Skip to main content

Hunted Labs Addresses the Open Source Requirements in Department of War Instruction 8430.01

ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Entercept and DepsDiver help defense programs and contractors assess foreign influence, project governance, and identify maintainer risk in open source software

Hunted Labs, the software supply chain security company behind the easyjson and fast-glob research, today detailed how its Entercept platform and DepsDiver tool help defense contractors meet the open source software risk assessment requirements under Department of War Instruction (DoWI) 8430.01, "Accelerated Mission Software," which took effect September 8, 2026.

DoWI 8430.01 directs DoW Components to prioritize open source and commercial software before building anything new, and requires them to assess specific risks in every third-party component they adopt. Those risks include potential adversarial ownership, investment, contribution, or control of an open source project. Hunted Labs builds contributor intelligence tools that identify who develops, maintains, and controls open source code, matching the analysis the instruction calls for.

DoWI 8430.01 is a Department-wide instruction issued by the DoW Chief Information Officer that applies to DoW Components and to programs containing software regardless of dollar value. For third-party and open source software, the instruction requires:

  • Analysis of six risk factors for every third-party component (§3.5.i(2)): sustainment, source trustworthiness, dependencies, security posture, integrity protections, and foreign influence risk.
  • A detailed review of every non-trivial open source component (§3.5.i(3)): governance and control model, including who holds commit authority; community health and security practices, including pull-request review rigor, disclosure policy, and maintainer track record; and license compliance and legal risk.
  • SBOM coverage (§3.5.i(4)): all third-party components, including transitive dependencies, listed in the system SBOM.
  • Continuous supply chain monitoring (§3.5.h): ongoing monitoring of deployed software for vulnerabilities and supply chain risks.
  • Review of AI-generated code (§3.6): code suggested or generated by AI treated as unverified input and subject to the same review and security testing as human-written code.

Learn more about Department of War Instruction (DoWI) 8430.01, "Accelerated Mission Software,” and its impact on open source code here.

Hunted Labs’ research highlighted the need for these requirements

Hunted Labs has published open source software threat research since 2025. In May 2025, the company reported that easyjson, a Go serialization package used in Kubernetes, Helm, and Istio, was maintained largely by Moscow-based developers at VK Group, whose CEO is sanctioned by the United States and European Union. In August 2025, the company reported that fast-glob, a Node.js utility with tens of millions of weekly downloads, is maintained by a single developer employed by Yandex. National press covered both reports, and the fast-glob findings were later cited in a Senate letter to the Office of the National Cyber Director.

How Entercept and DepsDiver support the DoW Instruction

  • Entercept™ covers the software organizations build and run. Its contributor attribution engine traces the people and organizations behind every open source component, flags suspicious activity patterns, and prioritizes risk based on developer behavior and code history. Entercept generates SBOMs with direct and transitive dependencies and searches containers and repos for compromised packages. It monitors continuously so teams learn when control of an existing dependency shifts (§3.5.h). Entercept deploys across the cloud and produces evidence that supports the §3.5.i(2)(f) foreign influence assessment.
  • DepsDiver™ vets packages before a team decides whether to adopt them. A search on any package returns project health, maintainer behavior, and control and influence signals, including ownership changes, governance shifts, and who is actually steering the project. That analysis is the heart of the §3.5.i(3) open source review. DepsDiver requires no SBOM, so a package can be investigated before it touches a build.
  • DepsDiver Assist brings the same signals into the developer's IDE. When a developer or an AI coding assistant adds a dependency, DepsDiver Assist flags high-risk packages in real time and shows the contributor details behind each alert. It then suggests safer alternatives and hands the swap to whichever AI code assistant the team is approved to use, supporting the §3.6 requirement to review AI-generated code as it is written.

Availability

Entercept and DepsDiver are available now. DepsDiver includes a free trial at huntedlabs.com/depsdiver. Program offices and defense contractors can request a demo at huntedlabs.com/request-a-demo.

About

Founded in 2024, Hunted Labs is an AI-native software security company helping organizations secure their software supply chains through real-time intelligence and behavioral attribution. By turning static data into actionable insights, Hunted Labs empowers security teams to identify blind spots, reduce noise, and stop threats before they spread. Visit us at huntedlabs.com and follow us on social media to join the hunt (LinkedIn).

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article

Recent Quotes

View More
Symbol Price Change (%)
AMZN  249.57
-5.41 (-2.12%)
AAPL  337.03
-2.72 (-0.80%)
AMD  613.58
-10.19 (-1.63%)
BAC  55.99
-0.21 (-0.36%)
GOOG  336.17
-11.24 (-3.24%)
META  749.38
+12.79 (1.74%)
MSFT  499.49
+1.49 (0.30%)
NVDA  225.45
-3.42 (-1.49%)
ORCL  145.59
-3.61 (-2.42%)
TSLA  379.87
+0.97 (0.26%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.