Check Point® Software Technologies Ltd.(link is external) has emerged as a leading player in Attack Surface Management (ASM) with its acquisition of Cyberint, as highlighted in the recent GigaOm Radar report.
Contrast Security announced its partnership with Red Hat to enable OpenShift users to deploy secure, containerized applications by integrating within native continuous integration and continuous delivery (CI/CD) pipelines.
These integrations empower OpenShift users to retain the scalability of the OpenShift Container Platform, while adding automated security testing as a routine part of the software delivery process with no manual configuration or additional overhead costs.
These integrations were a joint effort between Contrast and Red Hat to ensure security is embedded as a core component of the software delivery value stream. Contrast continuously monitors customers' OpenShift applications at runtime to deliver the most actionable results without requiring AppSec teams to waste hundreds of hours validating results and causing delays for developers.
"Unfortunately many organizations lack the means to implement scalable security gates within their CI/CD pipelines which translates to insecure code being shipped across distributed cloud environments. Our partnership with Red Hat OpenShift ensures that these teams can now drive their DevSecOps transformation with automation at scale," said Sanjay Ramnath, VP of Product Management at Contrast Security. "This partnership is another component to Contrast's overall mission of ensuring developers are empowered to embed security within their environments without imposing additional work on them. We want to make security a value-add for everyone."
Contrast and Red Hat OpenShift integrations enable users to benefit from the following capabilities:
- Source-to-Image Deployment: Cloud developers can embed Contrast's Assess and Protect agents into their source code image to ensure continuous vulnerability detection with runtime context and ensure their apps are protected from targeted attacks in production.
- CI/CD Jenkins Pipelines: AppSec teams can trigger automated security tests within native Jenkins pipelines and ensure security policy gates are established to ensure no vulnerabilities are shipped to production.
- OpenShift Pipelines via Tekton: Contrast provides OpenShift users with automated tasks that can be used to create repeatable pipeline templates within the OpenShift Pipeline environment. APIs provided by the Contrast Secure Coding Platform help initiate automated vulnerability scanning at build time and instrument security telemetry within the application prior to deployment.
The Contrast Secure Code Platform is available to users leveraging the OpenShift Platform with support for Java, .NET, and Node.js applications.
Industry News
GitHub announced the general availability of security campaigns with Copilot Autofix to help security and developer teams rapidly reduce security debt across their entire codebase.
DX and Spotify announced a partnership to help engineering organizations achieve higher returns on investment and business impact from their Spotify Portal for Backstage implementation.
Appfire announced its launch of the Appfire Cloud Advantage Alliance.
Salt Security announced API integrations with the CrowdStrike Falcon® platform to enhance and accelerate API discovery, posture governance and threat protection.
Lucid Software has acquired airfocus, an AI-powered product management and roadmapping platform designed to help teams prioritize and build the right products faster.
StackGen has partnered with Google Cloud Platform (GCP) to bring its platform to the Google Cloud Marketplace.
Tricentis announced its spring release of new cloud capabilities for the company’s AI-powered, model-based test automation solution, Tricentis Tosca.
Lucid Software has acquired airfocus, an AI-powered product management and roadmapping platform designed to help teams prioritize and build the right products faster.
AutonomyAI announced its launch from stealth with $4 million in pre-seed funding.
Kong announced the launch of the latest version of Kong AI Gateway, which introduces new features to provide the AI security and governance guardrails needed to make GenAI and Agentic AI production-ready.
Traefik Labs announced significant enhancements to its AI Gateway platform along with new developer tools designed to streamline enterprise AI adoption and API development.
Zencoder released its next-generation AI coding and unit testing agents, designed to accelerate software development for professional engineers.
Windsurf (formerly Codeium) and Netlify announced a new technology partnership that brings seamless, one-click deployment directly into the developer's integrated development environment (IDE.)