Lineaje Releases Open-Source Manager
May 01, 2024

Lineaje released Open-Source Manager (OSM), a solution to bring transparency to open-source software components in applications and proactively manage and mitigate associated risks.

Lineaje’s OSM enables full lifecycle governance of open-source software with trust, speed, and reliability helping to build an overall stronger security posture for complex software development organizations.

Lineaje's OSM unveils the hidden depths of open-source dependencies, tracing 20+ levels and pinpointing every package - down to the last level. It provides risk analysis for each component in that supply chain - including more vulnerabilities than any other tool. OSM automatically attests every component for tamperability and integrity - making it unique in its ability to discover components of dubious origin in software as well as to detect tampers like 3CX, XZ, and SolarWinds.

“As organizations continue to embrace open-source to drive high innovation and to accelerate development cycles, our software supply chain is effectively open-sourced. Open-source developers are typically great innovators but not-so-great maintainers of software," said Javed Hasan, CEO & Co-Founder, Lineaje. "OSM is an automated open-source office in a box, extending an organization's AppSec posture to open-source dependencies. It not only separates well-maintained and unmaintained open-source components but enables proactive mitigation of embedded open-source risks."

OSM goes beyond discovery by introducing an innovative "plan & fix” module. Not all patches or vulnerability fixes are equally compatible or applied at the same dependency depth. Lineaje AI with BOMbots generates plans in minutes for open-source patching so that developers can apply all compatible and all incompatible patches in batches. This reduces mean time to protect (MTTP) and saves up to 40% in software maintenance efforts. Unmaintained components with unfixed vulnerabilities and policy violations can be routed to inner or out-sourced teams chartered to maintain risky open-source dependencies.

The OSM solution enables companies to:

- Simplify Discovery & Search Comprehensively: Find and search all direct open-source dependencies down to the deepest level and discover the impact of vulnerabilities and risks.

- Analyze Inherent Risk: Automatically examine each component and application for risks–vulnerabilities, licenses, code quality, security posture, maintainability, age, supplier, provenance and more.

- Monitor Tamperability & Integrity Levels: Sophisticated fingerprinting identifies components that have suspicious and unknown origins.

- Establish Governance: Use consistent criteria for selecting, upgrading and fixing open-source components, and create rules for each. Auto-detect components violating policy using Lineaje’s Findings engine.

- Optimize Planning and Fix: Lineaje AI, using BOMbots, builds SMART “what if” plans in minutes. These SMART plans reduce maintenance efforts by up to 40%.

- Fix Unmaintained Open-Source: 95% of all vulnerabilities come from open-source; 56% of them are left unresolved. Unmaintained open-source components identified by OSM are routed to the inner or outer sourced development teams with detailed remediation instructions.

- Integrated Search: Search all dependencies in seconds for vulnerabilities, licenses, provenance, supplier details and more across all supply chain trees, enhancing operational efficiency.

Share this

Industry News

December 19, 2024

Check Point® Software Technologies Ltd. has been recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for Email Security Platforms (ESP).

December 19, 2024

Progress announced its partnership with the American Institute of CPAs (AICPA), the world’s largest member association representing the CPA profession.

December 18, 2024

Kurrent announced $12 million in funding, its rebrand from Event Store and the official launch of Kurrent Enterprise Edition, now commercially available.

December 18, 2024

Blitzy announced the launch of the Blitzy Platform, a category-defining agentic platform that accelerates software development for enterprises by autonomously batch building up to 80% of software applications.

December 17, 2024

Sonata Software launched IntellQA, a Harmoni.AI powered testing automation and acceleration platform designed to transform software delivery for global enterprises.

December 17, 2024

Sonar signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software.

December 17, 2024

Kindo formally launched its channel partner program.

December 16, 2024

Red Hat announced the latest release of Red Hat Enterprise Linux AI (RHEL AI), Red Hat’s foundation model platform for more seamlessly developing, testing and running generative artificial intelligence (gen AI) models for enterprise applications.

December 16, 2024

Fastly announced the general availability of Fastly AI Accelerator.

December 12, 2024

Amazon Web Services (AWS) announced the launch and general availability of Amazon Q Developer plugins for Datadog and Wiz in the AWS Management Console.

December 12, 2024

vFunction released new capabilities that solve a major microservices headache for development teams – keeping documentation current as systems evolve – and make it simpler to manage and remediate tech debt.

December 11, 2024

CyberArk announced the launch of FuzzyAI, an open-source framework that helps organizations identify and address AI model vulnerabilities, like guardrail bypassing and harmful output generation, in cloud-hosted and in-house AI models.

December 11, 2024

Grid Dynamics announced the launch of its developer portal.

December 10, 2024

LTIMindtree announced a strategic partnership with GitHub.