Cloud Native

Lineaje AI cuts open-source software maintenance costs by up to 50% | Javed Hasan -Lineaje

0

Securing the modern software stack is becoming increasingly complex due to the widespread adoption of open-source software, which uses code from  a variety of sources, including dependencies and libraries. However, open-source software also offers advantages for security, as organizations are not dependent on a single vendor to identify and fix patches. Instead, they can manage and patch issues independently and more quickly.

To facilitate securing the entire software supply chain, “Lineaje provides solutions for the entire software supply chain, including the software we source, build, sell and buy. We can give the full Lineaje and the inherent risks associated with all of that software,” says Javed Hasan, CEO and Co-Founder, Lineaje.

Highlights of this show:

Software supply chain security risks and solutions

  • Lineaje aims to trace the origins of software, addressing a crucial yet unresolved problem. When developers create software today, they assemble it as much as they code it. In fact, 70 to 80% of all software components are sourced externally, from open-source projects and third-party vendors.
  • Hasan explains that most software released today contains components whose origins are unknown. If a piece of software 25 levels deep is tampered with, most analysis tools cannot detect it. If you can’t see the tampering, you can’t prevent potential breaches.
  • This has led to a rise in software supply chain attacks, where compromised components infiltrate downstream development processes and ultimately reach customers, resulting in breaches. Lineaje addresses this by providing comprehensive solutions for software supply chain management.
  • Hasan points out that the awareness of software supply chain risks has increased due to executive order 14028, but customers still seek solutions.

Software security risks and challenges in open source software

  • Open source software risks increase as software components become more opaque and unknown.
  • Hasan highlights the fact that compliance mandates drive security needs, with government compliance mandates influencing software purchasing decisions.
  • He adds that patches may break software, leading to maintenance challenges.

Software maintenance, security, and compliance

  • Lineaje AI detects compatibility issues in software upgrades, reducing maintenance costs by 40-50%.
  • Hasan highlights the fact that security has become more important, with CEOs signing off on software compliance.

Software supply chain security and global expansion

  • Hasan highlights the growing importance of security, complexity of software development, and need for better tools to manage risk and protect brands.
  • He adds that Wipro Ventures invested in the company to distribute software globally.
  • The company aims to expand globally through Aramco’s funding and entry into the Middle East market.

Leveraging partnerships to expand rapidly in AI and supply chain security

  • AI workloads need Lineaje tracking for security and transparency in software development. AI as a workload has 4 components: frameworks, models, data, security.
  • Hasan discusses the importance of education and guidance in supply chain security, highlighting the need for industry experts to share their experiences and provide solutions.
  • The first Software Supply Chain Summit is scheduled for August 6 at Black Hat, with quarterly events to follow, providing a platform for vendors, customers, and practitioners to exchange ideas and solve supply chain security problems.

Guest: Javed Hasan (LinkedIn)
Company: Lineaje (Twitter)
Show: Let’s Talk

Perforce delivers enhanced security in latest Static Analysis release

Previous article

Hazelcast’s new vector search capability and its potential applications in AI workloads | Anthony Griffin

Next article