DevSecOps
Extending the GitOps Pipeline: DevSecOps and Trusted Application Delivery
The fusion of DevSecOps and trusted application delivery can extend the GitOps pipeline and add business value ...
New Relic Adds App Security Testing Tool to Observability Platform
New Relic made available a public preview of an application security testing tool that will be integrated into its observability platform ...
Shift Left With DAST: Dynamic Testing in the CI/CD Pipeline
By focusing on application security like an attacker would, DAST can discover potential security threats that static testing methods might miss ...
Communicating Common Web App Security Threats to Developers
Shift left involves providing developers with the context they need to prioritize and remediate threats appropriately ...
JFrog Adds Curation Capability for Open Source Software Components
JFrog is adding a curation capability for open source software that will use metadata generated by binaries to identify malicious packages and software components with licensing issues ...
Tabnine Unveils Beta of Generative AI Automated Testing Tool
Tabnine this week made available in beta a tool that enables developers to use natural language to interact with the artificial intelligence (AI) models embedded within its test automation platform. Brandon Jung, ...
Harnessing AI in Continuous Delivery and Deployment
In my recent article Revolutionizing the Nine Pillars of DevOps with AI-Engineered Tools, I explained that the continuous delivery pillar is an approach where code changes are automatically built, tested and prepared ...
HashiCorp Acquires BluBracket to Extend Secrets Management Reach
HashiCorp this week acquired BluBracket to add a set of static secrets discovery tools to its portfolio ...
Bionic Extends Application Security Posture Management Platform
Bionic this week added a pair of tools to its application security posture management (ASPM) platform that make it simpler to triage threats based on severity and attach a risk score. Josh ...
How to Empower DevSecOps in a Complex Multi-Cloud Landscape
Organizations are embracing cloud-based application delivery for speed of delivery and scale. However, the proliferation of multi-cloud systems to access and maximize the cloud’s capabilities is driving complexity in IT environments. Many ...
How to Avoid Risk When Using Multiple Low-Code Platforms
Organizations are still increasing their use of low-code/no-code (LCNC). But this adoption isn't always consolidated around one tool—frequently, multiple low-code/no-code platforms are used under the same roof. In fact, Gartner predicts that ...
The Security Pipeline
Over the last few years, the ability to secure our applications has grown, and deep integration into the DevOps toolchain has, too. There are more tools doing more security checks protecting more ...

