Sushi Bytes

Due Diligence Déjà Vu: License Compliance in Software M&A

4 min · 29. joulu 2025
jakson Due Diligence Déjà Vu: License Compliance in Software M&A kansikuva

Kuvaus

Startups are moving fast – fueled by AI-generated code, experimental “vibe coding,” and a breakneck pace of shipping software. But when those startups become acquisition targets, things can get messy. In this episode, Shinobi goes solo (with Gen temporarily sidelined by a network outage) to unpack how this new wave of coding introduces license risk that traditional SBOMs miss. Learn why SCA-powered software audits are essential for surfacing modified open source fragments, how blind audits protect confidentiality, and why acquirers need more than metadata to see what’s really lurking in a target’s repo.

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity Sushi Bytes-yhteisöön!

Aloita nyt

1 kuukausi hintaan 1 €

Sitten 7,99 € / kuukausi · Peru milloin tahansa.

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

14 jaksot

jakson Agentic SCA is the Next Evolution in Software Supply Chain Integrity kansikuva

Agentic SCA is the Next Evolution in Software Supply Chain Integrity

AI didn’t just change how you build software, it broke your process for inspecting it for open source license compliance and security vulnerabilities. In this episode of Sushi Bytes, Shinobi and Gen reconnect with Aaron Branson to unpack FossID’s newly announced Agentic SCA strategy – and why the timing couldn’t be better after our last conversation on SCA in the AI Era. As code generation accelerates and the sheer volume of code explodes, software risk leaders are facing a new reality: more code, more complexity, and less time to react. Aaron breaks down how Agentic SCA shifts the process from passive scanning to active participation – embedding intelligence, automation, and policy enforcement directly into the development workflow. If you’re dealing with AI-generated code, SBOM pressure, or stepping up compliance rigor without slowing developers down – this is the conversation you need right now.

16. huhti 202613 min