openPR Logo
Press release

GitHub Advanced Security Integrates Endor Labs Software Composition Analysis for End-to-End Application Security

02-12-2025 09:06 AM CET | IT, New Media & Software

Press release from: Endor Labs

GitHub Advanced Security now integrates Endor Labs Software Composition Analysis (SCA); Development teams can dismiss up to 92% of low-risk dependency security alerts, and focus on greatest threats and new capabilities

Endor Labs, the leader in open source software security, announced a critical partnership with GitHub, the platform for software developers to create and share code, that makes it easier than ever for application security teams and developers to accurately identify and remediate the most serious security vulnerabilities-all without leaving GitHub. In an environment where the number of Common Vulnerabilities and Exposures (CVEs) has spiked by 500% in just the past decade, the enhanced ease and precision enabled by the partnership will deliver major benefits to organizations.

"While a few supply chain attacks, like last year's XZ Utils episode, get wide attention, they represent only a fraction of the overall threat landscape," said Varun Badhwar, co-founder and CEO of Endor Labs. "The greatest risks instead come from unpatched vulnerabilities embedded in lesser-known open source dependencies. Effectively responding to all of those devours developer time and resources. Endor Labs technology makes it significantly easier to identify and prioritize the most serious threats, and developers can now derive those benefits while working within GitHub. We're proud to enter into this partnership with GitHub, and we look forward to jointly delivering many more technology advances."

The complications associated with hidden CVEs are buried deep inside the software development lifecycle. While the typical application development project has just 10 direct dependencies, each of those might have hundreds of indirect, or transitive, dependencies. It's estimated that up to 95% of all dangers can be found within these subsets. Developers do indeed get security alerts, but there are so many that the task of dealing with each one is overwhelming. Meanwhile, these efforts represent a massive distraction from the goal of delivering new applications and related technologies.

Endor Labs and GitHub bring significant advantages to this partnership. Endor Labs' SCA technology helps identify and prioritize dependency vulnerabilities by their potential impact, based on factors such as reachability, exploitability and more. For example, Endor Labs checks if the vulnerable function of a given dependency is actually reachable by a given application, or is just sitting in an unused corner of a transitive dependency. Similarly, GitHub Advanced Security (GHAS) - the developer-first application security suite that brings GitHub's world-class security capabilities to public and private repositories - integrates crucial security practices directly into the workflow, offering developers a streamlined way to secure their code. It enables code scanning, secret scanning, AI autofixes, and more.

Now, with Endor Labs SCA integrated into GitHub Advanced Security, development teams can dismiss up to 92% of low-risk dependency security alerts. That allows them to focus on the vulnerabilities that matter most, and the new capabilities they seek to deliver to users.

Just three months earlier, Microsoft - GitHub's parent company, natively integrated the Endor Labs advanced SCA capabilities within Microsoft Defender for Cloud, a leading Cloud-Native Application Protection Platform (CNAPP) to empower organizations to consolidate their application security and cloud security programs into a single platform, securing cloud workloads and code seamlessly in one place. The partnership now allows organizations to deploy SCA and CNAPP solutions from a unified dashboard, achieving comprehensive security coverage from code to runtime.

Read more about the partnership at https://github.blog/security/from-finding-to-fixing-github-advanced-security-integrates-endor-labs-sca/

444 High St Ste 300, Palo Alto, CA 94301

The pace and complexity of software development is rapidly intensifying. Developers are trying to keep up by maximizing reuse of code (internally developed as well as open source), adopting microservices architectures, and relying on a vast array of third party tools and services to automate bits and pieces of the CI-CD process. However, this can quickly sprawl and become untenable, only causing more headaches for development and security teams in the long term. Our mission is to deliver the impossible - create secure software supply chains that actually make developers more productive, rather than drowning in useless alerts. For more information, visit https://www.endorlabs.com.

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release GitHub Advanced Security Integrates Endor Labs Software Composition Analysis for End-to-End Application Security here

News-ID: 3863445 • Views:

More Releases from Endor Labs

Endor Labs Helps Organizations Identify and Select Secure Open Source Artificial Intelligence Models
Endor Labs Helps Organizations Identify and Select Secure Open Source Artificial …
Endor Scores for AI Models ranks available options for security, popularity, quality and activity; in step forward for AI governance, developers can now start clean with AI models Endor Labs, the leader in open source software security, today announced Endor Scores for AI Models, a unique capability that makes it easier than ever for companies to identify the most secure open source AI models currently available on Hugging Face, the popular
Endor Labs Receives Strategic Investment from Citi Ventures
Endor Labs, a leader in software supply chain security, announced a strategic investment from Citi Ventures. In a further validation of Endor Labs' unique approach to securing the software supply chain, this comes less than a year after the company received $70M in oversubscribed Series A financing from Lightspeed Venture Partners (LSVP), Coatue, Dell Technologies Capital, Section 32 and more than 30 industry-leading CEOs, CISOs and CTOs. Endor Labs was
Endor Labs Named a CRN 2023 Stellar Startup
Endor Labs, creator of the Code and Pipeline Governance Platform, has been named to the CRN 2023 Stellar Startups list in the application development category. This annual list, previously known as CRN Emerging Vendors, recognizes fast-rising technology manufacturers committed to delivering leading-edge solutions that propel innovation and growth in the IT channel. Jennifer Follett, vice president of U.S. Content and Executive Editor of CRN at The Channel Company, said: "With
Endor Labs Receives Intellyx Digital Innovation Award
Endor Labs Receives Intellyx Digital Innovation Award
Endor Labs, creator of the Code Governance platform helping development and security teams maximize the use of open source software (OSS), has been named a winner of the 2023 Intellyx Digital Innovator Award. Created by Intellyx, an industry analysis and advisory firm focused on digital transformation, it recognizes technology providers who make it through the company's rigorous briefing selection process - leading-edge vendors driving enterprise digital

All 5 Releases


More Releases for GitHub

Code Review Market Top Players- GitHub, Bitbucket, GitLab, Gerrit, Crucible.
InsightAce Analytic Pvt. Ltd. announces the release of a market assessment report on the " Code Review Market - (By Type (On-premise, Cloud-based), By Application (Individual, Enterprise), By Organization Size (Small, Medium, Large)), Trends, Industry Competition Analysis, Revenue and Forecast To 2031." According to the latest research by InsightAce Analytic, the Code Review Market is valued is expected to expand with a CAGR of 8.24% during the forecast period of 2024-2031. Get
Code Review Market Top Companies Study - GitHub, Bitbucket, GitLab, Gerrit, Cruc …
InsightAce Analytic Pvt. Ltd. announces the release of a market assessment report on the " Code Review Market - (By Type (On-premise, Cloud-based), By Application (Individual, Enterprise), By Organization Size (Small, Medium, Large)), Trends, Industry Competition Analysis, Revenue and Forecast To 2031." According to the latest research by InsightAce Analytic, the Code Review Market is valued is expected to expand with a CAGR of 8.24% during the forecast period of 2024-2031. Get
Software Development Tools Market Key Players - Spiralogics, CodeLobster, GitHub …
United States, New Jersey: Software Development Tools Market is growing at a faster pace with substantial growth rates over the past few years and is estimated that the market will grow significantly in the forecast period i.e. 2020 to 2027. The Software Development Tools Market has been experiencing significant growth over the past few years, driven by technological advancements, shifting consumer preferences, and increasing investment from both public and private sectors. This
Open Source Project Management Software Market | Frappe, GanttProject, GitHub, H …
The global open source project management software market report is a comprehensive report that provides a detailed analysis of the current status and future trends of the open source project management software market worldwide. This report provides valuable information to industry stakeholders by offering an in-depth perspective on market dynamics, competitive landscape, growth opportunities, and key challenges faced by industry participants. From the perspective of market dynamics, this report explores the
Code Manager Market Next Big Thing | Major Giants GitHub, MyGov, WAGsys Technolo …
The latest update on Global Code Manager Market study provides comprehensive valuable insights on the market development activities demonstrated by industry players, growth opportunities, and market sizing for Code Manager, complete with analysis by key segments, leading and emerging players and geographies (2022-2029). The 90 page study covers the detailed business overview of each profiled player, its complete research, and market development history with the latest news and press releases.
Agrifood Blockchain Market May See a Big Move | SAP, GitHub, Origintrail
Agrifood Blockchain is the latest research study released by AMR evaluating the market, highlighting opportunities, risk side analysis, and leveraged with strategic and tactical decision-making support. The study provides information on market trends and development, drivers, capacities, technologies, and the changing investment structure of the Agrifood Blockchain Market. The report demonstrates the trends and technological advancement in the Agrifood Blockchain industry. Also, the report offers a practical outlook with detailed