Synopsys hopes to mitigate upstream risks in software supply chains with new SCA tool
Summary
Synopsys has released a new solution to help companies manage upstream risks of software supply chains. The tool also performs post-build analysis that can help detect malware or potentially unwanted applications. SBOMs can be exported in SPDX or CycloneDX formats, which makes it easier to meet customer, industry, or regulatory requirements, according to Synopsys. “This requires constant vigilance over the patchwork of software dependencies that get pulled in from a variety of sources, including open source components downloaded from public repositories, commercial software packages purchased from vendors, code generated from AI coding assistants, and the containers and IT infrastructure used to deploy applications. It also requires the ability to detect and generate actionable insights for a wide range of risk factors such as known vulnerabilities, exposed secrets, and malicious code.”