The 2020 SolarWinds hack served as an alarming wake-up call about the threat of the software supply chain, spurring rapid shifts in how organizations secure third-party applications. And yet, two years later, open source repositories remain ripe for exploitation.
The US government and the Open Source Security Foundation have released guidance to shore up software supply chain security, and now it's up to developers to act.