Checkmarx announced a new generation in software supply chain security with its Secrets Detection and Repository Health solutions to minimize application risk.
Black Duck announced a collaboration with Atlassian to manage open source security, compliance, and quality risks, while ensuring DevOps teams maintain speed and agility.
The goal is to provide development teams with solution integrations that enhance their ability to maintain velocity and security as they build software using open source components.
“Modern applications are built with open source,” said Jukka Alanen, VP of Business Development and Corporate Strategy. “Black Duck is working with Atlassian to enable software teams to manage and secure their use of open source as part of their existing DevOps and agile processes.”
Black Duck has released two Atlassian integrations to automate the management and security of open source and both are available through the Atlassian Marketplace.
Black Duck’s Atlassian JIRA Software integration allows teams to trigger and manage developer workflows based on open source use and security policies defined in Black Duck Hub. The integration also alerts JIRA Software users when new open source vulnerabilities are identified by Hub. Black Duck’s Atlassian Bamboo CI integration enables teams to automate discovery of open source in their code via Bamboo build processes, helping teams efficiently track and automate open source use as part of their continuous delivery pipeline. This will also help enforce policies to prevent release of applications with unsafe or non-compliant open source.
“Software teams nowadays rely heavily on open source components,” said Bryant Lee, Head of Partnerships and Integration, Atlassian. “The Black Duck Hub add-ons for Bamboo and JIRA provide visibility and control for software teams to use open source with trust and confidence.”
The Atlassian collaboration follows Black Duck’s recent announcement that it is integrating Hub with Microsoft Visual Studio Team Services (TS) and Team Foundation Server (TFS). Both integrations are part of a broader Black Duck commitment to simplify and integrate open source management with the tools and platforms that development and DevOps teams use to automate software development and delivery.
Industry News
SmartBear has appointed Dan Faulkner, the company’s Chief Product Officer, as Chief Executive Officer.
Horizon3.ai announced the release of NodeZero™ Kubernetes Pentesting, a new capability available to all NodeZero users.
Veracode acquired certain assets of Phylum, including its malicious package analysis, detection, and mitigation technology.
AppViewX announced the completion of its acquisition by Haveli Investments.
Check Point® Software Technologies Ltd. has been recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for Email Security Platforms (ESP).
Progress announced its partnership with the American Institute of CPAs (AICPA), the world’s largest member association representing the CPA profession.
Kurrent announced $12 million in funding, its rebrand from Event Store and the official launch of Kurrent Enterprise Edition, now commercially available.
Blitzy announced the launch of the Blitzy Platform, a category-defining agentic platform that accelerates software development for enterprises by autonomously batch building up to 80% of software applications.
Sonata Software launched IntellQA, a Harmoni.AI powered testing automation and acceleration platform designed to transform software delivery for global enterprises.
Sonar signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software.
Kindo formally launched its channel partner program.
Red Hat announced the latest release of Red Hat Enterprise Linux AI (RHEL AI), Red Hat’s foundation model platform for more seamlessly developing, testing and running generative artificial intelligence (gen AI) models for enterprise applications.
Fastly announced the general availability of Fastly AI Accelerator.