DevSecOps
WhiteSource Becomes Mend, Launches Automated Remediation Platform
WhiteSource rechristened itself Mend today and launched a remediation platform that automatically resolves security issues for application developers. Rami Sass, co-founder and CEO of Mend, said now the company is going beyond ...
Survey Surfaces Challenges Ahead on National DevOps Day
A survey published today for National DevOps Day found nearly two-thirds (63%) have seen an increase in the frequency of service incidents that have affected their customers over the course of the ...
Competing Priorities Prevent Devs From Creating Secure Code
The recently released Secure Code Warrior State of Developer-Driven Security Survey revealed that developers continue to wrestle with secure coding practices in a working environment that has long prioritized features and functionality ...
DevSecOps Deluge: Choosing the Right Tools
In the last few years, DevSecOps has become the security process of choice for many forward-thinking enterprises. These organizations have come to understand that fixing bugs in the latter stages of product ...
Managing Hardcoded Secrets to Shrink Your Attack Surface
The practice of hardcoding secrets—such as authentication credentials, passwords, API tokens and SSH Keys—as non-encrypted plain text into source code or scripts has been common in software development for many years. It ...
15 Ways Software Becomes a Cyberthreat
Software is an integral part of private and commercial life; there is no way around it. You need software to do your taxes, book a flight or browse the internet. Software has ...
Progress Expands Scope of Compliance-as-Code Capabilities
Progress this week extended its DevSecOps portfolio—built atop the Chef automation framework it acquired in 2020—to now include the ability to programmatically address compliance mandates. At the same time, Progress has updated ...
How to Secure CI/CD Pipelines With DevSecOps
Many companies are adopting a DevOps approach in their workflows as IT moves toward a more automated and cloud-native world—but for some industries, this migration isn't easy. Many of these companies—in finance, ...
Does GraphQL Introduce New Security Risks?
The GraphQL query language is an excellent tool for increasing the ease of data sharing. The premise is that you request the fields you need in a single bundled request, avoiding multiple ...
OpenSSF Adds Open Source Package Analysis Tool Prototype
The Open Source Security Foundation (OpenSSF) has made available a prototype of a package analysis tool that has already identified more than 200 malicious packages uploaded to PyPI and npm software components ...
Checkmarx Report Highlights Need for AppSec Collaboration
A research report published by Checkmarx finds the same basic malicious software developed using multiple programming languages as cyberattackers industrialize their malware development processes. Checkmarx, a provider of code scanning tools, shared ...
DevSecOps: Realities of Policy Management
Policy management is essential to scale cloud environments and is key to secure DevOps practices. It enables organizations to manage policies put in place that secure the cloud environment, ensure Kubernetes configurations ...

