DevSecOps - A DevOps Blog Category - DevOps.com https://devops.com/category/blogs/devsecops/ Where the world meets DevOps Tue, 17 Dec 2024 17:53:18 +0000 en-US hourly 1 https://devops.com/wp-content/uploads/2021/10/android-chrome-256x256-1-130x130.png DevSecOps - A DevOps Blog Category - DevOps.com https://devops.com/category/blogs/devsecops/ 32 32 144979424 Sonar Acquires Tidelift to Extend DevSecOps Reach Into Open Source Software https://devops.com/sonar-acquires-tidelift-to-extend-devsecops-reach-into-open-source-software/ Tue, 17 Dec 2024 17:53:18 +0000 https://devops.com/?p=174700 Tidelift, DevSecOps, code, open source, AWS, devsecops, Digital.ai DevSecOps business SDLC Integrating Security in the Development Process with DevSecOpsTidelift, DevSecOps, code, open source, AWS, devsecops, Digital.ai DevSecOps business SDLC Integrating Security in the Development Process with DevSecOpsSonar today revealed it has agreed to acquire Tidelift to gain access to third-party open-source code that it plans to integrate into its static code analysis tools.]]> 174700 DefectDojo Adds Ability to Normalize DevSecOps Data to ASPM Platform https://devops.com/defectdojo-adds-ability-to-normalize-devsecops-data-to-aspm-platform/ Tue, 10 Dec 2024 14:30:28 +0000 https://devops.com/?p=174484 defectdojo, parser, devsecops, DevSecOpsdefectdojo, parser, devsecops, DevSecOpsDefectDojo today added a universal parser to its application security posture management platform (ASPM) that makes it possible to normalize data ingested from any DevSecOps tools and platforms that expose data in a JSON or XML format.]]> 174484 How an Effective AppSec Program Shifts Your Teams From Fixing to Building https://devops.com/how-an-effective-appsec-program-shifts-your-teams-from-fixing-to-building/ Mon, 02 Dec 2024 13:55:48 +0000 https://devops.com/?p=174365 devsecops, developers, appsec, tool, appsec, Bionic modernization DevSecOps AppSec Cortex materialized view SIEMdevsecops, developers, appsec, tool, appsec, Bionic modernization DevSecOps AppSec Cortex materialized view SIEMDevelopment teams are under growing pressure to build cutting-edge applications with shorter development lifecycles. However, they are often slowed down by the growing burden of fixing security vulnerabilities. Ineffective application security processes mean these teams can spend more time firefighting than building, diverting focus from their primary objective: Delivering innovative, high-performance software. Yet, healthy security […]]]> 174365 Microsoft Enlists Endor Labs to Integrate SCA Tool with CNAPP https://devops.com/microsoft-enlists-endor-labs-to-integrate-sca-tool-with-cnapp/ Mon, 25 Nov 2024 13:59:40 +0000 https://devops.com/?p=174306 microsoft, endor, Sysdig NetApp Spotmicrosoft, endor, Sysdig NetApp SpotMicrosoft has tapped Endor Labs to incorporate a software composition analysis (SCA) tool into its cloud-native application protection platform (CNAPP).]]> 174306 Checkmarx Extends DevSecOps Reach to Repository Security and Secrets Discovery https://devops.com/checkmarx-extends-devsecops-reach-to-repository-security-and-secrets-discovery/ Thu, 21 Nov 2024 17:27:33 +0000 https://devops.com/?p=174263 checkmarx, supply chain, supply, risk, supply chain, API management Red Hat supply chaincheckmarx, supply chain, supply, risk, supply chain, API management Red Hat supply chainCheckmarx this week extended the scope of its ability to protect software supply chains with tools that access how secure a repository is and find where application secrets have been shared in a way that is not secure. Ori Bendet, vice president of product management for Checkmarx, said the Repository Health and Secrets Detection tools […]]]> 174263 Four Steps to Balance Agility and Security in DevSecOps https://devops.com/four-steps-to-balance-agility-and-security-in-devsecops/ Wed, 06 Nov 2024 13:17:55 +0000 https://devops.com/?p=174060 agility, agility and security, SDLC, identity, security, development,agility, agility and security, SDLC, identity, security, development,Balancing agility and security in DevSecOps is achievable with the right mix of automation, collaboration and continuous feedback. By embedding security into agile processes, organizations can deliver software that is both fast and secure, meeting the demands of today’s fast-paced tech environment. ]]> 174060 Update to Open Source WhiteRabbitNeo Project Brings Smarter AI to DevSecOps https://devops.com/update-to-open-source-whiterabbitneo-project-brings-smarter-ai-to-devsecops/ Wed, 23 Oct 2024 13:00:08 +0000 https://devops.com/?p=173738 DevSecOps, WhiteRabbitNeo, security, Prime, DevSecOpsDevSecOps, WhiteRabbitNeo, security, Prime, DevSecOpsKindo today revealed that WhiteRabbitNeo, an open-source DevSecOps platform, has been updated to take advantage of improved large language models (LLMs) that generate more accurate outputs when resolving prompts related to offensive cybersecurity, surfacing remediations for potential threats and integrating threat intelligence and vulnerability data.]]> 173738 AI Will Soon Automate DevSecOps Governance https://devops.com/ai-will-soon-automate-devsecops-governance/ Thu, 17 Oct 2024 17:47:59 +0000 https://devops.com/?p=173617 DevSecOps, appsec, ai, open-source, Sonatype, AppSec , devsecops, Traceable supply chainDevSecOps, appsec, ai, open-source, Sonatype, AppSec , devsecops, Traceable supply chainThe role cybersecurity teams play in ensuring applications are secure is about to become a lot more proactive in the age of artificial intelligence (AI).]]> 173617 Prime Security to Apply AI Guardrails to DevSecOps Workflows https://devops.com/prime-security-to-apply-ai-guardrails-to-devsecops-workflows/ Thu, 10 Oct 2024 16:52:30 +0000 https://devops.com/?p=173484 DevSecOps, WhiteRabbitNeo, security, Prime, DevSecOpsDevSecOps, WhiteRabbitNeo, security, Prime, DevSecOpsPrime Security today emerged from stealth to make available a beta version of a platform that leverages artificial intelligence (AI) to ensure the appropriate guardrails are being followed as software is developed.]]> 173484 Legit Security Adds Application Security Rating Scorecards to ASPM Platform https://devops.com/legit-security-adds-application-security-rating-scorecards-to-aspm-platform/ Thu, 03 Oct 2024 15:45:05 +0000 https://devops.com/?p=173280 ASPM, legit , application security, Launchable, CloudBees, application security, microservices testing Your Applications Are the Weakest Security LinkASPM, legit , application security, Launchable, CloudBees, application security, microservices testing Your Applications Are the Weakest Security LinkLegit Security today added an ability to rate the level of software security that has been attained to its application security posture management (ASPM) platform.]]> 173280