NetRise Provenance launched to expose open source contributor risk, map impact across software supply chains - Industrial Cyber
Summary
NetRise launched NetRise Provenance, a software supply-chain-security product that identifies risk tied to open-source contributors and maps how risky maintainers propagate across dependency graphs. The product integrates with the NetRise Platform and is available via API, CLI, and GitHub Action to enrich SBOMs, container images, and binaries with maintainer attribution, advisory history, geographic context, and trust signals. Security, procurement, and product teams can set policies to automatically fail CI builds when dependencies exceed risk thresholds, run blast-radius analysis, and prioritize remediation to meet compliance obligations. NetRise positions Provenance to speed impact assessments from weeks to minutes and to give builders and buyers clearer visibility into who maintains the code running in their environments.