DevSecOps
Codenotary Launches Cloud Service to Generate SBOMs
Codenotary has launched a Codenotary Cloud platform that can automatically generate a software bill of materials (SBOM) and make it easier to discover what components have been included in an application. Moshe ...
Why Developer-First is the Future of AppSec
DevOps culture and rapid cloud adoption mean developers are shipping code faster than ever and, in many cases, security teams struggle to keep up. To avoid relegating security to afterthought status, organizations ...
App Store Antitrust Bill | GDPR vs. Google Fonts | Wordle Worth $1M+
In this week’s The Long View: The Open App Markets Act polls well among devs, Germany fines a website for using Google Fonts, and the NY Times buys Wordle for an unfeasible ...
Improving Software Security in 2022
The recent Log4j vulnerability showed just how quickly a security bug could disrupt not just an industry, but the entire world. Organizations, especially federal agencies, will always find themselves at some level ...
Securing Your Software Development Pipelines
Earlier this year, it was announced that the attack on IT management software provider SolarWinds had been used to compromise other organizations, including parts of the United States government. There were several ...
Salt Security Adds Support for GraphQL APIs
Salt Security has extended its platform for securing application programming interfaces (APIs) to include support for APIs built using GraphQL. GraphQL is an open source data query and manipulation language for APIs ...
Sysdig Adds Cloud Access Controls to DevSecOps Platform
Sysdig announced today that it is adding a Cloud Infrastructure Entitlements Management (CIEM) capability to its Secure DevOps platform as part of an effort to better enforce least-privilege access within the context ...
Codenotary Uses Immutable Database to Verify Software Artifacts
Codenotary today unfurled a free notarization and verification service for open source artifacts and containers to enable IT organizations to track the provenance of the components that make up their applications. Dennis ...
A Blueprint for Securing Software Development
Software development has changed dramatically in recent years, as technologies like DevOps, application containers, and cloud-native transform how software is built and distributed. Unfortunately, attackers have been paying close attention to these ...
Snyk Extends Tools Portfolio to Drive DevSecOps Adoption
During its online SnykCon 2021 conference this week, Snyk extended Snyk Code, a static application security testing (SAST) tool that already supports the Java, JavaScript and Python programming languages to include support ...
Transform Mobile DevOps into Mobile DevSecOps
Mobile developers are mostly focused on adding new features and functionality to their apps. Security features—such as RASP protection, obfuscation, encryption, jailbreak/root prevention and MiTM prevention—are usually addressed at the end of ...
Zero-Trust Network Access Platforms Slash DevOps Bottlenecks
In a prior article, I indicated why a new remote zero-trust platform is needed to support DevOps teams. Traditional remote access configurations are not well-suited for DevOps given a shifting user population ...

