FOSSA has acquired EdgeBit for an undisclosed amount, bringing together two companies at the forefront of software supply chain security. This strategic purchase underscores a commitment to fortifying modern software development processes against evolving security threats. EdgeBit provides a platform that empowers engineering teams to ship security updates significantly faster by automating dependency update analysis. Its technology transforms labor-intensive manual reviews into rapid, automated processes, helping organizations find and fix security vulnerabilities while maintaining a secure, up-to-date software supply chain.
EdgeBit's comprehensive platform specializes in continuous software composition analysis (SCA), real-time vulnerability management, and dependency autofix. It enables the continuous cataloging of open-source usage, identification of vulnerabilities, and mapping them to production environments. Key features include support for GitHub pipelines, Kubernetes, ECS, containers, and integrations with tools like Jira and Vanta, all designed to ensure vulnerabilities are not just identified but actively found, fixed, and merged with low risk.
This acquisition is a strategic move to significantly enhance FOSSA's offerings within the software security and open-source compliance landscape. By integrating EdgeBit's capabilities, FOSSA aims to provide an even more robust and comprehensive solution for managing the complexities of software dependencies and supply chain risks. EdgeBit's focus on automated remediation and real-time insights will complement FOSSA's existing platform, creating a more unified approach to software integrity and security posture management.
The combined entity is poised to deliver powerful synergies, accelerating the pace of security updates and streamlining vulnerability management for engineering and security teams. The integration is expected to offer customers an end-to-end platform for secure software delivery, from managing open-source governance to meeting stringent software supply chain regulations. The acquisition reflects a forward-looking vision to empower organizations to proactively address security challenges, ensuring productivity while building secure and compliant software.

