How Software Composition Analysis Transforms Open Source Risk Management
The gap between knowing what open source components you use and understanding the risk those components represent is where most software composition analysis programs stall. Generating an inventory is achievable.…