No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, November 2, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

Software Composition Analysis Is The AppSec Hero We Deserve AND Need

by TheAdviserMagazine
6 months ago
in Market Analysis
Reading Time: 3 mins read
A A
Software Composition Analysis Is The AppSec Hero We Deserve AND Need
Share on FacebookShare on TwitterShare on LInkedIn


Software composition analysis (SCA) stepped out from behind the long shadow of static application security testing (SAST)/dynamic application security testing to prove its worth years ago. And thanks to ambitious bad actors, the complex software supply chain, and generative AI (genAI) coding assistants accelerating overall code volume, SCA solutions are essential to clean up the supply chain and bolster application security.

SCA is also an application security (AppSec) darling for its ability to generate a software bill of materials (SBOM). With the EU’s Cyber Resilience Act finalized, the proposed US Department of Defense Software Fast Track Initiative requiring SBOMs, and governments such as Australia releasing guidelines for software development that include SBOMs, more software suppliers around the world will need to provide SBOMs to win and maintain business. Advanced SCA tools go beyond just generating an SBOM; they continuously monitor for newly disclosed vulnerabilities for proactive alerts and will ingest third-party SBOMs to identify the risk of incorporating a third-party component.

Opportunistic attacks that take advantage of newly introduced vulnerabilities and unpatched software require patience and timing. But attackers can be proactive by directly poisoning open-source and third-party components. These types of attacks, such as dependency confusion and typo squatting, were already on the rise. But now, “slopsquatting” happens when AI hallucinates package names that developers must add. Additionally, bad actors willing to play the long game, typically affiliated with nation states, will bully their way into maintaining obscure but widely used open-source software dependencies such as XZ Utils to bury malicious code and target downstream recipients. SCA solutions provide insight into open-source component health during selection and actively block malicious packages from being downloaded. Clearly, SCA is the AppSec hero we need.

Enterprises have been eager to embed and utilize AI in the customer-facing applications that they build. In Forrester’s 2024 survey of business and technology professionals, 33% reported using genAI in production applications. This means a whole new world of application dependencies consisting of AI models, third-party APIs, and open-source dependencies. Python is a popular language for AI applications, as is the PyPI package manager for open-source dependencies. Bad actors did not waste any time in uploading legitimate-looking but malicious packages that were downloaded hundreds of times by developers building AI applications. Poisoned AI models could be pulled down from Hugging Face and other public repositories. At the time of The Forrester Wave™: Software Composition Analysis Software, Q4 2024 evaluation, only a few SCA vendors were scanning AI models or creating AI bills of materials, but this functionality is needed broadly and quickly.

When thinking about purchasing or upgrading your SCA software, consider key insights we gathered from talking with SCA vendor customers to get the tool you not only deserve but also need:

Evaluate more than one vendor. This may seem obvious, but SCA software differs in functionality and the quality of output. Some software is primarily focused on open-source components, while others go beyond and assess third-party components and even inner-source components (those shared components written by your organization). The quality of the results also differs based on language and ability to detect vulnerabilities in transitive dependencies. Most reference customers evaluated three vendors’ software as part of the purchasing process (see figure below).
Don’t settle. You’re going to be in it for the long haul. Customer references have been with their vendor on average for over 3.5 years. And they are happy! Twenty-two of 28 references rate their vendor at a nine or 10. If you have an SCA solution and you are not satisfied, it’s worth your time to revisit this at the next renewal period.
Keep an eye out for the extras. SCA software vendors have expanded their offering to cover more of the software supply chain, such as offering malicious package detection and package firewall protection, infrastructure as code and container image scanning, and secrets detection. Depending on the vendor and its pricing and packaging model, these capabilities could be add-ons to the base price. Static reachability (the ability to determine whether the vulnerable function is called by the first-party code) should be table stakes for SCA solutions, but some vendors require you to also purchase their static SAST solution to get this level of insight.

 

Be your company’s hero and select an SCA software solution that helps secure your software supply chain by utilizing Forrester’s Buyer’s Guide: Software Composition Analysis Software, 2025, and The Forrester Wave™: Software Composition Analysis Software, Q4 2024. For more insights, schedule a guidance session or inquiry with me. Protecting your brand, your customers’ data, and your revenue is worth the effort.



Source link

Tags: AnalysisAppSecCompositiondeserveHeroSoftware
ShareTweetShare
Previous Post

15 Counties With the Most Housing Growth in the Past 10 Years

Next Post

National Streaming Day Offers You Can Score {Just in Time for Summer Break!}

Related Posts

edit post
5 Undervalued Stocks Under  Poised for Double-Digit Rebounds

5 Undervalued Stocks Under $10 Poised for Double-Digit Rebounds

by TheAdviserMagazine
October 31, 2025
0

Investing in stocks priced under $10 can offer significant opportunities for investors seeking high-growth potential at a low entry point....

edit post
Forrester’s Consumer Predictions For 2026

Forrester’s Consumer Predictions For 2026

by TheAdviserMagazine
October 31, 2025
0

I wrote the theme to this year’s consumer predictions to the beat of Rihanna’s “We Found Love,” with the lyric...

edit post
The Year AI Tests The Heart Of Healthcare

The Year AI Tests The Heart Of Healthcare

by TheAdviserMagazine
October 31, 2025
0

In 2025, the healthcare industry experienced significant shake-ups: the uncertain future of premium tax credits; the fracturing of vaccine policy;...

edit post
The Customer Is “Neo,” Not You

The Customer Is “Neo,” Not You

by TheAdviserMagazine
October 31, 2025
0

You need to deliver value to customers, right? Wrong! Myth: Your Organization Can “Deliver” Value To Customers If you believe...

edit post
Shifting From Creator Tools To Creative Participation: Adobe MAX Takeaways

Shifting From Creator Tools To Creative Participation: Adobe MAX Takeaways

by TheAdviserMagazine
October 30, 2025
0

Creativity has always extended beyond creative and content teams. But for years, many marketers and other employees lacked the tools,...

edit post
Amazon Earnings Preview: Layoffs Mark the Start of AI-Era Efficiency Drive

Amazon Earnings Preview: Layoffs Mark the Start of AI-Era Efficiency Drive

by TheAdviserMagazine
October 30, 2025
0

Amazon plans up to 30,000 layoffs to streamline operations and prepare for AI-driven growth. AWS performance remains the key focus...

Next Post
edit post
National Streaming Day Offers You Can Score {Just in Time for Summer Break!}

National Streaming Day Offers You Can Score {Just in Time for Summer Break!}

edit post
How does a U.S.-dollar TFSA work?

How does a U.S.-dollar TFSA work?

  • Trending
  • Comments
  • Latest
edit post
77-year-old popular furniture retailer closes store locations

77-year-old popular furniture retailer closes store locations

October 18, 2025
edit post
Pennsylvania House of Representatives Rejects Update to Child Custody Laws

Pennsylvania House of Representatives Rejects Update to Child Custody Laws

October 7, 2025
edit post
What to Do When a Loved One Dies in North Carolina

What to Do When a Loved One Dies in North Carolina

October 8, 2025
edit post
Another Violent Outburst – Democrats Inciting Civil Unrest

Another Violent Outburst – Democrats Inciting Civil Unrest

October 24, 2025
edit post
Probate vs. Non-Probate Assets: What’s the Difference?

Probate vs. Non-Probate Assets: What’s the Difference?

October 17, 2025
edit post
California Attorney Pleads Guilty For Role In 2M Ponzi Scheme

California Attorney Pleads Guilty For Role In $912M Ponzi Scheme

October 15, 2025
edit post
Doral to build NIS 1.5b solar project in Texas

Doral to build NIS 1.5b solar project in Texas

0
edit post
Gene Hackman’s Estate: The Importance of Updated Wills and Clear Intentions

Gene Hackman’s Estate: The Importance of Updated Wills and Clear Intentions

0
edit post
UPDATE: High Dividend 50: Cogent Communications Holdings

UPDATE: High Dividend 50: Cogent Communications Holdings

0
edit post
Professor Jesús Huerta de Soto’s Acceptance Address at the Casa Rosada

Professor Jesús Huerta de Soto’s Acceptance Address at the Casa Rosada

0
edit post
Chainlink Maintains Its Base, But One Push Could Flip Sentiment Fast

Chainlink Maintains Its Base, But One Push Could Flip Sentiment Fast

0
edit post
Earnings Preview: AMD set to report Q3 2025 results. Here’s what to expect

Earnings Preview: AMD set to report Q3 2025 results. Here’s what to expect

0
edit post
GM Breweries tops October charts with 75% gain as indices snap winning streak. Check other monthly winners

GM Breweries tops October charts with 75% gain as indices snap winning streak. Check other monthly winners

November 2, 2025
edit post
Bankman-Fried Blames Lawyers for FTX Collapse, Says 0B in Value Was Lost

Bankman-Fried Blames Lawyers for FTX Collapse, Says $100B in Value Was Lost

November 1, 2025
edit post
Chainlink Maintains Its Base, But One Push Could Flip Sentiment Fast

Chainlink Maintains Its Base, But One Push Could Flip Sentiment Fast

November 1, 2025
edit post
Global power demand seen surging nearly a third by 2035 – Rystad (XLU:NYSEARCA)

Global power demand seen surging nearly a third by 2035 – Rystad (XLU:NYSEARCA)

November 1, 2025
edit post
Cattle faces a growing threat from a protected vulture spreading north amid climate change

Cattle faces a growing threat from a protected vulture spreading north amid climate change

November 1, 2025
edit post
Instacart, DoorDash, Gopuff and Zip are offering discounts to SNAP recipients

Instacart, DoorDash, Gopuff and Zip are offering discounts to SNAP recipients

November 1, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • GM Breweries tops October charts with 75% gain as indices snap winning streak. Check other monthly winners
  • Bankman-Fried Blames Lawyers for FTX Collapse, Says $100B in Value Was Lost
  • Chainlink Maintains Its Base, But One Push Could Flip Sentiment Fast
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.