Over 70% of applications utilize open source software (OSS) components to speed up development cycles, but this introduces legal, security, and obsolescence risks, according to Gartner. The ubiquitous use of OSS in the software supply chain has increased organizations’ exposure to security attacks from hackers and legal action from IP owners. This has led organizations of all sizes globally to adopt a new standard for controlling open source risks requiring an SBOM to accompany any software being delivered, such as the recent cybersecurity executive order (EO) issued by the US federal government. Any business seeking to deliver software in today’s environment needs the ability to produce an SBOM with speed and accuracy.
CAST Highlight, a software intelligence product, plugs directly into source code repositories and analyzes applications in minutes, without disrupting developers. It performs Software Composition Analysis (SCA) of an application portfolio and automatically creates a full inventory of the 3rd party and Open Source components used within the codebase, including license versions. It highlights licensing exposures and security vulnerabilities as well as recommendations on the most critical remediations required. The SBOMs can be viewed and exported in Excel, Word, PPT, and CycloneDX.
CAST Highlight enabled us to assess OSS risks across all our applications in minutes versus hundreds of hours.
VP, Open Source Governance
We've tried alternatives. We recommend CAST Highlight due to its speed and lower cost.