OpenChain ISO/IEC 5230:2020 standard, focusing on requirements for license compliance programs and how to achieve OpenChain Conformance.

open-source, compliance

Read Article](https://fossa.com/blog/takeaways-iso-iec-dis-5230-openchain-specification.md)

[![Top Security Takeaways from the 2020 FOSS Contributor Survey](https://fossa.com/_next/image/?url=%2Fpexels-artem-podrez-5716032-2.jpg&w=3840&q=75)

Jan 19, 2021

7 min

#### Top Security Takeaways from the 2020 FOSS Contributor Survey

Discover key security insights from the 2020 FOSS Contributor Survey and explore actionable recommendations for open source project owners.

Open Source, Security

Read Article](https://fossa.com/blog/top-security-takeaways-from-the-2020-foss-contributor-survey.md)

[![The Future of Software Composition Analysis, Featuring Forrester](https://fossa.com/_next/image/?url=%2Fthe-future-of-SCA.png&w=3840&q=75)

Jan 13, 2021

5 min

#### The Future of Software Composition Analysis, Featuring Forrester

Exploring the future of Software Composition Analysis (SCA) with key insights into automation, governance, and developer integration.

software, open-source

Read Article](https://fossa.com/blog/future-software-composition-analysis-featuring-forrester.md)

[![Improving Page Speed Using Google PageSpeed Insights in Rails Apps](https://fossa.com/_next/image/?url=%2FScreen-Shot-2020-11-29-at-6.37.11-PM.png&w=3840&q=75)

Jan 8, 2021

7 min

#### Improving Page Speed Using Google PageSpeed Insights in Rails Apps

Integrate Google’s PageSpeed Insights API into Rails apps to improve site performance, accessibility, and SEO.

Rails, Google PageSpeed

Read Article](https://fossa.com/blog/improving-page-speed-google-pagespeed-insights-rails-apps.md)

[![5 Ways Companies Can Get More Value From Open Source Software](https://fossa.com/_next/image/?url=%2F5-ways.png&w=3840&q=75)

Dec 29, 2020

9 min

#### 5 Ways Companies Can Get More Value From Open Source Software

Explore strategies for maximizing open source software benefits while ensuring compliance and security.

open-source, software development

Read Article](https://fossa.com/blog/5-ways-companies-get-more-value-from-open-source-software.md)

[![SolarWinds, Supply Chain Attacks, and Software Composition Analysis](https://fossa.com/_next/image/?url=%2FSolarWinds_Hack_Before.png&w=3840&q=75)

Dec 23, 2020

9 min

#### SolarWinds, Supply Chain Attacks, and Software Composition Analysis

Exploring the implications of the SolarWinds hack and methods to prevent similar software supply chain attacks, with a focus on software composition analysis.

supply chain attacks, cybersecurity

Read Article](https://fossa.com/blog/solarwinds-supply-chain-attacks-software-composition-analysis.md)

[![How UiPath Reduced Open Source Risk Through Team Collaboration](https://fossa.com/_next/image/?url=%2Fchris-liverani-9cd8qOgeNIY-unsplash-2.jpg&w=3840&q=75)

Dec 22, 2020

7 min

#### How UiPath Reduced Open Source Risk Through Team Collaboration

Explore how UiPath reduces open source risk through collaboration between engineering, compliance, and security teams.

open-source, risk management

Read Article](https://fossa.com/blog/how-uipath-reduced-open-source-risk-through-team-collaboration.md)

[![What is Software Composition Analysis?](https://fossa.com/_next/image/?url=%2FSCA-Post-Cover.png&w=3840&q=75)

Dec 17, 2020

5 min

#### What is Software Composition Analysis?

Discover how Software Composition Analysis (SCA) helps you manage and reduce risks associated with open source components in your software.

software, analysis

Read Article](https://fossa.com/blog/what-is-software-composition-analysis/)

[![Pros and Cons of Using Monorepos](https://fossa.com/_next/image/?url=%2FSCA-and-monorepo.png&w=3840&q=75)

Dec 12, 2020

6 min

#### Pros and Cons of Using Monorepos

Monorepos, used by companies like Google and Facebook, offer benefits like simplified dependency management and large-scale code refactoring, but also present challenges in build pipelines and VCS tooling.

monorepos, software development

Read Article](https://fossa.com/blog/pros-cons-using-monorepos.md)

[![How Zendesk’s Legal Team Scored an Open Source Compliance Victory](https://fossa.com/_next/image/?url=%2FZendesk-case-study.png&w=3840&q=75)

Dec 9, 2020

5 min

#### How Zendesk’s Legal Team Scored an Open Source Compliance Victory

Discover how Zendesk's legal team improved open source compliance with the help of FOSSA, optimizing workflows and reducing time spent on compliance processes.

open-source, compliance

Read Article](https://fossa.com/blog/how-zendesks-legal-team-scored-open-source-compliance-victory.md)

[![FOSSA Announces SOC 2 Compliance](https://fossa.com/_next/image/?url=%2FSOC-2.png&w=3840&q=75)

Dec 4, 2020

3 min

#### FOSSA Announces SOC 2 Compliance

FOSSA has achieved SOC 2 Type 2 compliance, reaffirming its commitment to the highest standards of security and data protection.

SOC 2, compliance

Read Article](https://fossa.com/blog/fossa-announces-soc-2-compliance.md)

[![How to Choose the Right Open Source License](https://fossa.com/_next/image/?url=%2F2.png&w=3840&q=75)

Nov 25, 2020

6 min

#### How to Choose the Right Open Source License

This post guides you on how to choose the right open source license for your project, ensuring your software is protected and shared as you wish.

open-source, licensing

Read Article](https://fossa.com/blog/how-choose-right-open-source-license.md)

[![A Look Inside FOSSA’s New Product Design](https://fossa.com/_next/image/?url=%2Fbefore-and-after.png&w=3840&q=75)

Nov 21, 2020

4 min

#### A Look Inside FOSSA’s New Product Design

Explore FOSSA’s recent design refresh, focusing on brand consistency and user experience improvements.

design, product update

Read Article](https://fossa.com/blog/look-inside-fossa-new-product-design.md)

[![Q&A: Heather Meeker on Open Source License Notices](https://fossa.com/_next/image/?url=%2Fheather-2-2.png&w=3840&q=75)

Nov 18, 2020

9 min

#### Q&A: Heather Meeker on Open Source License Notices

Heather Meeker shares insights on open source software licensing and the role of automation in managing license notices.

Open Source, License Compliance

Read Article](https://fossa.com/blog/q-and-a-heather-meeker-open-source-license-notices.md)

[![Heather Meeker on Open Source License Notices and Automation](https://fossa.com/_next/image/?url=%2Fheather-3.png&w=3840&q=75)

Nov 13, 2020

10 min

#### Heather Meeker on Open Source License Notices and Automation

Discussing the importance of open source license notices and how automation can help address compliance challenges.

open-source, license compliance

Read Article](https://fossa.com/blog/heather-meeker-open-source-license-notices-automation.md)

[![A Journey Through Our New Brand and Website](https://fossa.com/_next/image/?url=%2F01.png&w=3840&q=75)

Oct 27, 2020

12 min

#### A Journey Through Our New Brand and Website

Explore how we redesigned FOSSA's brand and website, focusing on new design principles and a modernized aesthetic that enhances user experience and brand identity.

branding, website redesign

Read Article](https://fossa.com/blog/journey-through-our-new-brand-website/)

[![A Framework for Evaluating Software Composition Analysis Tools](https://fossa.com/_next/image/?url=%2FSCA-blogpost-image-1.png&w=3840&q=75)

Oct 20, 2020

5 min

#### A Framework for Evaluating Software Composition Analysis Tools

Understand the importance of Software Composition Analysis (SCA) tools for mitigating risks associated with open source components in modern software development.

Software Composition Analysis, Risk Mitigation

Read Article](https://fossa.com/blog/framework-for-evaluating-software-composition-analysis-tools.md)

[![FOSSA Raises a $23.2M Series B](https://fossa.com/_next/image/?url=%2Fpost-cover-SeriesB.png&w=3840&q=75)

Oct 15, 2020

3 min

#### FOSSA Raises a $23.2M Series B

FOSSA announces a new funding round of $23.2M to accelerate the development of open source inventory solutions.

funding, open-source

Read Article](https://fossa.com/blog/fossa-raises-series-b.md)

[![Press Release: FOSSA Accelerates Growth, Hits Significant Milestones](https://fossa.com/_next/image/?url=%2FFrame-28.png&w=3840&q=75)

Oct 15, 2020

4 min

#### Press Release: FOSSA Accelerates Growth, Hits Significant Milestones

FOSSA announces $23.2 million in Series B funding and launches new security management capabilities, affirming its leadership in the software composition analysis market.

open-source, security management

Read Article](https://fossa.com/blog/press-release-october-2020.md)

[![Introducing Open Source Security Management at Enterprise Scale](https://fossa.com/_next/image/?url=%2FBP-Image-01-1.png&w=3840&q=75)

Oct 14, 2020

5 min

#### Introducing Open Source Security Management at Enterprise Scale

Announcing the launch of FOSSA Security Management, empowering enterprises to prevent vulnerabilities proactively and continuously.

security, open-source

Read Article](https://fossa.com/blog/introducing-open-source-security-management-at-enterprise-scale.md)

[![How Open Source License Audits Became a Strategic Key to M&A Success](https://fossa.com/_next/image/?url=%2FMergers-Acquisitions.jpg&w=3840&q=75)

Sep 17, 2020

4 min

#### How Open Source License Audits Became a Strategic Key to M&A Success

Open source non-compliance can impact company transactions like mergers and acquisitions by slowing, devaluing, or breaking deals.

open-source, M&A

Read Article](https://fossa.com/blog/ma-due-diligence.md)

[![The Huge Risk that Most IPOs Miss](https://fossa.com/_next/image/?url=%2FIPO-stock-market-ticker.png&w=3840&q=75)

Sep 15, 2020

8 min

#### The Huge Risk that Most IPOs Miss

Explore the often-overlooked risks in IPO preparations, focusing on open source license management and compliance.

IPOs, Risk Management

Read Article](https://fossa.com/blog/the-huge-risk-that-most-ipos-miss.md)

[![Now's the Perfect Time to Evolve Legal and Engineering Collaboration](https://fossa.com/_next/image/?url=%2Fossflowchart.png&w=3840&q=75)

Aug 27, 2020

4 min

#### Now's the Perfect Time to Evolve Legal and Engineering Collaboration

In remote work, businesses' confidence in their software supply chain is crucial, highlighting risk mitigation's importance.

open-source, compliance

Read Article](https://fossa.com/blog/nows-the-perfect-time-to-evolve-legal-and-engineering-collaboration.md)

[![TikTok, Trump, and the Future of Open Source Surveillance](https://fossa.com/_next/image/?url=%2Ftiktok-trump.jpg&w=3840&q=75)

Aug 26, 2020

9 min

#### TikTok, Trump, and the Future of Open Source Surveillance

Exploring the intersection of TikTok, national security, and the future of open source software surveillance.

surveillance, open-source

Read Article](https://fossa.com/blog/tiktok-trump-and-the-future-of-open-source-surveillance.md)

[![FOSSA and Container Scanning](https://fossa.com/_next/image/?url=%2Fheader-twitter-2.jpg&w=3840&q=75)

Jun 3, 2020

4 min

#### FOSSA and Container Scanning

Explore how FOSSA aids in scanning different components of a container to ensure compliance and security.

container, docker

Read Article](https://fossa.com/blog/fossa-container-scanning/)

[![Open Source Management: Fundamentals](https://fossa.com/_next/image/?url=%2FOpen-Source-Management_-Fundamentals-2.png&w=3840&q=75)

Apr 10, 2020

15 min

#### Open Source Management: Fundamentals

Explore the role of open source in the enterprise market and learn the essentials of managing open source software including strategies, policies, and tools for effective oversight.

Enterprise, Software

Read Article](https://fossa.com/blog/open-source-management-fundamentals-2020.md)

[![Why Source Code Scanning Tools Are Essential for Open Source Compliance](https://fossa.com/_next/image/?url=%2FSource-Code-Scanning-Tools.png&w=3840&q=75)

Apr 8, 2020

5 min

#### Why Source Code Scanning Tools Are Essential for Open Source Compliance

Explore the risks and necessity of source code scanning tools in open source compliance to prevent licensing issues and ensure smooth project management.

open-source, compliance

Read Article](https://fossa.com/blog/why-source-code-scanning-tools-are-essential-to-open-source-compliance.md)

[Feb 14, 2020

2 min

#### FOSSA January 2020 Product Release Notes

Explore the January 2020 FOSSA product release, featuring Release Groups for better project management and new dependency editing workflows, alongside various CLI improvements.

FOSSA, Product Updates

Read Article](https://fossa.com/blog/january-product-release-notes.md)

[Jan 6, 2020

2 min

#### FOSSA December 2019 Product Release Notes

December 2019 product release notes, highlighting user management enhancements and updates to attribution reports.

FOSSA, release notes

Read Article](https://fossa.com/blog/december-2019-product-release-notes.md)

[![Snippet Scanning: Is it Right for Your Team?](https://fossa.com/_next/image/?url=%2Fimage-8.png&w=3840&q=75)

Dec 18, 2019

5 min

#### Snippet Scanning: Is it Right for Your Team?

Explore the nuances of snippet scanning and its relevance to software development today, while considering risk profiles and modern development practices.

open-source, software composition analysis

Read Article](https://fossa.com/blog/snippet-scanning-is-it-right-for-your-team/)

[Dec 5, 2019

2 min

#### FOSSA November 2019 Product Release Notes

Learn about FOSSA's November 2019 product updates including user management enhancements, UI improvements, and new reporting features.

Read Article](https://fossa.com/blog/november-2019-product-release-notes.md)

[![FOSSA Named to CNBC's Upstart 100](https://fossa.com/_next/image/?url=%2FFOSSA-Named-to-CNBC-s-Upstart-100.png&w=3840&q=75)

Nov 12, 2019

2 min

#### FOSSA Named to CNBC's Upstart 100

FOSSA has been named to CNBC's Upstart 100 List following the closing of $8.5 Million in Series A Funding.

startups, open-source, recognition

Read Article](https://fossa.com/blog/fossa-named-to-the-upstart-100.md)

[![FOSSA Acquires Dawn Labs](https://fossa.com/_next/image/?url=%2Facquisition.png&w=3840&q=75)

Oct 3, 2019

2 min

#### FOSSA Acquires Dawn Labs

FOSSA announces the acquisition of Dawn Labs to enhance its focus on developer-focused products and expand its team with experienced developers known for creating Carbon and working with ZEIT.

Acquisition, Developer Tools

Read Article](https://fossa.com/blog/fossa-acquires-dawn-labs.md)

[Oct 2, 2019

2 min

#### FOSSA September 2019 Product Release Notes

Highlights from FOSSA's September 2019 release, including updates to JIRA integration, project addition enhancements, new reporting formats, and FOSSA-CLI improvements.

FOSSA, Product Release, Integrations

Read Article](https://fossa.com/blog/september-2019-product-release-notes.md)

[![FOSSA Raises $8.5M for Enterprise Open Source Management](https://fossa.com/_next/image/?url=%2Fimage.png&w=3840&q=75)

Sep 16, 2019

4 min

#### FOSSA Raises $8.5M for Enterprise Open Source Management

FOSSA announces an $8.5M Series A funding to enhance open source management for enterprises, and shares success stories with notable clients.

Enterprise, Open Source

Read Article](https://fossa.com/blog/fossa-series-a.md)

[![DevOps and Open Source + CI/CD = Mitigating Risk Without Sacrificing Speed](https://fossa.com/_next/image/?url=%2Fdevops-blog-post.png&w=3840&q=75)

Sep 11, 2019

2 min

#### DevOps and Open Source + CI/CD = Mitigating Risk Without Sacrificing Speed

Explore how DevOps and open source tools can be leveraged with CI/CD to mitigate risk without compromising on speed.

DevOps, CI/CD

Read Article](https://fossa.com/blog/devops-and-open-source-ci-cd-mitigating-risk-without-sacrificing-speed.md)

[Sep 2, 2019

3 min

#### FOSSA August 2019 Product Release Notes

Highlighting FOSSA's August 2019 product updates, including streamlined issue management, new language support, and enhanced reporting features.

FOSSA, release notes

Read Article](https://fossa.com/blog/august-product-release-notes.md)

[![We’re excited to partner with CircleCI to release our CircleCI orb!](https://fossa.com/_next/image/?url=%2Ffossa-circleci.png&w=3840&q=75)

Aug 14, 2019

1 min

#### We’re excited to partner with CircleCI to release our CircleCI orb!

Learn about FOSSA's new CircleCI orb for easier OSS license compliance and CI/CD integration.

CircleCI, Open Source

Read Article](https://fossa.com/blog/were-excited-to-partner-with-circleci.md)

[Aug 1, 2019

1 min

#### FOSSA July 2019 Product Release Notes

Enhancements to the FOSSA CLI, Rust support, and improvements to on-prem deployment are highlighted in the FOSSA July 2019 product release notes.

Product Release, FOSSA, CLI

Read Article](https://fossa.com/blog/july-product-release-notes.md)

[![A Partnership Between Legal Teams and Software Engineers is More Important Than Ever](https://fossa.com/_next/image/?url=%2FOpen-Source-Awareness-02b-light-bckgrnd-3.png&w=3840&q=75)

Jul 22, 2019

1 min

#### A Partnership Between Legal Teams and Software Engineers is More Important Than Ever

Explore why collaboration between legal and engineering teams is critical in the era of privacy legislation and open source licensing.

legal, engineering

Read Article](https://fossa.com/blog/a-partnership-between-legal-and-engineering-teams-is-more-important-than-ever.md)

[![FOSSA Marketing Intern Reflection](https://fossa.com/_next/image/?url=%2F890-291.png&w=3840&q=75)

Jul 19, 2019

3 min

#### FOSSA Marketing Intern Reflection

Mahak Bandi shares her experiences and growth as a Marketing Intern at FOSSA.

Marketing, Internship

Read Article](https://fossa.com/blog/marketing-intern-reflection.md)

[![WTFPL to Beerware: Top 6 Out-There Open Source Licenses](https://fossa.com/_next/image/?url=%2Faustin-distel-jpHw8ndwJ_Q-unsplash-1.jpg&w=3840&q=75)

Jul 9, 2019

3 min

#### WTFPL to Beerware: Top 6 Out-There Open Source Licenses

Explore some of the most unconventional open source licenses, from Beerware to WTFPL.

open-source, licenses

Read Article](https://fossa.com/blog/top-6-most-out-there-open-source-licenses.md)

[Jul 2, 2019

2 min

#### FOSSA June 2019 Product Release Notes

Kick off the summer with new Haskell language support, plain text reporting, and major enhancements to FOSSA's project page.

FOSSA, release notes

Read Article](https://fossa.com/blog/june-product-release-notes.md)

[![All About Open Source Licenses](https://fossa.com/_next/image/?url=%2Foss.png&w=3840&q=75)

Jun 26, 2019

6 min

#### All About Open Source Licenses

A comprehensive guide to understanding open source licenses, including permissive and copyleft licenses, and how to apply them.

open-source, licenses

Read Article](https://fossa.com/blog/what-do-open-source-licenses-even-mean.md)

[![What is a Private Artifact Repository?](https://fossa.com/_next/image/?url=%2Ftobias-fischer-185901-unsplash.jpg&w=3840&q=75)

Jun 24, 2019

3 min

#### What is a Private Artifact Repository?

Exploration of the benefits and limitations of private artifact repositories, highlighting three common issues developers face along with solutions offered by FOSSA.

open-source, artifact repository

Read Article](https://fossa.com/blog/three-things-to-watch-out-for-with-a-private-artifact-repository.md)

[![Still Asking Engineers to Fill Out Open Source Request Forms?](https://fossa.com/_next/image/?url=%2Fstill-asking-blog-image.jpg&w=3840&q=75)

Jun 10, 2019

7 min

#### Still Asking Engineers to Fill Out Open Source Request Forms?

Exploring the impact of manual open source request processes on engineering culture and innovation speed.

open-source, software development

Read Article](https://fossa.com/blog/are-your-open-source-policies-slowing-down-innovation.md)

[![We’re Excited to Announce Our CNCF Membership](https://fossa.com/_next/image/?url=%2Fcncf-blog-feature-image.jpeg&w=3840&q=75)

Jun 7, 2019

1 min

#### We’re Excited to Announce Our CNCF Membership

FOSSA is excited to announce its CNCF membership, highlighting the importance of open source in software development and our commitment to the community.

open-source, CNCF

Read Article](https://fossa.com/blog/were-excited-to-announce-our-cncf-membership.md)

[Jun 4, 2019

3 min

#### FOSSA May 2019 Product Release Notes

Explore the latest updates from FOSSA, including simplified reporting, enhanced CLI, and better support for NuGet and Gradle.

product, release notes

Read Article](https://fossa.com/blog/may-product-release-notes.md)

[![A Case For Continuous Compliance](https://fossa.com/_next/image/?url=%2Fphoto-1532619187608-e5375cab36aa.jpeg&w=3840&q=75)

May 16, 2019

5 min

#### A Case For Continuous Compliance

Exploring the importance and benefits of continuous compliance in the use of open source software.

open-source, compliance

Read Article](https://fossa.com/blog/a-case-for-continuous-compliance.md)

[![Creating a Comprehensive 3rd-Party Package License Policy for OSS](https://fossa.com/_next/image/?url=%2Fcarlos-alberto-gomez-iniguez-jqiAU_JQGyk-unsplash-2.jpg&w=3840&q=75)

May 14, 2019

9 min

#### Creating a Comprehensive 3rd-Party Package License Policy for OSS

Learn how to create a comprehensive third-party package license policy, a vital element for companies engaging with open source software and ensuring compliance across various licenses.

OSS, Open Source Compliance

Read Article](https://fossa.com/blog/creating-a-comprehensive-third-party-package-license-policy.md)

[![Why Open Source License Compliance Needs to Be CI-Agnostic](https://fossa.com/_next/image/?url=%2Fchristopher-gower-m_HRfLhgABo-unsplash-1.jpg&w=3840&q=75)

Mar 15, 2019

5 min

#### Why Open Source License Compliance Needs to Be CI-Agnostic

Exploring the importance of adopting platform-agnostic tools for open source license compliance and the benefits of avoiding vendor lock-in.

open-source, license compliance

Read Article](https://fossa.com/blog/why-license-compliance-needs-to-be-ci-agnostic.md)

[![Automating Open Source Reports with FOSSA at Applause](https://fossa.com/_next/image/?url=%2Fapplause-europe-buero-berlin.jpg&w=3840&q=75)

Feb 19, 2019

3 min

#### Automating Open Source Reports with FOSSA at Applause

Discover how Applause leveraged FOSSA to automate their OSS licensing and compliance process, saving time and improving accuracy.

open-source, FOSSA

Read Article](https://fossa.com/blog/automating-open-source-reports-with-fossa-at-applause.md)

[Nov 29, 2018

5 min

#### Cost/Benefit Analysis: Manual Audits vs Automated License Compliance

Exploring the costs and benefits of manual versus automated license compliance in software companies.

compliance, audits

Read Article](https://fossa.com/blog/cost-benefit-analysis--manual-audits-vs-automated-license-compliance.md)

[![Fast Integration Tests for 3rd Party Services - The Easy Way](https://fossa.com/_next/image/?url=%2FScreen-Shot-2018-11-20-at-11.31.34-PM.png&w=3840&q=75)

Nov 29, 2018

5 min

#### Fast Integration Tests for 3rd Party Services - The Easy Way

Learn how to efficiently use integration tests for third-party services with mocha-tape-deck, optimizing speed and reliability.

integration tests, third-party services

Read Article](https://fossa.com/blog/quickly-buildin.md)

[Nov 15, 2018

3 min

#### Reflecting on 1 year of early-stage engineering

Reflections on an engineer's journey in a small company, highlighting the diverse roles and skills acquired.

software engineering, startups

Read Article](https://fossa.com/blog/engineering-at-fossa.md)

[![Which Open Source License Is Best for Commercialization?](https://fossa.com/_next/image/?url=%2Fimage-9.png&w=3840&q=75)

Nov 15, 2018

4 min

#### Which Open Source License Is Best for Commercialization?

Exploring the best open source licenses for commercialization, including the balance between permissive and restrictive licenses.

open-source, licenses

Read Article](https://fossa.com/blog/which-open-source-license-is-the-best-for-commercialization.md)

[![Discussing Commons Clause on Software Engineering Daily](https://fossa.com/_next/image/?url=%2FScreen-Shot-2018-11-05-at-10.13.24-AM.png&w=3840&q=75)

Nov 5, 2018

2 min

#### Discussing Commons Clause on Software Engineering Daily

Exploration of open source software, business models, and the impact of the Commons Clause, with insights from Kevin Wang.

open-source, business models

Read Article](https://fossa.com/blog/discussing-commons-clause-on-software-engineering-daily.md)

[![Pathologies of Go Package Management](https://fossa.com/_next/image/?url=%2FPathologies-of-Go-Package-Management.png&w=3840&q=75)

Oct 24, 2018

10 min

#### Pathologies of Go Package Management

An exploration of the challenges and strategies in managing Go package dependencies, including issues with reproducible builds and dependency analysis.

Go, package management

Read Article](https://fossa.com/blog/pathologies-of-go-package-management.md)

[Oct 17, 2018

4 min

#### FOSSA 0.8.0: Overhauling our onboarding system + other usability improvements

FOSSA introduces version 0.8.0, featuring an overhauled onboarding system and a series of usability improvements.

FOSSA, software updates

Read Article](https://fossa.com/blog/080-overhauling-onboarding.md)

[![300+ New Licenses Supported in FOSSA](https://fossa.com/_next/image/?url=%2F1-SLQ19DlQ_SWZvT5Y9OR8Dg.png&w=3840&q=75)

May 30, 2018

3 min

#### 300+ New Licenses Supported in FOSSA

Announcing new license data quality updates with over 300 new licenses in FOSSA.

FOSSA, licenses

Read Article](https://fossa.com/blog/300--new-licenses-supported-in-fossa.md)

[![JS Foundation chooses FOSSA as the Open Source License Cert. Provider](https://fossa.com/_next/image/?url=%2Fkris_headshot.png&w=3840&q=75)

May 1, 2018

5 min

#### JS Foundation chooses FOSSA as the Open Source License Cert. Provider

The JS Foundation, supporting critical JavaScript infrastructure, chooses FOSSA for automated open-source license compliance.

JavaScript, Open Source

Read Article](https://fossa.com/blog/js-foundation-chooses-fossa-as-its-open-source-license-certification-provider.md)

[Apr 16, 2018

5 min

#### Combating Alert Fatigue with a Global Issue Dashboard

This post discusses how FOSSA's new dashboard tools address alert fatigue by improving issue management and triage for modern enterprises.

alert fatigue, dashboard

Read Article](https://fossa.com/blog/combating-alert-fatigue-with-a-global-issue-dashboard.md)

[![Open sourcing FOSSA’s build analysis in fossa-cli](https://fossa.com/_next/image/?url=%2F1-UmCOpqOgmAMSS0iFr1avWw.png&w=3840&q=75)

Mar 15, 2018

3 min

#### Open sourcing FOSSA’s build analysis in fossa-cli

FOSSA is open sourcing its dependency analysis infrastructure, allowing everyone access to the tools necessary to get comprehensive dependency data from any codebase.

open-source, dependency-analysis

Read Article](https://fossa.com/blog/open-sourcing-fossa-s-build-analysis-in-fossa-cli.md)

[![Delivering a better on-premises experience](https://fossa.com/_next/image/?url=%2FFOSSA-Deployment.png&w=3840&q=75)

Feb 5, 2018

4 min

#### Delivering a better on-premises experience

Explore the unique challenges of on-premises deployments and discover how FOSSA improves onboarding, support, and integrations to enhance user experience.

on-premises, deployment, FOSSA

Read Article](https://fossa.com/blog/delivering-a-better-on-premises-experience.md)

[![Legal Concerns for SaaS Companies Going On-Prem](https://fossa.com/_next/image/?url=%2F1_7uMqFz51Pz96deHbX_KvaA.png&w=3840&q=75)

Nov 30, 2017

5 min

#### Legal Concerns for SaaS Companies Going On-Prem

Explore the legal and compliance challenges SaaS companies face when transitioning to on-prem solutions for high profile clients, such as Fortune 500 companies.

SaaS, Legal, On-Prem

Read Article](https://fossa.com/blog/legal-concerns-for-saas-companies-going-on-prem.md)

[Nov 1, 2017

5 min

#### Organization-wide issues & conditional policies

Discover how FOSSA improves organization-level issue management and introduces conditional policy rules to streamline compliance.

compliance, policies

Read Article](https://fossa.com/blog/organization-wide-issues-conditional-policies.md)

[![Don’t Over-REACT to the Facebook Patents License](https://fossa.com/_next/image/?url=%2F1_tuW_Ne_3Txsra9VY-iogjA.png&w=3840&q=75)

Aug 24, 2017

7 min

#### Don’t Over-REACT to the Facebook Patents License

The controversy surrounding Facebook's 'BSD+ Patents' license is more partisan than practical, and the Apache Foundation's decision to reclassify it is unlikely to impact the use of ReactJS.

open-source, Facebook, patents

Read Article](https://fossa.com/blog/dont-over-react-to-the-facebook-patents-license.md)

[![The Ultimate GPL Survival Guide](https://fossa.com/_next/image/?url=%2F1-xihjzYKsqn8pByQ9GUxavg.png&w=3840&q=75)

Jul 7, 2017

6 min

#### The Ultimate GPL Survival Guide

A comprehensive guide on GPL compliance for professionals in consumer electronics, IoT, and automotive industries, featuring useful flowcharts and checklists.

GPL, open-source, compliance

Read Article](https://fossa.com/blog/the-ultimate-gpl-survival-guide.md)

[![Announcing FOSSA Public Beta & Funding](https://fossa.com/_next/image/?url=%2F1-5Jxiz-aBnwc7d2XfuzMqtQ.png&w=3840&q=75)

Feb 23, 2017

7 min

#### Announcing FOSSA Public Beta & Funding

Announce the public beta release of FOSSA and a $2.2MM seed round led by Bain Capital Ventures.

FOSSA, Open Source

Read Article](https://fossa.com/blog/announcing-fossa-public-beta---funding.md)

[![You can’t get around code scanning if you care about open source licenses](https://fossa.com/_next/image/?url=%2F1_GSq1ojaLX5TFD_RsMpJnJQ.png&w=3840&q=75)

Feb 21, 2017

6 min

#### You can’t get around code scanning if you care about open source licenses

Exploring the necessity of code scanning tools for tracking and complying with open source licenses in modern software development.

open-source, code scanning

Read Article](https://fossa.com/blog/you-can-t-get-around-code-scanning-if-you-care-about-open-source-licenses.md)

[![How SmartThings runs IoT open source compliance across dozens of releases per day](https://fossa.com/_next/image/?url=%2Fdean-3.jpg&w=3840&q=75)

Jan 1, 2017

5 min

#### How SmartThings runs IoT open source compliance across dozens of releases per day

An exploration of how SmartThings automates their code release process for IoT platforms with the help of FOSSA compliance tools.

IoT, SmartThings

Read Article](https://fossa.com/blog/how-smartthings-runs-iot-open-source-compliance-across-dozens-of-releases-per-day.md)

[![FOSSA partners with npm to deliver open source license compliance](https://fossa.com/_next/image/?url=%2F1_y5YLuOKO5XM7MOzve6XsDQ.png&w=3840&q=75)

Jul 5, 2016

4 min

#### FOSSA partners with npm to deliver open source license compliance

FOSSA introduces a new add-on for npm Enterprise to enhance open source license compliance.

open-source, compliance

Read Article](https://fossa.com/blog/fossa-partners-with-npm-to-deliver-open-source-license-compliance.md)

## Source

Canonical page: https://fossa.com/blog/
