What Your Company Can Do About It
The first step, however cliché it may sound, is to admit you have a problem. Of all of the companies with which I’ve worked and spoken, the overwhelming majority aren’t aware of their SSC at all, let alone of the weak links in it. Once made aware, few choose to take action. More than once, I’ve seen one of these companies mentioned in the tech press for suffering from vulnerabilities and related issues that were easily preventable with even a small amount of intention and attention.
Since relatively few companies have paid much attention to their FOSS supply chains, the ones that do are at a competitive advantage. The odds are that their competitors aren’t doing much to ensure the integrity and sustainability ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access