Progress announced new powerful capabilities and enhancements in the latest release of Progress® Sitefinity®.
GitLab completed integration of Peach Tech, a security software firm specializing in protocol fuzz testing and dynamic application security testing (DAST) API testing, and Fuzzit, a continuous fuzz testing solution providing coverage-guided testing.
Both acquired in June of this year, the full integration of Peach Tech and Fuzzit into GitLab provides users with capabilities such as continuous fuzzing, coverage guided fuzz testing, and web API fuzz testing, with results provided directly to the developer while they are still iterating on their code. Traditionally, fuzzing can be difficult and hard to get results from. By bringing Peach Tech and Fuzzit into GitLab, developers and security teams alike can easily integrate fuzz testing into their workflows to take advantage of its powerful benefits in a meaningful and actionable way.
“No longer can security be viewed as a separate step outside of DevOps processes,” said David DeSanto, Director, Product for the Secure and Protect stages at GitLab. “With the completed integration of these fuzzing technologies, GitLab is making it easier for development and security teams to incorporate both coverage-guided and API fuzz testing techniques much earlier in the software development lifecycle. Developers can employ DevSecOps best practices with ease as well as understand what security vulnerabilities are being created at code commit. This enables close collaboration with their security counterparts to reduce their organization’s overall security risk.”
“A common paint point for security teams is how to integrate automated security testing into the DevOps CI pipeline, ensuring that project teams follow a prescribed set of testing and that security policies are adhered to,” said Cindy Blake, GitLab. “GitLab’s Ultimate tier and Gold tier simplify this effort. Templates can be set up and applied to projects in a consistent manner with exceptions documented.”
With completed implementation of Peach Tech and Fuzzit technologies, GitLab Secure customers have an even more comprehensive and fully-integrated security solution, from Auto DevOps deployment of security testing to vulnerability management and remediation. Fuzzing and all other GitLab scans (DAST, SAST, Dependency scanning, Container scanning, Secrets Detection, and License Compliance) are available within the CI pipeline out-of-the-box, requiring no complicated APIs and no Plug-ins. This fully integrated approach allows GitLab to innovate further with the acquired fuzzing IP, with plans to add replay capabilities to DAST to easily recreate how the vulnerability occurs and to correlate fuzz test findings to improve the fidelity of GitLab’s already leading SAST capabilities.
Fuzz testing specific future plans include advanced configuration options for users who want to customize their fuzz tests and expanding fuzz testing to address additional use cases, beyond only web apps and APIs.
Industry News
Red Hat announced the general availability of Red Hat Enterprise Linux 9.5, the latest version of the enterprise Linux platform.
Securiti announced a new solution - Security for AI Copilots in SaaS apps.
Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:
Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.
Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.
OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.
Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.
Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.
Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.
Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.
Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.
Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.
MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.