DevSecOps
Codenotary Automates SBOM Creation
Codenotary today launched a tool that enables an application to automatically generate a software bill of materials (SBOM) by adding a single line to its source code. Codenotary CEO Moshe Bar said ...
Aqua Security Claims Compliance With Biden’s Executive Order
Aqua Security this week claimed it is the first software supply chain security platform provider to meet the attestation requirements as defined by an executive order issued to federal agencies last year ...
Rust Momentum Intensifies | Elon Says No WFH
In this week’s The Long View: People won’t shut up about Rustlang, and Musk mandates Twitter teams return to the office ...
Standardizing Federal Cybersecurity With DevSecOps
DevSecOps is having a moment in the federal government. With President Biden’s Executive Order on Improving the Nation’s Cybersecurity and federal agencies’ issuance of DevSecOps best practices based on the Enduring Security ...
2023 Application Security Budgets on the Rise
A survey of 500 DevSecOps professionals in the U.S. found nearly three-quarters (73%) of organizations plan to increase investment in application security in 2023. The survey, conducted by Wakefield Research on behalf ...
OpenSSL Fiasco: What can DevOps Learn? | Elon Fires ‘50%’ of Twitter
In this week’s The Long View: The OpenSSL project has egg on its face, and half of Twitter’s staff are for the chop tomorrow ...
Tanium Uses SBOMs to Automate Vulnerability Remediation
Tanium this week added the ability to detect libraries and software packages with known vulnerabilities within a software bill of materials (SBOM) manifest that can then be used to automate remediation of ...
Update to Open Source ZAP Tool Improves DAST Performance
An update to the OWASP Zed Attack Proxy (ZAP) open source dynamic application security testing (DAST) tool made available today improves performance by employing a multi-threaded passive scanner engine. Version 2.12.0 of ...
PlanSecOps: Incorporating Security Strategies in Design
Organizations that don’t adapt and change aren’t likely to survive. The same can be said about DevSecOps, a discipline created to ensure security is baked into the software development process, not an ...
The Scariest Things About SCA
It is a time of ghouls, mischievous spirits and David S. Pumpkins. In the spirit of Halloween, here are the top five scariest limitations of software composition analysis (SCA) tools that are ...
Meta Income Down by Half | Will Apple Make it Worse? | Linux Secure Boot Fix
In this week’s The Long View: Meta’s latest results are very bad, Apple wants its cut of Facebook ads, and Lennart Poettering proposes improving Secure Boot for Linux ...
Sigstore Code Signing Service Becomes Generally Available
A free digital signing service for software created by the Sigstore open source community has become generally available this week via the cloud. Announced at the SigstoreCon event that occurred during the ...

