5 Questions to Ask Before Adopting an Open Source Dependency

Most open source dependency decisions don’t feel like decisions at all. The package looks familiar. Someone’s used it before. It solves the problem you’re trying to fix. So you add it and move on. The problem is, those choices tend to stick around. Once a dependency is part of your software, it’s rarely as temporary […]

Introducing DepsDiver: Eliminating the Security Blind Spots in Your Dependencies

Hunted Labs is introducing DepsDiver, a new class of dependency security focused on uncovering foreign influence and code repository risk early and providing package alternatives.   Dependency Risk Has Changed Open source is the foundation of modern software, but dependency decisions no longer happen the way security teams assume they do. In practice, most dependencies […]

Popping Fast-Glob’s Hood

Solo maintainer poses supply chain risk to more than 5,000 software packages, including container images in Node.js and Department of Defense systems

Our Research

Hayden Smith

The following is a story about the recent XZ Utils security breach and how things came about. Formore context on the

Our Blog

Request A Demo

Fill out the form below so we can arrange a product demo for you.

    Request A Demo

    Fill out the form below so we can arrange a product demo for you.

    Thank You

    We have received your submission.