(Photo courtesy Sonatype/YouTube)
Fulton-based Sonatype is bringing on some deeper knowledge about potential security vulnerabilties with an acquisition.
The company that makes tools to automate software processes and potential holes in open source code acquired Vor Security, which is based in Ottowa, Canada. Terms were not disclosed.
Vor Security founder Ken Duck created the OSS Index, which is an index of open source software vulnerabilities. The startup complied details on 120,000 security vulnerabilities. Access is initially free, and the company also offers premium licensing and support.
— Derek E. Weeks (@weekstweets) June 29, 2017
The two companies are also complementary in their approach.
“Vor approached the vulnerability correction and assignment from the project to the components, which is exactly opposite of the Sonatype approach of finding the vulnerable code and tracking it back to the released component,” Sonatype’s Brian Fox wrote in a blog post about the deal. “By merging the top down and bottom up approaches, we can significantly increase our vulnerability coverage.”
Sonatype was founded in 2010 by Wayne Jackson, who was previously CEO of Sourcefire. The company raised $30 million last year, and has a host of corporate clients.
Duck, the Vor founder, will join Sonatype in the deal.-30-
Congressman: ‘No evidence’ that NSA cyberweapon was used in Baltimore
Protecting passwords: Relatively simple solutions for a big cybersecurity risk
Alliance Data Systems acquires ‘select’ tech assets of Baltimore-based Blispay
Building a data acquisition system? Don’t make this mistake
NYT: Tool used in cyber attack on City of Baltimore was developed at Maryland-based NSA
Mayor: City of Baltimore will have to rebuild some IT systems to recover from cyber attack
City of Baltimore ransomware attack affects home sales, payments and more
How SmartLogic accelerated these startups’ product growth trajectories
Sign-up for daily news updates from Technical.ly Baltimore