Aqua Security and Pivotal Partner on Application Security
October 18, 2018

Aqua Security announced the general availability of Aqua Security for (PCF) as an integrated service for Pivotal Cloud Foundry (PCF).

Pivotal users can now download and install the Aqua Security for PCF service from Pivotal Network, and use it to scan application or container artifacts for vulnerabilities. Aqua Security for PCF empowers Pivotal Cloud Foundry users to apply Aqua Security's best practices early on in the build process to ensure that only code that complies with their organization's security and compliance policies is deployed.

"Aqua Security provides valuable insights into IT security posture with automated security scans, threat detection, remediation, and expedited compliance processes at scale," said Nima Badiey, Head of Technology Ecosystem at Pivotal. "We are excited to make this integrated solution available to all Pivotal customers through the Pivotal Services Marketplace. One of the many advantages of using Pivotal to build containerized, cloud-native applications is that it presents an opportunity to improve application security, and Aqua helps Pivotal customers do that at DevOps speed."

Aqua Security for PCF provides enterprise customers with the following capabilities:

- Automatically scan application or container artifacts for known vulnerabilities, based on an updated feed from multiple resources (e.g., public CVEs, vendor-issued, proprietary vulnerability data streams and malware lists)

- Identify unauthorized application or container artifacts based on pre-configured assurance policies that check for:
Authorization
CVEs and score
Presence of hard-coded secrets
Presence of malware

- Add custom compliance checks to identify security and compliance risks (e.g., PII, PCI, GDPR-related data)

- Developers and Security teams get actionable information on how to mitigate detected vulnerabilities

- Users gain visibility into vulnerabilities in their application or container artifacts directly from CI/CD tools and the Aqua dashboard

The Aqua solution is easy to operate, supports more than 40 languages, including Java, Go, C++, Python, Ruby, NodeJS and others, as well as static binaries, and finds known vulnerabilities, embedded "secrets", and malware. Users can integrate Aqua Security with their existing CI/CD tools for security testing as part of the build, with Active Directory/LDAP for user authentication, and with SIEM/analytics to output audit and alert data. Based on image assurance policies, users can then approve or block application or container artifacts depending on their vulnerability posture, the presence of embedded secrets, malware, and runtime configuration parameters.

Share this

Industry News

January 09, 2025

Checkmarx announced a new generation in software supply chain security with its Secrets Detection and Repository Health solutions to minimize application risk.

January 08, 2025

SmartBear has appointed Dan Faulkner, the company’s Chief Product Officer, as Chief Executive Officer.

January 07, 2025

Horizon3.ai announced the release of NodeZero™ Kubernetes Pentesting, a new capability available to all NodeZero users.

January 06, 2025

GitHub announced GitHub Copilot Free.

January 06, 2025

Veracode acquired certain assets of Phylum, including its malicious package analysis, detection, and mitigation technology.

January 06, 2025

AppViewX announced the completion of its acquisition by Haveli Investments.

December 19, 2024

Check Point® Software Technologies Ltd. has been recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for Email Security Platforms (ESP).

December 19, 2024

Progress announced its partnership with the American Institute of CPAs (AICPA), the world’s largest member association representing the CPA profession.

December 18, 2024

Kurrent announced $12 million in funding, its rebrand from Event Store and the official launch of Kurrent Enterprise Edition, now commercially available.

December 18, 2024

Blitzy announced the launch of the Blitzy Platform, a category-defining agentic platform that accelerates software development for enterprises by autonomously batch building up to 80% of software applications.

December 17, 2024

Sonata Software launched IntellQA, a Harmoni.AI powered testing automation and acceleration platform designed to transform software delivery for global enterprises.

December 17, 2024

Sonar signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software.

December 17, 2024

Kindo formally launched its channel partner program.

December 16, 2024

Red Hat announced the latest release of Red Hat Enterprise Linux AI (RHEL AI), Red Hat’s foundation model platform for more seamlessly developing, testing and running generative artificial intelligence (gen AI) models for enterprise applications.

December 16, 2024

Fastly announced the general availability of Fastly AI Accelerator.