logo

2025 Was Quietly Good for Application Security

ID: 7d642c29-f17d-5eb7-af6d-2af80fcbb06a

STIX ID: report--7d642c29-f17d-5eb7-af6d-2af80fcbb06a

Feed Name: Checkmarx Zero

Date Published: 2025-12-29

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

The report surveys six 2025 advances that strengthened software supply-chain security and developer safety: tougher npm/GitHub controls (mandatory 2FA, trusted publishing via short‑lived tokens, removal of legacy tokens, and faster coordinated takedowns), safer-by-default developer tooling and reduced default permissions, new GitHub constraints to blunt malicious pull requests, broader adoption of a shared “supply chain risk” language to drive SDLC improvements, greater cross‑organization researcher collaboration, and reduced reliance on a single government’s vulnerability programs via initiatives like the CVE Foundation, EUVD, and OSV.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.