Skip to main content
S

SafeDep

The startup offers an online platform that automates the vetting of open source software (OSS) dependencies through policy-driven guardrails integrated into CI/CD pipelines, including GitHub Actions, GitLab CI, and Jenkins. This solution enables engineering teams to enhance security and governance while mitigating risks associated with the use of potentially vulnerable OSS components.

Dover, United StatesFounded 20243200+ followers
Updated 3 months ago

Funding

$350K raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

Funding rounds are not available yet.

Founders

Product

Problem

Organizations face increasing risks from vulnerabilities, malicious code, and license violations within open source software (OSS) dependencies, which can be difficult to identify and manage at scale. Traditional software composition analysis (SCA) tools often lack contextual risk identification, leading to noisy and inefficient results.

Solution

SafeDep provides a platform for security engineering teams to implement policy-driven guardrails that mitigate risks associated with OSS components. The platform automates the vetting of OSS dependencies by integrating with CI/CD pipelines such as GitHub Actions, GitLab CI, and Jenkins. SafeDep leverages open source security metadata, internal GitHub repository metadata, and dynamic analysis to determine the safety of OSS components based on vulnerabilities, licensing, popularity, and potential malicious intent. It enables teams to build a continuous inventory of OSS components, enforce security policies as code, and protect against supply chain attacks.

Target Audience

SafeDep is designed for security engineering teams, DevSecOps teams, and open source maintainers who need to manage and mitigate risks associated with open source software dependencies.

Features

  • Automated scanning of source code repositories, package manifests, and container images to build a comprehensive OSS inventory
  • Integration with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins) for seamless deployment and continuous monitoring
  • Policy-as-code engine to automate organizational OSS security policies and enforce security guardrails
  • Aggregation of OSS security metadata from sources like deps.dev, OSV, NVD, and the OpenSSF scorecard
  • Dynamic analysis to uncover abnormal runtime behaviors and potential malicious activities in OSS packages
  • Generation of Software Bill of Materials (SBOMs) in CycloneDX format for regulatory compliance
  • Package Manager Guard (PMG) to protect developers from malicious packages at the time of installation
  • VS Code and Cursor extension scanning for malicious code
This profile is AI-generated and may contain inaccuracies.