{"id":4920,"date":"2022-03-03T08:27:18","date_gmt":"2022-03-03T12:27:18","guid":{"rendered":"https:\/\/solutionsreview.com\/endpoint-security\/?p=4920"},"modified":"2022-03-03T10:34:08","modified_gmt":"2022-03-03T14:34:08","slug":"tips-to-improve-open-source-software-supply-chain-health-and-security","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/","title":{"rendered":"3 Tips to Improve Open-Source Software Supply Chain Health and Security"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4923\" src=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg\" alt=\"\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg 800w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security-300x150.jpg 300w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security-768x384.jpg 768w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security-540x270.jpg 540w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security-162x81.jpg 162w, https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security-360x180.jpg 360w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify;\"><strong><em>As part of Solutions Review&#8217;s Premium Content Series\u2014a collection of contributed columns written by industry experts in maturing software categories\u2014Donald Fischer, the co-founder and CEO of <a href=\"https:\/\/tidelift.com\/\" target=\"_blank\" rel=\"noopener\">Tidelift<\/a>, shares some insights on improving the health and security of an open-source software supply chain.<\/em><\/strong><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\"><span style=\"font-size: 1em;\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3778 alignleft\" src=\"https:\/\/solutionsreview.com\/security-information-event-management\/files\/2022\/01\/SR-Premium-Content.gif\" alt=\"\" width=\"84\" height=\"88\" \/><\/span>When it comes to modern enterprise application development, open-source software is everywhere. Some surveys have found that <\/span><a href=\"https:\/\/blog.tidelift.com\/open-source-is-everywhere-survey-results-part-1\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">more than 90% of modern applications contain open-source components<\/span><\/a><span data-contrast=\"auto\"> and for a good reason. Developing applications with open-source gives organizations an enormous head start\u2014billions of lines of freely available code that can be downloaded and used to accomplish everyday tasks, allowing developers to focus on the pieces unique to their app.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Open-source has been an enormous gift to application development, and we often take for granted what a marvel it is that we even have all of this free code available to use. Yet, at the same time, recent events like Log4Shell, the vulnerability that impacted the ubiquitous Java logging component Log4j, have many organizations more focused than ever on how to improve the health and security of their open-source software supply chain.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>What is Log4Shell, and why was it so dangerous? \u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Log4j is a Java logging component that has been in use for over 20 years. It was developed and maintained by unpaid volunteers and has over 3,600 dependent packages in the Java language ecosystem. In late 2021, a vulnerability was discovered in Log4j, nicknamed Log4Shell. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><span data-contrast=\"auto\">Log4Shell is widely considered among the most severe software vulnerabilities in history. It allows attackers to execute code remotely and insert malware or take control of impacted devices, potentially numbering in the hundreds of millions.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Assessing the impact of and remediating Log4Shell was and, for many organizations, continues to be an expensive, challenging, and time-consuming effort. First, Log4j is ubiquitous\u2014almost every organization uses Java, which means they use Log4j. Second, most organizations don&#8217;t have a good process for managing open-source across the enterprise. This means that when another Log4Shell-style vulnerability emerges, they&#8217;ll experience this same pain again.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h2 style=\"text-align: center;\"><strong>3 Tips to Improve Your Open-Source Software Supply Chain&#8217;s Health and Security<\/strong><\/h2>\n<hr \/>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">So <a href=\"https:\/\/solutionsreview.com\/endpoint-security\/lessons-on-how-to-harden-software-supply-chains-from-recent-attacks\/\" target=\"_blank\" rel=\"noopener\">how can organizations prepare for the next vulnerability<\/a> and more effectively manage the health and security of their open-source software supply chain? These three steps provide a good start.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>Step 1: Understand your open-source usage\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The first step to implementing a best-in-class strategy for managing open-source is to get better visibility into the open-source components already in use within your organization. This often involves creating a software bill of materials (SBOM) to track open-source components, versions, and upstream transitive dependencies (additional features being called by the components you are using) across the organization. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">This SBOM can&#8217;t just be a static document because components and versions in use are constantly changing as new versions become available, as security vulnerabilities are patched, etc. When Log4Shell happened, organizations with a comprehensive SBOM or set of SBOMs documenting open-source usage could triage and remediate impacted applications.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Last year&#8217;s <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">White House Executive Order on Improving the Nation&#8217;s Cybersecurity<\/span><\/a><span data-contrast=\"auto\"> accelerated a chain of events increasing the urgency around maintaining accurate SBOMs. In essence, it stated that any organization wanting to sell to the US Government would have to provide an SBOM showing the software components in use while simultaneously attesting to the integrity and provenance of these components.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>Step 2: Define security, maintenance, and licensing standards\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Once your organization has a sense for the open-source already in use today, it can turn attention to defining a set of standards and policies around open-source usage. What policies or procedures should you use when bringing new components into the organization? Do you have different levels of security tolerance for internet-facing applications vs. internal? Are there specific open-source licenses or categories of licenses that are not acceptable to your legal team?<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">In organizations without clear standards around open-source security, maintenance, and licensing, developers are slowed down because they don&#8217;t have consistent answers regarding how to bring in and manage the long-term health of open-source components. This leaves them to either address these issues on their own as they come up\u2014which they may not have the specific knowledge or experience to do effectively\u2014or worse, ignore them and create risk for the organization.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>Step 3: Build a centralized repository of approved open-source components\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The best way to ensure your developers can move fast and stay safe when building applications with open-source technology is to create a trusted repository of approved open-source components that meet your organization&#8217;s security, maintenance, and licensing standards. Developers can pull pre-vetted components directly from the centralized repository when building applications. <\/span><span data-contrast=\"auto\">While this requires a resource investment to centralize the workaround approving and updating guidance for open-source components in the repository, it will save the organization money in the long term because it creates an economy of scale. How?<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Rather than each developer vetting and making decisions on open-source components on their own, work that may be done for the same piece several times by different developers, a centralized repository means that vetting work is done once for the entire organization. Over time, this repository of approved components will continue to grow, which means more components will be pre-vetted when a developer finds the need for them, allowing them to avoid bureaucratic approval processes.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">Think of the repository as a box of crayons. When you start building a repository, it may be a box with eight crayons, but over time, it can grow to be the 64 crayon box or the 264 crayon box, and the developers will have more choice while accelerating their development pace.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<h3 style=\"text-align: justify;\" aria-level=\"2\"><strong>A More Healthy and Secure Open-Source Software Supply Chain\u00a0<\/strong><\/h3>\n<p style=\"text-align: justify;\"><span data-contrast=\"auto\">The best way to improve the health and security of the open-source software supply chain is systematically over time. But once your organization has gone through the process of 1) understanding their open-source usage, 2) defining security, maintenance, and licensing standards, and 3) building a centralized repository of approved open-source components, they&#8217;ll be much better positioned to help ensure their developers are moving fast and staying safe, while also taking advantage of the full innovative potential of open-source at the same time.<\/span><\/p>\n<hr \/>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\"><div class=\"widget\"><div class=\"aside-card\">\t\t\t<div class=\"textwidget\"><p><a class=\"#\" href=\"https:\/\/solutionsreview.com\/endpoint-security\/free-endpoint-protection-buyers-guide\/\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1682\" src=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2019\/01\/endpoint-security-speedbump-cta.jpg\" alt=\"Download Link to Endpoint Security Buyer's Guide\" width=\"800\" height=\"225\" \/><\/a><\/p>\n<\/div>\n\t\t<\/div><\/div><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As part of Solutions Review&#8217;s Premium Content Series\u2014a collection of contributed columns written by industry experts in maturing software categories\u2014Donald Fischer, the co-founder and CEO of Tidelift, shares some insights on improving the health and security of an open-source software supply chain. When it comes to modern enterprise application development, open-source software is everywhere. Some [&hellip;]<\/p>\n","protected":false},"author":115,"featured_media":4923,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[2,335],"tags":[1603,1606,1590,1609,1605,1596,1608,1607,1592,1604],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>3 Tips to Improve Open-Source Software Supply Chain Health and Security<\/title>\n<meta name=\"description\" content=\"As part of Solutions Review&#039;s Premium Content Series, Donald Fischer of Tidelift shares insights on improving open-source software supply chain security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"3 Tips to Improve Open-Source Software Supply Chain Health and Security\" \/>\n<meta property=\"og:description\" content=\"As part of Solutions Review&#039;s Premium Content Series, Donald Fischer of Tidelift shares insights on improving open-source software supply chain security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Best Endpoint Protection Security (EPP) Tools, Software, Solutions &amp; Vendors\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/solutionsreview\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-03T12:27:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-03T14:34:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Donald Fischer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@InfoSec_Review\" \/>\n<meta name=\"twitter:site\" content=\"@InfoSec_Review\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Donald Fischer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\"},\"author\":{\"name\":\"Donald Fischer\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/6c17476a46ddf32c55f63869f23d9110\"},\"headline\":\"3 Tips to Improve Open-Source Software Supply Chain Health and Security\",\"datePublished\":\"2022-03-03T12:27:18+00:00\",\"dateModified\":\"2022-03-03T14:34:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\"},\"wordCount\":1044,\"publisher\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#organization\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg\",\"keywords\":[\"Donald Fischer\",\"Log4j\",\"Log4Shell\",\"Open-Source Software\",\"Open-Source Software Supply Chain\",\"Premium Content Series\",\"SBOM\",\"Software Bill of Materials\",\"Software Supply Chain\",\"Tidelift\"],\"articleSection\":[\"Best Practices\",\"Featured\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\",\"name\":\"3 Tips to Improve Open-Source Software Supply Chain Health and Security\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg\",\"datePublished\":\"2022-03-03T12:27:18+00:00\",\"dateModified\":\"2022-03-03T14:34:08+00:00\",\"description\":\"As part of Solutions Review's Premium Content Series, Donald Fischer of Tidelift shares insights on improving open-source software supply chain security.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg\",\"width\":800,\"height\":400,\"caption\":\"Open-Source Software Supply Chain\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/endpoint-security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"3 Tips to Improve Open-Source Software Supply Chain Health and Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#website\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/\",\"name\":\"Best Endpoint Protection Security (EPP) Tools, Software, Solutions &amp; Vendors\",\"description\":\"All the Latest News, Best Practices and Buyer&#039;s Guides for Endpoint Security and Protection\",\"publisher\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/endpoint-security\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#organization\",\"name\":\"Solutions Review\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png\",\"contentUrl\":\"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png\",\"width\":200,\"height\":200,\"caption\":\"Solutions Review\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/solutionsreview\",\"https:\/\/x.com\/InfoSec_Review\",\"https:\/\/www.linkedin.com\/company\/cyber-security-solutions-review\",\"https:\/\/www.youtube.com\/user\/SolutionsReview\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/6c17476a46ddf32c55f63869f23d9110\",\"name\":\"Donald Fischer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/93528aaf80ecdaf85a4b9bf3d7585087?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/93528aaf80ecdaf85a4b9bf3d7585087?s=96&d=mm&r=g\",\"caption\":\"Donald Fischer\"},\"description\":\"Donald Fischer is the VP at Sonar. Previously he was a venture partner at General Catalyst, a member of the investment team at Greylock Partners, and an executive at Typesafe (now Lightbend) and Red Hat. He holds a BS in economics and computer science from Yale University, an MS in computer science from Stanford University, and an MBA from Columbia Business School.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/donaldfischer\/\"],\"url\":\"https:\/\/solutionsreview.com\/endpoint-security\/author\/dfischer\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"3 Tips to Improve Open-Source Software Supply Chain Health and Security","description":"As part of Solutions Review's Premium Content Series, Donald Fischer of Tidelift shares insights on improving open-source software supply chain security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/","og_locale":"en_US","og_type":"article","og_title":"3 Tips to Improve Open-Source Software Supply Chain Health and Security","og_description":"As part of Solutions Review's Premium Content Series, Donald Fischer of Tidelift shares insights on improving open-source software supply chain security.","og_url":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/","og_site_name":"Best Endpoint Protection Security (EPP) Tools, Software, Solutions &amp; Vendors","article_publisher":"https:\/\/www.facebook.com\/solutionsreview","article_published_time":"2022-03-03T12:27:18+00:00","article_modified_time":"2022-03-03T14:34:08+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg","type":"image\/jpeg"}],"author":"Donald Fischer","twitter_card":"summary_large_image","twitter_creator":"@InfoSec_Review","twitter_site":"@InfoSec_Review","twitter_misc":{"Written by":"Donald Fischer","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#article","isPartOf":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/"},"author":{"name":"Donald Fischer","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/6c17476a46ddf32c55f63869f23d9110"},"headline":"3 Tips to Improve Open-Source Software Supply Chain Health and Security","datePublished":"2022-03-03T12:27:18+00:00","dateModified":"2022-03-03T14:34:08+00:00","mainEntityOfPage":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/"},"wordCount":1044,"publisher":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#organization"},"image":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg","keywords":["Donald Fischer","Log4j","Log4Shell","Open-Source Software","Open-Source Software Supply Chain","Premium Content Series","SBOM","Software Bill of Materials","Software Supply Chain","Tidelift"],"articleSection":["Best Practices","Featured"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/","url":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/","name":"3 Tips to Improve Open-Source Software Supply Chain Health and Security","isPartOf":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg","datePublished":"2022-03-03T12:27:18+00:00","dateModified":"2022-03-03T14:34:08+00:00","description":"As part of Solutions Review's Premium Content Series, Donald Fischer of Tidelift shares insights on improving open-source software supply chain security.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#primaryimage","url":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg","contentUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2022\/03\/3-Tips-to-Improve-Open-Source-Software-Supply-Chain-Health-and-Security.jpg","width":800,"height":400,"caption":"Open-Source Software Supply Chain"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/endpoint-security\/tips-to-improve-open-source-software-supply-chain-health-and-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/endpoint-security\/"},{"@type":"ListItem","position":2,"name":"3 Tips to Improve Open-Source Software Supply Chain Health and Security"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#website","url":"https:\/\/solutionsreview.com\/endpoint-security\/","name":"Best Endpoint Protection Security (EPP) Tools, Software, Solutions &amp; Vendors","description":"All the Latest News, Best Practices and Buyer&#039;s Guides for Endpoint Security and Protection","publisher":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/endpoint-security\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#organization","name":"Solutions Review","url":"https:\/\/solutionsreview.com\/endpoint-security\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/","url":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png","contentUrl":"https:\/\/solutionsreview.com\/endpoint-security\/files\/2016\/05\/SR_Icon.png","width":200,"height":200,"caption":"Solutions Review"},"image":{"@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/solutionsreview","https:\/\/x.com\/InfoSec_Review","https:\/\/www.linkedin.com\/company\/cyber-security-solutions-review","https:\/\/www.youtube.com\/user\/SolutionsReview"]},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/6c17476a46ddf32c55f63869f23d9110","name":"Donald Fischer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/endpoint-security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/93528aaf80ecdaf85a4b9bf3d7585087?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/93528aaf80ecdaf85a4b9bf3d7585087?s=96&d=mm&r=g","caption":"Donald Fischer"},"description":"Donald Fischer is the VP at Sonar. Previously he was a venture partner at General Catalyst, a member of the investment team at Greylock Partners, and an executive at Typesafe (now Lightbend) and Red Hat. He holds a BS in economics and computer science from Yale University, an MS in computer science from Stanford University, and an MBA from Columbia Business School.","sameAs":["https:\/\/www.linkedin.com\/in\/donaldfischer\/"],"url":"https:\/\/solutionsreview.com\/endpoint-security\/author\/dfischer\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/posts\/4920"}],"collection":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/users\/115"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/comments?post=4920"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/posts\/4920\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/media\/4923"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/media?parent=4920"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/categories?post=4920"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/endpoint-security\/wp-json\/wp\/v2\/tags?post=4920"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}