Founded in 2014, Source Code Control is a leading consultancy specializing in Software Supply Chain Management. We help organizations where software is central
The developers behind LibreOffice have questioned Euro-Office’s sovereignty credentials and use of a Microsoft-based document format
A California TV case may sound far from cars, but modern dashboards run on open-source software too. If buyers can enforce those licenses, automakers may face a new kind of software accountability.
Your open-source dependencies are a ticking clock, and CVE scanners won't save you. Uncover the truth behind recent supply chain attacks and AI-driven risks.
The EU’s Cyber Resilience Act aims to make hardware and software more secure, and applies to vendors and to end-user organizations.
SBOM adoption is advancing, but data quality, skills, and completeness gaps remain, according to ENISA's findings.
Euro-Office 1.0 launches June 9 as a free, open-source Microsoft 365 alternative built entirely on European infrastructure. The suite integrates into Nextcloud Hub 26 Spring and supports real-time...
Coding agents are no longer just tools---they are becoming contributors. This talk explores how agents will transform open source development, from autonomously writing code and fixing bugs to...
Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.
OpenSSF warns that 66% of open source practitioners are unready and unaware of the Cyber Resilience Act compliance deadline
The EU's new tech sovereignty package is met with mixed reactions: open-source advocates rejoice, but US industry associations warn of severe market disruptions.
According to a recent LinkedIn post from RunSafe Security, the company’s CTO, Shane Fry, was interviewed by Critical Software on software bills of materials (SBOMs)...
In May 2026, malicious code appeared inside packages used across NHS software projects. The software supply chain attack named Mini Shai-hulud by researchers
Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks
Bambu Lab’s critics continue to line up to take shots at the company. Following the company's pressure to take an OrcaSlicer fork that restores the connection to its cloud service offline, attention...
Thousands are daring Bambu to take legal action.
Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud.
Traficom will oversee the Cyber Resilience Act market surveillance and notified bodies, while AI Act authorities supervise high-risk AI systems.
In a move to reduce extra-European dependencies, France’s Interministerial Directorate for Digital Affairs (DINUM) has announced in April that all government workstations will be using Linux by 2027.
Most organisations now accept that software supply chain risk is no longer a niche security concern. The pressure comes from every direction at once.
Open source and Microsoft finally became friends with a slightly awkward handshake.