YATA-NODE Blog

Blog

Secure development

Articles tagged "Secure development".

Technical

SBOM & OSS Compliance Tools — One Parts List, Two Lenses (US/EU)

Asked to "provide an SBOM"? A practical map: SPDX / CycloneDX today, ten tools by role (Syft, Trivy, Grype, OSV-Scanner, ScanCode, and SaaS), realistic setups by team size, a copy-paste CI recipe, and the US/EU drivers (EO 14028, EU CRA) — free OSS first.

Read more
Technical

Before You Build an Internal App — Three Pillars and a Pre-Release Checklist

Building an internal app in-house? A builder-and-approver guide: the convenience-vs-control trade-off, the shadow-IT to citizen-development to in-house gradient, the three pillars (operations, security, licensing), a pre-release checklist, and the US/EU secure-development picture (NIST SSDF, EU CRA/PLD).

Read more