Apiiro Introduces Code-to-Runtime
November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

Code-to-Runtime is seamless and agentless, requiring only API-based integration to Source Code Management (SCM) and runtime environments without the need for manual tagging, labeling, or other methods. With deeper insight into software architecture, users can now deliver actionable insights to the right developer, making risk prioritization, remediation, and prevention more efficient.

With autonomous Code-to-Runtime mapping, Apiiro automatically performs a deep code analysis on code repositories to identify all types of code components including APIs, OSS dependencies, code modules, DataModels, and more. In addition, it analyzes container images and identifies similarities with no setup or intervention required. With Code-to-Runtime, customers can now:

- Streamline risk prioritization and remediation: Prioritize risks detected at the development phase with runtime context and remediate risks detected in runtime with enriched code context. Apiiro provides insight into where code components or toxic combinations of risky code components are deployed using agentless, API-based integrations in customer Kubernetes clusters or CSPM vendors to identify internet exposure. This connection enriches runtime risks with code context including the code owner and locations within code where the vulnerability needs to be addressed to enable successful remediation. This provides AppSec engineers and software developers with the deepest insights into software architecture and full exposure paths including related pipelines that build and deploy the code repository or code module.

- Reduce friction between AppSec, GRC, and development teams: AppSec solutions on the market today don’t have a deep enough understanding of software architectures from code-to-runtime that enables developers to effectively deliver software to production. Apiiro’s deep code analysis (DCA) combined with its Risk Graph engine implements guardrail at the design, development, and delivery phases, eliminating time developers are blocked by silo application security tools or other ASPM platforms by 85%.

- Reduce alert fatigue: Correlate and group different versions of the same container image to create a single risk for a vulnerability detected in multiple versions. Apiiro also correlates between the container risk and the code risk found by software composition analysis (SCA) scanners.

- Gain single pane of glass into Artifact inventories: Achieve complete visibility into complex software architecture with a single, risk-based pane of glass view. Apiiro deduplicates Artifact inventories by pulling information from security tools running in continuous integration, registries, and deployed containers. Information is then correlated with deployment insights from Kubernetes clusters and/or CSPMs to deduplicate and enrich with relevant code context.

“Apiiro is committed to enabling autonomous security across the entire software development lifecycle, and true code-to-runtime matching goes beyond containers and cloud environments,” said Moti Gindi, chief product officer at Apiiro. “Our platform understands that not every code component is relevant to what’s running in production and not every runtime component is relevant to the codebase or person responsible for it. Code-to-Runtime delivers the level of precision required to gather meaningful insights and prevent the influx of false positives that plague other solutions on the market. As evidenced by our partnership with Akamai earlier this year, we’re delivering a holistic approach, matching APIs in code to API endpoints in runtime. This not only enhances overall application security, it enables teams to focus on the most critical issues to foster a more secure and efficient development lifecycle.”

Share this

Industry News

November 19, 2024

OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.

November 19, 2024

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.

November 19, 2024

Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.

November 19, 2024

Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.

November 19, 2024

Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.

November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

November 19, 2024

Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.

November 18, 2024

Elastic announced its AI ecosystem to help enterprise developers accelerate building and deploying their Retrieval Augmented Generation (RAG) applications.

Read the full news on APMdigest

November 18, 2024

Red Hat introduced new capabilities and enhancements for Red Hat OpenShift, a hybrid cloud application platform powered by Kubernetes, as well as the technology preview of Red Hat OpenShift Lightspeed.

November 18, 2024

Traefik Labs announced API Sandbox as a Service to streamline and accelerate mock API development, and Traefik Proxy v3.2.

November 18, 2024

Kubiya announced Captain Kubernetes, an AI-powered teammate designed to simplify Kubernetes management with natural language interaction and autonomous, self-healing capabilities.

November 14, 2024

Solo.io is donating its open source API Gateway, Gloo Gateway, to the Cloud Native Computing Foundation (CNCF) to further its mission of building a complete omni-gateway connectivity solution.

November 14, 2024

LaunchDarkly announced a new approach to software delivery—Guarded Releases—that empowers organizations to ship with confidence and manage risk proactively.

November 14, 2024

Diagrid announced details of the upcoming release of Dapr 1.15, a Cloud Native Computing Foundation project maintained by Diagrid, Microsoft, Intel, Alibaba, and others.