software supply chain

Airbyte Adds Workspaces and HubSpot Writes to Agentic Data Platform

Airbyte Adds Workspaces and HubSpot Writes to Agentic Data Platform

Airbyte has updated its Agents platform with Workspaces for scoped access control and write operations for HubSpot connectors. The moves address a critical governance gap in enterprise agentic AI deployments. ECI Research data shows why the timing aligns with where enterprise priorities are heading.

Airbyte Adds Workspaces and HubSpot Writes to Agentic Data Platform Read More »

Accuris BOM Intelligence AI: Verified Data Meets Supply Chain Risk

Accuris BOM Intelligence AI: Verified Data Meets Supply Chain Risk

Accuris has launched new AI capabilities for BOM Intelligence, combining natural-language component querying, continuous risk monitoring, and predictive compliance intelligence on a foundation of 1.3 billion verified components. The announcement makes a pointed argument that AI built on unverified data automates confusion rather than accelerating decisions. ECI Research analysis explains why verified data is becoming the real competitive moat in enterprise AI.

Accuris BOM Intelligence AI: Verified Data Meets Supply Chain Risk Read More »

Open Secure AI Alliance: NVIDIA's Bet on Open Cybersecurity

Open Secure AI Alliance: NVIDIA’s Bet on Open Cybersecurity

NVIDIA and more than 40 industry partners have formed the Open Secure AI Alliance, arguing that open AI models and harnesses are essential defensive assets for cybersecurity. The alliance is contributing open agent frameworks, supply chain integrity tools, and zero-trust identity infrastructure to a shared defense stack. ECI Research data shows enterprises already operate in blended open/closed security tooling models, making the alliance’s approach practically relevant today.

Open Secure AI Alliance: NVIDIA’s Bet on Open Cybersecurity Read More »

Kata Containers 4.0: Open Source AI Agent Sandboxing Grows Up

Kata Containers 4.0: Open Source AI Agent Sandboxing Grows Up

Kata Containers 4.0 promotes its Rust-based runtime to default, replacing Go, and positions the project as the open source standard for isolating AI agents in Kubernetes. The release addresses real production risk as nearly two-thirds of organizations report elevated security exposure from AI tooling. Confidential Containers integration broadens the appeal to regulated industries facing data sovereignty requirements.

Kata Containers 4.0: Open Source AI Agent Sandboxing Grows Up Read More »

Gurobi's Academic Report Reveals the GenAI-Optimization Opportunity

Gurobi’s Academic Report Reveals the GenAI-Optimization Opportunity

Gurobi’s first State of Mathematical Optimization in Academia report surveys 1,180+ faculty and students, revealing strong GenAI adoption in optimization workflows. The findings signal a long-term talent pipeline strategy as much as an academic exercise. ECI Research data shows engineering teams spend little time on net-new innovation, making AI-assisted optimization formulation a meaningful productivity lever.

Gurobi’s Academic Report Reveals the GenAI-Optimization Opportunity Read More »

AI Code Security: Why False Negatives Beat Hallucinations

AI Code Security: Why False Negatives Beat Hallucinations

Sonatype CTO Brian Fox argues that AI coding tools have become more dangerous as they’ve gotten smarter—trading visible hallucinations for silent false negatives that leave vulnerable dependencies undetected. The fix requires grounding AI models in real-time dependency intelligence, not just scanning code after it’s written. ECI Research data confirms AI code governance is the top enterprise security investment priority heading into 2026.

AI Code Security: Why False Negatives Beat Hallucinations Read More »

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus Opens Free Secure Container Image Catalog | ECI Research

Minimus is opening its entire catalog of near-zero CVE container images for free, with no registration required. ECI Research examines why the move targets the growing asymmetry between AI-accelerated vulnerability discovery and slow remediation, and what it means for enterprise DevSecOps strategy. Signed SBOMs and an agent-ready CLI make this more than a freemium play.

Minimus Opens Free Secure Container Image Catalog | ECI Research Read More »

AI Code Visibility Gap Widens as Production Use Hits 44.7%

AI Code Visibility Gap Widens as Production Use Hits 44.7%

Flux’s AI Code Generation Reality Check finds nearly half of organizations are running AI-generated code in production, while 35% can’t ship it confidently due to inadequate visibility. ECI Research examines the governance and tooling gaps this creates, and what engineering leaders should do next.

AI Code Visibility Gap Widens as Production Use Hits 44.7% Read More »

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance

The Eclipse Foundation and ORC Working Group have launched the ORC Learning Hub, a free modular training platform helping developers, maintainers, and security teams prepare for the EU’s Cyber Resilience Act. With the first CRA obligations taking effect in September 2026, the initiative addresses a critical gap in role-specific compliance education for open source software supply chains. ECI Research analysts assess what this means for ITDMs and engineering teams navigating the new regulatory landscape.

ORC Learning Hub: Preparing Open Source Teams for CRA Compliance Read More »

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom Bets Big on Spring Ecosystem Security | ECI Research

Broadcom has released the largest Spring security update in the framework’s history, introducing commercial-first CVE-only patches and a SLSA Level 3-validated Java supply chain. AI-accelerated threat discovery has broken traditional patching cycles, and Broadcom’s response sets a new benchmark for open source stewardship under commercial cover. ECI Research examines what this means for enterprise risk posture, developer workflows, and the competitive landscape.

Broadcom Bets Big on Spring Ecosystem Security | ECI Research Read More »