Special thanks to our featured sponsors

Endor Labs

Supporting

Overview

90% of code in modern applications is open source. With over 43M Open Source Software (OSS) project versions, and clear indication that open source will dominate the “AI movement”, development teams can gain tremendous benefits from leveraging the OSS ecosystem, as long as organizations invest in the right tooling to address the security, scalability and maintainability challenges that come with it. Endor Labs’ Code & Pipeline Governance Platform focuses on these pain-points and outcomes: Software Composition Analysis (SCA): Only 12% of the OSS code is actually used within your applications. Endor Labs replaces the existing breed of SCA solutions that lack context on code usage, thereby cutting ~80% of the vulnerabilities being reported. Dependency & Tech Debt Management: Endor Labs helps engineers improve application performance and minimize attack surface by helping select and maintain secure & high quality dependencies across the SDLC. CI-CD Governance: Endor Labs helps you monitor the posture of your pipelines, including SCM configurations, developer access, and hardcoded secrets in code, all through a single hook and policy-as-code framework integrated into your pipeline. Compliance & SBOMs: Comply with emerging US Government led standards & regulation around Software Bill of Materials (SBOM), automated VEX generation, and adherence to the White House Executive Order 14028. Endor Labs fully integrates with GitHub Advanced Security to help AppSec and engineering teams secure applications without the “productivity tax” of continuously switching tools. With Endor Labs and GitHub Advanced Security you can achieve end-to-end application security without ever leaving GitHub! See it in action.

Videos

Cancel
03:33
live

Quality

×

an error occurred while loading this video