LaunchDarkly announced the private preview of Warehouse Native Experimentation, its Snowflake Native App, to offer Data Warehouse Native Experimentation.
Lineaje unveiled BOMbots, AI-based automation bots that analyze deep software bill of materials (SBOMs) to deliver optimized recommendations and remediations across the entire supply chain.
Using BOMbots, organizations dramatically reduce software maintenance investments and achieve a better security posture. BOMbots leverage Lineaje AI to create “intelligent recommendations,” enabling developers and security analysts to make better decisions – resulting in software that is more secure and delivered with efficiency. With these recommendations, software producers can reduce effort spent on software maintenance by up to 40% and cut software upgrade costs by the same amount.
The BOMbots generative AI tool acts like a “co-pilot,” enhancing a user’s ability to find, understand, and mitigate specific software security and maintenance issues through a specialized, comprehensive analysis by Lineaje AI. Using an intelligent chatbot feature, integrated with their SBOM, teams can engage via a human-like conversation for a comprehensive resolution of a complex issue. The resolution is adapted to an organization's specific situation and requirement, enabling software maintainers and security professionals to mitigate software issues more efficiently.
BOMbots deliver workflows of discovery, recommendations, and automated remediation through the entirety of the software supply chain built inside the organization and all open-source dependencies.
“Today’s developers often utilize already existing software code for faster development and innovation. At the same time, their security counterparts are challenged keeping up with a higher volume and speed of releases while combatting rapidly evolving threats. As a result, we’re seeing organizations succumb to the financial and reputational damages of software supply chain attacks. The cybersecurity industry needs solutions that quickly identify and remediate flaws in the software supply chain and mitigate risk,” said Melinda Marks, Senior Analyst, Enterprise Strategy Group. “BOMbots help developers and security teams work efficiently to remediate security issues using generative AI technologies to provide accurate recommendations for remediation without disrupting workflows.”
Regardless of company size, BOMbots alleviate compounded pain points associated with software maintenance. Key BOMbots available in this release include:
- Compatibility BOMbot: Fixing vulnerabilities, resolving security issues, and taking advantage of new features frequently means that software components must be upgraded to newer versions — which may or may not be compatible with the other software components. The Compatibility BOMbot evaluates thousands of components in an SBOM and creates a compatibility matrix aligned with an organization's goals to tune the recommendations from “least effort” to “most secure.” This enables organizations to eliminate as much as 25% of effort through the “compatibility dividend.”
- Maintainability BOMbot: Software components, including open-source dependencies, frequently age badly. The Maintainability BOMbot identifies dependencies that are risky and no longer maintained. It remediates by driving developers to fix that issue in the dependency themselves or choose a better alternative.
- Vulnerability BOMbot: 95% of vulnerabilities now come from the software supply chain. Unfortunately, many vulnerability prioritization approaches today focus on security urgency and not executability by developers. The Vulnerability BOMbot considers both executability and security parameters in its prioritizations, separating out all vulnerabilities into fixable by the organization’s developers or by dependency organizations. It then works together with the Compatibility and Maintainability BOMbots to figure out the most optimal recommendation. The Vulnerability BOMbot can distinguish between independent patching and upgrades, as well as implications of major and minor versions. It then automates execution through the software supply chain to save up to 20% in effort.
“Organizations already know that SBOMs are critical tools for software compliance. The next logical step for those who know ‘what’s in their software’ is to use that knowledge to improve it. Lineaje AI is leveraging SBOM data to directly optimize software maintenance and security. Our BOMbots offering will allow organizations to move beyond compliance to optimize their software maintenance. We expect that our BOMbots will help companies reduce software maintenance investments by up to 30% in the short term,” said Javed Hasan, CEO & Co-Founder, Lineaje Inc.
Industry News
SingleStore announced the launch of SingleStore Flow, a no-code solution designed to greatly simplify data migration and Change Data Capture (CDC).
ActiveState launched its Vulnerability Management as a Service (VMaas) offering to help organizations manage open source and accelerate secure software delivery.
Genkit for Node.js is now at version 1.0 and ready for production use.
JFrog signed a strategic collaboration agreement (SCA) with Amazon Web Services (AWS).
mabl launched of two new innovations, mabl Tools for Playwright and mabl GenAI Test Creation, expanding testing capabilities beyond the bounds of traditional QA teams.
Check Point® Software Technologies Ltd.(link is external) announced a strategic partnership with leading cloud security provider Wiz to address the growing challenges enterprises face securing hybrid cloud environments.
Jitterbit announced its latest AI-infused capabilities within the Harmony platform, advancing AI from low-code development to natural language processing (NLP).
Rancher Government Solutions (RGS) and Sequoia Holdings announced a strategic partnership to enhance software supply chain security, classified workload deployments, and Kubernetes management for the Department of Defense (DOD), Intelligence Community (IC), and federal civilian agencies.
Harness and Traceable have entered into a definitive merger agreement, creating an advanced AI-native DevSecOps platform.
Endor Labs announced a partnership with GitHub that makes it easier than ever for application security teams and developers to accurately identify and remediate the most serious security vulnerabilities—all without leaving GitHub.
Are you using OpenTelemetry? Are you planning to use it? Click here to take the OpenTelemetry survey(link is external).
GitHub announced a wave of new features and enhancements to GitHub Copilot to streamline coding tasks based on an organization’s specific ways of working.
Mirantis launched k0rdent, an open-source Distributed Container Management Environment (DCME) that provides a single control point for cloud native applications – on-premises, on public clouds, at the edge – on any infrastructure, anywhere.
Hitachi Vantara announced a new co-engineered solution with Cisco designed for Red Hat OpenShift, a hybrid cloud application platform powered by Kubernetes.