Blog

From the blog

Perspectives on regulation, supply-chain attacks and compliance.

Categories
Topics
16 posts
18 Sept 2026 · Entwicklungsprozess, Risk Management, Kryptographie, Crypto-Agility, SCA

Crypto Agility – Making Your Software Post-Quantum Ready

NIST's post-quantum standards are out — here's why Crypto Agility should already be a top priority in your software development process.

Crypto AgilityPost-QuantumCryptographic AgilitySBOMNISTSupply Chain Risk
8 Sept 2026 · Risk Management, Schwachstellen, Supply Chain, Threat Modelling

Threat Modeling at Scale: Automating What Used to Take Weeks

Threat modeling stays sporadic because it's complex and manual. See how automation reshapes the economics and why v3 finally makes it accessible.

ThreatmodelingThreat Modeling AutomationDevSecOpsProduct SecuritySTRIDE
7 Sept 2026 · Risk Management, Schwachstellen, Threat Modelling, Vulnerability

How Risk-Based Vulnerability Management Changes the Game

Most teams drown in CVEs. This article shows why risk-based prioritization — not patch velocity — is the metric that truly reduces exposure.

Vulnerability ManagementCVERisk-Based PrioritizationCVSSSoftware Vulnerability
27 Aug 2026 · Product security, emb3d, release management

Tackling the Challenge of Matching Product and Software Release Cycles

Hardware and software ship on different cadences. How TrustSource's product package keeps SBOMs, CVE mappings and compliance status consistent across both timelines.

SBOMSoftware Bill of MaterialsProduct SecuritySoftware ReleaseSupply Chain Risk
12 Jun 2026 · sca

Running ts-scan from a Docker Image

A concise technical walkthrough showing how to pull and run the official ts-scan Docker image and pipe results into TrustSource.

SCASoftware Composition Analysists-scanDockerDevSecOps
27 May 2026 · risk-management

Integrated Risk Management: From SBOM to Board Insight

Risk management in software is maturing beyond spreadsheets: structured SBOM and threat-modeling data can produce risk postures teams can act on.

Risk ManagementSoftware RiskSupply Chain Riskthreat modelingSBOM
21 May 2026 · Background, Knowledge

Why Every Software Team Needs an SBOM Strategy in 2026

Regulatory pressure from the CRA and NIS2 keeps rising. A field report on why an SBOM is an operational tool, not just a compliance checkbox.

sbomscacyclonedxspdxopen source
10 Mar 2026 · Resources, Solutions

TrustSource adds EoL data

Unknown EoL components silently threaten security every day. The EU Cyber Resilience Act makes lifecycle management mandatory.

27 Feb 2026 · Knowledge, Resources, Solutions

Securing the foundations

SCA in C/C++ world remains a challenge. Learn how bimodal scanning will help you to reduce analysis efforts...

cpluspluscryptocybersecurityembeddedSBOM
1 Feb 2026 · Cryptography, Knowledge

Beyond the Horizon: The Architecture of Quantum Resilience

Post Quantum Readiness requires as a first step to set up an asset inventory cataloging the algorithms used.

crypto-algorithmsinventorypost-quantumquantumquantum agility
28 Jan 2026 · Announcements, Products, Solutions

ts-scan available as github-action

TrustSource added ts-scan github action to github's marketplace. You may add it directly into your repositories workflows. Read more for details!

algorithmsautomationcompliancecrypto-algorithmscyclonedx
25 Jan 2026 · Cryptography, Knowledge, Security, Solutions

Navigating PQC Threat

Understand the threats arising from quantum computing to today's cryptography and learn how to protect your applications.

crypto-agorithmsencryptionpost-quantumquantumSCA
24 Sept 2025 · Products, Security, Solutions

Update ts-scan to v1.5.2

Based on the learnings from the Shai-Hulud attack, we limited the default configuration of ts-scan to prevent script execution from package.json.

9 Sept 2025 · Knowledge, Security

Tackling the nx-Challenge

the latest software supply chain attack on the nx component is a good example on how vulnerable our development environments are.

component impactsoftware supply chain securitySSCS
28 Jan 2025 · Security

TSSI-25:0000 - Security Information Feed Test

A test advisory (TSSI-25:0000) confirming the TrustSource Security Information RSS feed is live and working as expected.

informationsecurityvdf
19 Jan 2025 · Announcements, Knowledge, Resources

Cyber Resilience Act published

The EU Cyber Resilience Act (CRA) has been published recently. This article summarises the major impacts and obligations this will cause.

CRACyber Resilience ActEunew regulationsobligations