{"id":74498,"date":"2022-03-22T09:03:00","date_gmt":"2022-03-22T13:03:00","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=74498"},"modified":"2026-01-26T17:36:30","modified_gmt":"2026-01-26T15:36:30","slug":"the-open-source-supply-chain-under-assault-new-defenses-are-required","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/","title":{"rendered":"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required"},"content":{"rendered":"<p class=\"has-text-align-center\"><strong><em>For those who\u2019ve been working in the world of information security over the last two decades have likely taken note of attacker Tactics, Techniques, and Procedures (TTP), and how they\u2019ve evolved over time. Let\u2019s take a closer look at what\u2019s changed.<\/em><\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">The Evolution of TTP<\/h2>\n\n\n\n<p>In the very beginning of cyberattacks, attackers would spend time creating self-propagating viruses and worms to exploit vulnerable operating systems and desktop applications. For example, the \u201cI Love You\u201d virus, which dates back to the year 2000, infected over ten million computers worldwide. Names like Code Red, SQL Slammer, Sobig, MyDoom, Netsky, Stuxnet, Zues, and so on, made headlines all over the globe. As a result, antivirus companies proliferated, holes were plugged in operating systems, devices and perimeters were hardened, bug bounties were initiated, and many of these TTPs were defeated.<\/p>\n\n\n\n<p>During much of this same period, a new genre of TTPs emerged in concert with these highly successful malware examples, and phishing became the new name &#8211; of an old game. Since perimeter and workstation defenses were somewhat difficult to overcome from the outside-looking-in, attackers knew that if they could fool someone into clicking on a link in an email, back doors could be opened, and perimeter defenses may well be defeated.<\/p>\n\n\n\n<p>Therefore, a whole new generation of malware surfaced in the form of ransomware and botnets. For example, names like Locky, Tiny Banker Trojan, Mirai, WannaCry, Petya, and many more were the next malware variants to gain notoriety. Email phishing defenses, spam detection systems, employee email phishing training, etc. proliferated and helped defeat some of these attacks.<\/p>\n\n\n\n<p>As a result, attackers likely began to conclude, \u201cIf we can infect a software supply chain, our malware proliferation and victim count could grow exponentially.\u201d And in December of 2020 they did just that. The SolarWinds supply chain attack took place, leading to both government and enterprise data breaches that made headlines worldwide. However, the SolarWinds\u2019 attack was leveraged against a commercial software supply chain and was not necessarily focused on what is called the <strong><em>open-source supply chain<\/em><\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">Why Supply Chain \u2013 Why Now?<\/h2>\n\n\n\n<p>Today\u2019s attackers realize that infecting the supply chain of open source libraries, packages, components, modules, etc., in the context of open source repositories, a whole new Pandora&#8217;s box can be opened. And as we all know, once you open that box, it\u2019s nearly impossible to close. In fact, Checkmarx leadership saw this coming. Back in December of 2019, Maty Siman, Founder and CTO of Checkmarx contributed to this predictions blog.<\/p>\n\n\n\n<p>Maty wrote, \u201cWith organizations increasingly leveraging open-source software in their applications, next year, we\u2019ll see an uptick in cybercriminals infiltrating open-source projects. Expect to see attackers \u2018contributing\u2019 to open source communities more frequently by injecting malicious payloads directly into open source packages, with the goal of developers and organizations leveraging this tainted code in their applications.<\/p>\n\n\n\n<p>As we see this scenario unfold, there will be a growing need for processes like developer and open-source contributor background checks [contributor reputation]. Currently, open-source environments are based entirely on trust &#8211; organizations typically don\u2019t vet developers\u2019 past projects or reputations. However, as attackers take advantage of open source projects, this trust will begin to erode, forcing organizations to take proactive mitigation steps by thoroughly vetting the open-source code within their applications, as well as those providing it.\u201d<\/p>\n\n\n\n<p>So, as we see here, Maty Siman was spot on. Not only did Checkmarx see attacks on the open-source supply chain coming, in fact, they did something about it by <a href=\"https:\/\/checkmarx.com\/press-releases\/checkmarx-acquires-software-supply-chain-security-provider-dustico\/\" target=\"_blank\" rel=\"noreferrer noopener\">acquiring<\/a> Dustico in August of 2021. Now, TTPs like dependency confusion, typosquatting, repository jacking (aka ChainJacking), and star jacking are the new name of the game. In fact, Checkmarx just released a new white paper today, <a href=\"https:\/\/info.checkmarx.com\/introduction-to-supply-chain-attacks?hs_preview=RMSqrvvr-67871205396?utm_source=Blog&amp;utm_medium=Blog&amp;utm_search_query=ebook-understanding-open-source-supply-chain&amp;utm_campaign=MAD\" target=\"_blank\" rel=\"noreferrer noopener\">Introduction to Supply Chain Attacks<\/a>, explaining how these attacks actually work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">Landscape Changer: Checkmarx Supply Chain Security<\/h2>\n\n\n\n<p>As a result of Maty\u2019s predictions (which did come true, by the way), and their proactive stance on defeating supply chain attacks, Checkmarx just announced a new arrow in the quiver of enterprise-class, open-source supply chain defenses. Checkmarx SCA with Supply Chain Security (SCS) is now available, and the solution sets an entirely new bar for all SCA solutions.<\/p>\n\n\n\n<p>Checkmarx is first to market with supply chain defenses organizations need now which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Health and Wellness, and Software Bill of Materials (SBOM)<\/li>\n\n\n\n<li>Malicious Package Detection<\/li>\n\n\n\n<li>Contributor Reputation<\/li>\n\n\n\n<li>Behavior Analysis<\/li>\n\n\n\n<li>Continuous Results Processing<\/li>\n<\/ul>\n\n\n\n<p>In addition to our white paper on supply chain attacks, Checkmarx released another white paper today, <a href=\"https:\/\/info.checkmarx.com\/dont-take-code-from-strangers2?utm_search_query=whitepaper-don%E2%80%99t-take-code-from-stragners\" target=\"_blank\" rel=\"noreferrer noopener\">Don\u2019t Take Code from Strangers \u2013 An Introduction to Checkmarx Supply Chain Securit<\/a><a href=\"https:\/\/info.checkmarx.com\/dont-take-code-from-strangers2?utm_source=Blog&amp;utm_medium=Blog&amp;utm_search_query=whitepaper-don%E2%80%99t-take-code-from-stragners&amp;utm_campaign=MAD\" target=\"_blank\" rel=\"noreferrer noopener\">y<\/a>. This paper goes into detail about topics like SLSA, traditional code analysis, and pushing boundaries in secure software supply chain innovation.<\/p>\n\n\n\n<p>Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform. By natively integrating advanced behavioral analysis into SCA, Checkmarx provides developers with a streamlined, frictionless user experience to enhance their organization\u2019s supply chain security.<\/p>\n\n\n\n<p>To learn more about Checkmarx SCA with Supply Chain Security, you can request a demo <a href=\"\/solutions\/software-supply-chain-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>For those who\u2019ve been working in the world of information security over the last two decades have likely taken note of attacker Tactics, Techniques, and Procedures (TTP), and how they\u2019ve evolved over time. Let\u2019s take a closer look at what\u2019s changed. The Evolution of TTP In the very beginning of cyberattacks, attackers would spend time [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":74522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[84],"tags":[87,400,395,190,188,178,385],"class_list":["post-74498","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-appsec","tag-ast-platform","tag-awareness","tag-english","tag-open-source-security","tag-sca","tag-supply-chain-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The Open-Source Supply Chain Under Assault \u0096 New Defenses Are Required<\/title>\n<meta name=\"description\" content=\"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required\" \/>\n<meta property=\"og:description\" content=\"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-22T13:03:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-01-26T15:36:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-14.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1365\" \/>\n\t<meta property=\"og:image:height\" content=\"682\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Stephen Gates\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required\" \/>\n<meta name=\"twitter:description\" content=\"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-14.png\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Stephen Gates\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\"},\"author\":{\"name\":\"Stephen Gates\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/1ea38abd0315d0956c3c9c173724345b\"},\"headline\":\"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required\",\"datePublished\":\"2022-03-22T13:03:00+00:00\",\"dateModified\":\"2026-01-26T15:36:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\"},\"wordCount\":870,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg\",\"keywords\":[\"AppSec\",\"AST Platform\",\"Awareness\",\"English\",\"Open-Source Security\",\"SCA\",\"SSCS\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\",\"name\":\"The Open-Source Supply Chain Under Assault \u0096 New Defenses Are Required\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg\",\"datePublished\":\"2022-03-22T13:03:00+00:00\",\"dateModified\":\"2026-01-26T15:36:30+00:00\",\"description\":\"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg\",\"width\":1024,\"height\":512},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/1ea38abd0315d0956c3c9c173724345b\",\"name\":\"Stephen Gates\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_15.png\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_15.png\",\"caption\":\"Stephen Gates\"},\"url\":\"https:\/\/checkmarx.com\/author\/stephen\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The Open-Source Supply Chain Under Assault \u0096 New Defenses Are Required","description":"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/","og_locale":"en_US","og_type":"article","og_title":"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required","og_description":"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.","og_url":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2022-03-22T13:03:00+00:00","article_modified_time":"2026-01-26T15:36:30+00:00","og_image":[{"width":1365,"height":682,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-14.png","type":"image\/png"}],"author":"Stephen Gates","twitter_card":"summary_large_image","twitter_title":"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required","twitter_description":"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.","twitter_image":"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-14.png","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Stephen Gates","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/"},"author":{"name":"Stephen Gates","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/1ea38abd0315d0956c3c9c173724345b"},"headline":"The Open-Source Supply Chain Under Assault \u2013 New Defenses Are Required","datePublished":"2022-03-22T13:03:00+00:00","dateModified":"2026-01-26T15:36:30+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/"},"wordCount":870,"commentCount":0,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg","keywords":["AppSec","AST Platform","Awareness","English","Open-Source Security","SCA","SSCS"],"articleSection":["Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/","url":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/","name":"The Open-Source Supply Chain Under Assault \u0096 New Defenses Are Required","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg","datePublished":"2022-03-22T13:03:00+00:00","dateModified":"2026-01-26T15:36:30+00:00","description":"Checkmarx SCA with Supply Chain Security (SCS) offers a more comprehensive approach to preventing supply chain attacks and securing open-source usage by enabling developers to perform vulnerability, behavioral, and reputational analysis from a single, integrated platform.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/the-open-source-supply-chain-under-assault-new-defenses-are-required\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2022\/03\/MicrosoftTeams-image-11.jpg","width":1024,"height":512},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/1ea38abd0315d0956c3c9c173724345b","name":"Stephen Gates","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_15.png","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_15.png","caption":"Stephen Gates"},"url":"https:\/\/checkmarx.com\/author\/stephen\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/74498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=74498"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/74498\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/74522"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=74498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=74498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=74498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}