Topics include Supply Chain Security, Vulnerability Management, Neat Tricks, and Contributor insights.
Wednesday, August 12, 2026 in Ortelius Committer Insights
Modern software organizations are producing more software, more containers, and more releases than security teams can reasonably track by hand. Applications are assembled from hundreds or thousands of open-source packages and distributed across …
Tuesday, April 21, 2026 in Ortelius Committer Insights
The New Categories of Security in AI Systems For years, cybersecurity has largely focused on a familiar set of questions: Is there a software bug? Is a dependency vulnerable? Has the patch been applied? Those questions still matter. But Artificial …
Wednesday, April 01, 2026 in Ortelius Committer Insights
Most security teams still treat vulnerability management as a build-time activity. But attackers don’t. Modern supply-chain attacks don’t target source code repositories or CI pipelines alone, they mainly target running systems. Production is now the …
Wednesday, April 01, 2026 in Ortelius Committer Insights
Security teams today face a constant barrage of CVE notifications, so many that the signal gets buried in the noise. Over time, alert fatigue sets in, and remediation remains a manual, time-consuming source of engineering toil rather than a fast path …
Sunday, March 29, 2026 in Ortelius Committer Insights
What are Non-functional Requirements Non-functional requirements specify criteria that define the operation of a system rather than its specific behaviors. They describe attributes such as performance, security, scalability, reliability, and …
Wednesday, September 03, 2025 in Ortelius Committer Insights
Ortelius MCP Automated Dependency Bot – Technical Overview At the Ortelius Open Source Project, we’re always working behind the scenes to make our platform more powerful, secure, and reliable. A big part of that is managing the …
Thursday, May 08, 2025 in Ortelius Committer Insights
Ortelius for Post-Deployment Security to Jenkins As software supply chains grow more complex and vulnerabilities emerge faster than ever, Jenkins users face a critical challenge: “How do you keep your deployed applications secure after the …
Saturday, December 21, 2024 in Ortelius Committer Insights
Introduction The OpenSSF Scorecard is an essential security metrics tool incubating at the Linux Foundation’s OpenSSF. OpenSSF Scorecard is designed to expose an open-source project or package adherence to security best practices. It assigns …
Tuesday, December 17, 2024 in Ortelius Committer Insights
Introduction Ensuring a robust IT security compliance strategy is more critical than ever. For organizations, the ability to track and report security compliance effectively is not just a regulatory necessity but also a vital component of …
Tuesday, October 29, 2024 in Ortelius Committer Insights
Introduction The importance of Software Bill of Materials (SBOMs) in modern software development cannot be ignored. High-profile security incidents, like the SolarWinds attack or Log4J, underscore the critical need for greater transparency within …