DevSecOps
Okta Offers PASETO as Alternative to JSON Tokens
Okta today launched an open source library for using Platform-Agnostic Security Tokens (PASETO) as an alternative to JSON Web Tokens (JWT) to authenticate end users. Randall Degges, head of evangelism for Okta, ...
Snyk Tool Prioritizes Open Source Vulnerabilities
Snyk today announced it has enhanced the ability of its namesake vulnerability scanning tool by adding the ability to identify which open source vulnerabilities should be fixed first using a scoring tool ...
Balancing UX and Privacy With IoT
As more IoT devices track data to improve customer UX, privacy concerns are becoming more prevalent. How can developers strike a balance? The internet of things, or IoT, is a system that ...
How to Make DevSecOps a Reality
DevSecOps is an increasingly popular term; however, security vulnerabilities in software continue to proliferate. 2019 saw a surge in web application breaches shining a spotlight on the fact that DevSecOps remains elusive ...
RunSafe Allies With JFrog to Secure Applications
RunSafe Security, a provider of Alkemist tools that prevent memory exploits, has partnered with JFrog to create a plug-in for the Artifactory repository manager platform. Alkemist employs a combination of runtime application ...
Traceable Secures Apps Using Distributed Tracing
Traceable this week announced it is making available under an early access program a namesake platform that combines distributed tracing and machine learning algorithms to better secure applications. Fresh of raising $20 ...
How to Source Vulnerability Data for True DevSecOps
Open source comes with code vulnerabilities that must be considered in the DevOps process The war between open source and “only proprietary code” is long over. Open source won the day by ...
How IaC Bridges the Divide Between DevOps, Security
IaC provides a connection between security and DevOps teams in a subtle, non-intrusive manner Companies often choose DevOps as means to provide value and responsiveness through rapid, high-quality service delivery. Instead of ...
ShiftLeft Brings Security Workflows to DevOps Processes
ShiftLeft has updated its NextGen Static Analysis (NG SAST) tool to include workflows that are purpose-built for developers. Company CEO Manish Gupta said the security workflows are designed to make it easier ...
Snyk Report Finds Decline in Open Source Vulnerabilities
Snyk, a provider of tools for discovering and remediating vulnerabilities in open source code, today published a report that finds the number of new vulnerabilities discovered in open source software packages has ...
SaltStack Looks to Automate DevSecOps Processes
SaltStack announced today it has integrated its automation framework with a variety of third-party security platforms to further the adoption of best DevSecOps processes. Mehul Revankar, director of product management for SaltStack, ...
The Secret to Winning at DevOps: Are You Up for the Challenge?
The main idea behind DevOps is to enable companies to keep up with the increased software velocity and advancements in agile culture for a smoother end-to-end software delivery cycle. The main goal ...

