News

Sonar Combines SAST and SCA Tools in Single Offer
Sonar today revealed it will at the end of May add an offering that combines its Static Application Security Testing (SAST) tool with the software composition analysis (SCA) tools it gained with ...

Analysis of GitHub Repositories Surfaces Nearly 23M Secrets
An analysis of public GitHub repositories published today finds 22.8 million hardcoded secrets, representing a 25% increase since a similar study was done a year ago ...

Synopsys Accelerates Software-Defined Product Development with Virtualizer Native Execution on Arm
Synopsys' new Virtualizer Native Execution on Arm hardware significantly speeds up virtual prototyping for automotive, HPC and IoT development workflows ...

GitHub’s Enhanced Pull Request Merge Experience: Streamlining the DevOps Workflow
GitHub enhances the pull request experience with logical check grouping, improved rule enforcement and better accessibility — making DevOps workflows more efficient and intuitive ...

Survey Surfaces Lack of DevOps Visibility into Consumption of Cloud Infrastructure
A survey of engineering leaders and developers from the U.S. and United Kingdom (UK) conducted by Harness finds less than half have access to real-time insights into idle cloud resources (43%), unused ...

DeepSource Open Sources Globstar Alternative to Semgrep to Analyze Code
DeepSource has made available an open source static code analysis tool, dubbed Globstar, that DevSecOps teams can employ to embed code checkers in their pipelines ...

Bad Actor Targets Linux, macOS Developers with Typosquatted Go Packages
The attacker published at least seven malicious packages on the Go Module Mirror that, if installed, will deliver a backdoor ...

Survey Pinpoints Inhibitors of Java Developer Productivity
A survey of 731 developers, team leads, managers and executives who work with Java pinpoints inhibitors of Java developer productivity ...

Dynatrace Acquires Metis: Revolutionizing Database Observability with AI
Dynatrace's acquisition of Metis brings AI-powered database observability to DevOps teams, enhancing troubleshooting and optimization for developers and SREs ...

Moderne Adds AI Agent to Simplify Application Modernization Initiatives
Moderne today added an artificial intelligence (AI) agent to its platform for refactoring codebases residing in multiple repositories ...

Go Compile-Time Instrumentation Gets a Major Boost: Alibaba, Datadog, and Quesma Join Forces
Three major tech players, Alibaba, Datadog and Quesma are pooling their expertise to tackle one of the most persistent challenges in the Go ecosystem: Streamlining instrumentation for telemetry collection ...

HashiCorp Focuses on Integration Following IBM Acquisition
Now that IBM has completed the acquisition of HashiCorp the focus will now shift toward integrating the various DevOps tools, frameworks and platforms the combined companies provide to securely automate the development ...