From the blog
Perspectives on regulation, supply-chain attacks and compliance.
Why Every Software Team Needs an SBOM Strategy in 2026
Regulatory pressure from the CRA and NIS2 keeps rising. A field report on why an SBOM is an operational tool, not just a compliance checkbox.
TrustSource adds EoL data
Unknown EoL components silently threaten security every day. The EU Cyber Resilience Act makes lifecycle management mandatory.
Securing the foundations
SCA in C/C++ world remains a challenge. Learn how bimodal scanning will help you to reduce analysis efforts...
Beyond the Horizon: The Architecture of Quantum Resilience
Post Quantum Readiness requires as a first step to set up an asset inventory cataloging the algorithms used.
ts-scan available as github-action
TrustSource added ts-scan github action to github's marketplace. You may add it directly into your repositories workflows. Read more for details!
Navigating PQC Threat
Understand the threats arising from quantum computing to today's cryptography and learn how to protect your applications.
Update ts-scan to v1.5.2
Based on the learnings from the Shai-Hulud attack, we limited the default configuration of ts-scan to prevent script execution from package.json.
Tackling the nx-Challenge
the latest software supply chain attack on the nx component is a good example on how vulnerable our development environments are.
TSSI-25:0000 - Security Information Feed Test
A test advisory (TSSI-25:0000) confirming the TrustSource Security Information RSS feed is live and working as expected.
Cyber Resilience Act published
The EU Cyber Resilience Act (CRA) has been published recently. This article summarises the major impacts and obligations this will cause.