Comprehensive Software Supply Chain Analysis

    公开(公告)号:US20240193276A1

    公开(公告)日:2024-06-13

    申请号:US18064717

    申请日:2022-12-12

    CPC classification number: G06F21/577 G06F8/71 G06F9/54 G06F2221/033

    Abstract: A current a version of an external component (e.g., an open-source component or a third-party component) that is used in a software application is identified. A new version of the current version of the external component is identified (supply chain components). For example, the new version may have been just released by an open-source community. In response to identifying the new version of the current version of the of the external component, a series of actions are implemented that include: identifying changes to Application Programming Interfaces (APIs) in the new version of the current version of the external component; identifying new vulnerabilities in the new version of the current version of the external component; and determining a quality history associated with the new version of the current version of the external component. Based on the actions, a composite score is generated and displayed to a developer.

Patent Agency Ranking