software provenance

AI Is Breaking Open Source Trust — And Provenance Is the Fix

AI Is Breaking Open Source Trust — And Provenance Is the Fix

AI-accelerated development is flooding open source maintainers with unreviewed pull requests while cryptographic signing and SBOM adoption remain dangerously low. Timothy Lewis of tea.inc. argues that provenance and identity are the missing foundations of enterprise software supply chain security. ECI Research data shows that AI-generated package risk is now the top open-source security concern for 2026.

AI Is Breaking Open Source Trust — And Provenance Is the Fix Read More »

CRA Compliance and Trustable Software: What OCX 2026 Revealed

CRA Compliance and Trustable Software: What OCX 2026 Revealed

The Eclipse Foundation’s OCX 2026 made clear that CRA compliance is a product development problem, not a legal checkbox. Manufacturers face a hard deadline, open source maintainers face an inbound wave of questionnaires, and AI-generated code is adding new layers of compliance debt. Here’s what ITDMs and developers need to act on now.

CRA Compliance and Trustable Software: What OCX 2026 Revealed Read More »