GitLab announced the general availability of GitLab Duo with Amazon Q.
Bridgecrew shifted their security scanning and fixing technology even further left with a new Visual Studio Code (VS Code) extension.
Developers will be notified about infrastructure as code (IaC) misconfigurations and policy violations at the earliest possible moment within the DevOps lifecycle: while they are coding on their local workstation.
"While Bridgecrew's mission is to ensure infrastructure security at every stage of the development lifecycle -- from code and build, through deployment, and into runtime -- the earlier you catch issues, the less headaches you'll have later down the road," said Barak Schoster, CTO and Co-Founder of Bridgecrew. "This is shifting security as early in the lifecycle as possible, directly into the developer's IDE where they spend most of their time."
The new VS Code extension combines hundreds of out-of-the-box policies from Bridgecrew's open-source tool Checkov with in-line fixes enabled by Bridgecrew's APIs. Launched in December 2019, Checkov has already been downloaded over a million times by developers to scan IaC frameworks for misconfigurations ad hoc or as part of automated CI/CD pipelines. But the ability to be notified in real-time while coding -- before that code is committed -- has been one of the most highly requested features to date.
Bridgecrew's VS Code extension supports all of the major infrastructure as code (IaC) frameworks: Terraform, CloudFormation, Kubernetes manifests, Serverless framework, and Azure Resource Manager (ARM). Real-time identification and in-line fixes separate this new offering from existing VS Code extensions, which traditionally need to be prompted to scan code (i.e. not real-time scanning) and do not offer fixes for the identified violations. The VS Code extension will automatically scan for security best practices such as those outlined by the Center of Internet Security (CIS) and against compliance benchmarks such as SOC II, HIPPA, FedRamp, and more.
Palo Alto Networks recently announced their intent to acquire Bridgecrew, stating that "the proposed acquisition will enable Prisma Cloud to provide developers with security assessment and enforcement capabilities throughout the DevOps process." Once the deal has closed, Palo Alto Networks will continue to invest in Bridgecrew's open-source initiatives as part of its ongoing commitment to DevOps security.
Industry News
Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.
Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.
CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.
Bauplan, a Python-first serverless data platform that transforms complex infrastructure processes into a few lines of code over data lakes, announced its launch with $7.5 million in seed funding.
Perforce Software announced the launch of the Kafka Service Bundle, a new offering that provides enterprises with managed open source Apache Kafka at a fraction of the cost of traditional managed providers.
LambdaTest announced the launch of the HyperExecute MCP Server, an enhancement to its AI-native test orchestration platform, HyperExecute.
Cloudflare announced Workers VPC and Workers VPC Private Link, new solutions that enable developers to build secure, global cross-cloud applications on Cloudflare Workers.
Nutrient announced a significant expansion of its cloud-based services, as well as a series of updates to its SDK products, aimed at enhancing the developer experience by allowing developers to build, scale, and innovate with less friction.
Check Point® Software Technologies Ltd.(link is external) announced that its Infinity Platform has been named the top-ranked AI-powered cyber security platform in the 2025 Miercom Assessment.
Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.
The Live API for Gemini models is now in Preview, enabling developers to start building and testing more robust, scalable applications with significantly higher rate limits.
Backslash Security(link is external) announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.
SmartBear launched API Hub for Test, a new capability within the company’s API Hub, powered by Swagger.
Akamai Technologies introduced App & API Protector Hybrid.