New ThreadFix Release Provides Application Security at DevOps Speed
April 18, 2017

Denim Group announced the release of the latest version of ThreadFix, the company’s application vulnerability resolution platform for developers and security professionals.

ThreadFix 2.5 automates application security in the DevOps Continuous Integration/Continuous Delivery (CI/CD) pipeline, enabling applications to be delivered more rapidly without sacrificing security. The upgrades in this release make it possible for security teams to centrally enforce pre-defined application security policies, and development teams to automatically orchestrate application testing resulting in seamless incorporation of security testing into the CI/CD pipeline.

Businesses and development teams are driven to embrace DevOps so they can be more agile, deploy code more quickly, and provide more value to their customers. To that end, it is incredibly important for DevOps teams to have up-to-the-minute feedback on the status of their development efforts so they know if a build is ready for production. The feedback cycle should include testing quality, performance, and security. By incorporating application security testing into the DevOps CI/CD pipeline, security vulnerabilities are found quickly and reported to developers in the issue and project tracking tools they’re already using, ultimately removing friction from the remediation process and keeping costs down.

“It’s our goal to take the pressure off DevOps teams,” said Dan Cornell, CTO, Denim Group. “Regardless of the timeline to which they are held, ThreadFix allows them to have a clear path towards securing their new releases. No other platform ingests existing application security testing tools that are prevalent in enterprises and makes them accessible to software development teams to ensure that application security is a part of every build.”

ThreadFix 2.5 provides the ability for development teams to take advantage of application security testing tools in their CI/CD pipelines by orchestrating both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools, automatically making pass/fail decisions for builds based on the results of application security testing and creating software defects in defect tracking systems. This allows for development teams to easily access and control application security testing capabilities through existing tools and platforms to run their CI/CD pipelines resulting in vulnerabilities being found earlier in the application security process.

As executives drive enterprises to adopt DevOps to support innovation and keep pace with customer and stakeholder requirements, the need for security to be included in the DevOps process is at an all-time high. ThreadFix 2.5 provides enhanced integrations based on the ongoing feedback from enterprises deploying and extending their ThreadFix installations. These enhanced integrations include HPE Fortify on Demand and HPE Fortify Software Security Center (SSC).

The Latest

April 27, 2017

In a movement that has gained momentum as quickly as DevOps has, it's always good to stop from time to time and evaluate where we are, where we have come from, and where we are going. We asked four industry experts some questions about the progress of ALM and DevOps ...

April 26, 2017

It's easy to ignore downtime. But ignoring downtime is a surefire way to upset your customers and your colleagues. More and more, teams need to think about shipping stellar experiences. Proper incident response is a great place to start ...

April 24, 2017

The expectation of regular software updates – it's what developers are tasked with, and what users expect and demand. Increased functionality, better performance, and fewer bugs – often in a week or less. Automation of critical processes such as QA can help meet the gargantuan task of constant updates, but it can also send your software into a death spiral of user abandonment unless deployed correctly ...

April 20, 2017

One could argue that testing is the most important phase of an IT project. It's also time-consuming and expensive. It's essential to strike a balance between an IT testing program that ensures a quality product and the cost-to-value ratio of your project. But when you're dealing with replatforming projects, how much testing is enough testing? ...

April 18, 2017

Whether through formal methods such as classroom or virtual training, job shadowing, and mentoring; or through informal methods such as team discussions or presentations, teaching needs to be a frequent element of team integration. It is a given that IT and business teams have difficulty understanding each other without a common taxonomy. Even teams within IT often fail to understand each other ...

April 17, 2017

Although DBAs fortunately have the rare ability to bridge the gap between development and operations, they have been detrimentally overlooked in many companies that deploy DevOps practices. A DBA's ability to interrogate code and construct a resilient, well–performing database environment uniquely defines the capabilities needed for DevOps – leaving me perplexed about why DBAs were not one of the first operations team members asked to join the DevOps movement ...

April 12, 2017

DEVOPSdigest asked experts across the industry — including analysts, consultants and vendors — for their opinions on the best way for a development or DevOps team to become more Agile. Part 5, the final installment in this series, provides tips on empowering people ...

April 10, 2017

DEVOPSdigest asked experts across the industry for their opinions on the best way for a development or DevOps team to become more Agile. Part 4 covers DevOps technologies ...

April 07, 2017

DEVOPSdigest asked experts across the industry for their opinions on the best way for a development or DevOps team to become more Agile. Part 3 provides some tips for getting started and gaining feedback ...

April 05, 2017

DEVOPSdigest asked experts across the industry for their opinions on the best way for a development or DevOps team to become more Agile. Part 2 covers processes including automation, continuous delivery and testing ..

Share this