Endor Labs Emerges From Stealth With $25 Million

<p><strong>PALO ALTO<&sol;strong> &&num;8212&semi; Endor Labs officially came out of stealth and raised &dollar;25 million&comma; launching the company with a Dependency Lifecycle Management Platform that helps development and security teams maximize software reuse by safely evaluating&comma; maintaining&comma; and updating dependencies&period;<&sol;p>&NewLine;<p>Endor Labs has raised &dollar;25 million in seed financing from Lightspeed Venture Partners&comma; Dell Technologies Capital&comma; and Sierra Ventures&comma; and several industry luminaries who have recognized the massive problem Endor Labs is solving&period; These include CEOs and executives from Palo Alto Networks&comma; Zoom&comma; Snowflake&comma; Zscaler&comma; Netskope&comma; Rubrik&comma; Databricks&comma; Microsoft&comma; and more&period;<&sol;p>&NewLine;<p>The average enterprise has more than 40&comma;000 open source dependencies directly downloaded by developers&period; Each of those dependencies can bring in on average 77 other &lpar;transitive&rpar; dependencies creating a massive&comma; uncontrollable sprawl that slows down development and increases the attack surface across multiple dimensions&period;<&sol;p>&NewLine;<p>The existing environment doesn’t have adequate solutions to deal with this problem&period; For example&comma; Software Composition Analysis &lpar;SCA&rpar; tools lack context on how developers are using the dependencies&period; As a result&comma; they drown developers with endless false positives&comma; and miss the ability to influence better OSS selection&comma; prioritize remediation or detect malicious dependencies&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;Eighty percent of the code in modern applications is code your developers didn’t write but depend on through open source packages&period; When our founding team was leading the Prisma Cloud engineering group at Palo Alto Networks&comma; we realized the true magnitude of this issue&comma;” said co-founder and CEO Varun Badhwar&period; &OpenCurlyDoubleQuote;Having previously created the Cloud Security Posture Management &lpar;CSPM&rpar; category&comma; this team knows how to take on next generation threats&period; Our mission now is to enable OSS to live up to its true potential without introducing unnecessary risk&period; It’s exciting to once again take a new approach to the market&comma; and we believe these solutions will radically enhance application development everywhere&period;”<&sol;p>&NewLine;<p>Endor Labs’ platform provides security and development teams with an unprecedented understanding of how dependencies are being used across their organization&period; Furthermore&comma; by performing deep analytics on each OSS dependency&comma; Endor Labs uncovers potential security and operational risks beyond just known vulnerabilities&period; Endor Labs helps customers select better dependencies&semi; secure&comma; monitor and maintain them at scale&semi; and quickly respond to incidents like Log4j&period; Having a full understanding of their dependency graph also lets customers generate and analyze accurate SBOMs and have a single source of truth for their entire software inventory&period;<&sol;p>&NewLine;<p>This lifecycle approach to dependency management means it becomes easier than ever to reuse software across the org&period; The result is increased productivity for development and security teams&comma; and significantly reduced supply chain risk&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;Dependency Lifecycle Management is going to be absolutely foundational for supply chain and open source security&comma;” said Rachit Lohani&comma; SVP and chief technology officer of Paylocity&period; &&num;8220&semi;With Dependency Lifecycle Management&comma; Endor Labs is setting an entirely new standard by which organizations can prioritize and zero in on the most significant security and operational issues that have the tendency to slow down application development&period;”<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;Endor Labs serves a critical need — while open source software development continues to grow&comma; the way OSS dependencies and their influence on supply chain risk is managed today hinders development&comma; and leaves both engineering and security teams frustrated&comma;” said Arif Janmohamed&comma; Partner at Lightspeed Venture Partners&period; &OpenCurlyDoubleQuote;They have carved out a market that is both massive and underserved&comma; and have assembled a world-class team to take on this challenge&period; These are exactly the qualities we seek to add to our portfolio&comma; and we look forward to a long and productive relationship with Endor Labs&period;”<&sol;p>&NewLine;

Editor

NVIDIA Awards $60,000 Grants to 10 Ph.D. Students

For 25 years, the NVIDIA Graduate Fellowship Program has supported graduate students doing outstanding work…

9 hours

Sequoia Leads $140 Million Round in Fal

SAN FRANCISCO -- Fal, a real-time generative-media platform powering the next decade of AI-driven content,…

9 hours

IBM Acquiring Confluent for $11 Billion

ARMONK, NY -- IBM has agreed to buy Confluent, Inc., the data streaming pioneer, for…

2 days

Marvell Buying Celestial AI for $3.25 Billion+

SANTA CLARA -- Marvell Technology, Inc., a leader in data infrastructure semiconductor solutions, plans to…

2 days

ALM Ventures Debuts $100 Million Fund

MOUNTAIN VIEW -- ALM Ventures has announced the launch of ALM Ventures Fund I, a…

5 days

Brainworks Ventures Launches $50 Million AI-Native Fund

SAN FRANCISCO -- Brainworks Ventures, an AI-native venture capital fund led by DARPA alumnus Dr.…

5 days