Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.
Sysdig and Docker announced the integration of Sysdig runtime insights into Docker Scout to help developers prioritize risk and move faster.
Docker and Sysdig will help customers reduce software supply chain noise, prioritize the insights that matter, and build leaner container images. Sysdig is the first runtime security integration into Docker Scout.
By leveraging real-time insights from production – such as in-use vulnerabilities, multidomain correlation, and in-use permissions – the Sysdig cloud-native application protection platform (CNAPP) connects the dots and identifies top risks across the software life cycle.
Docker Scout provides developers with actionable insights across the software supply chain via context-aware recommendations that result in improved application reliability and security. With this partnership, built on a shared open source heritage and commitment to cloud-native innovation, Sysdig and Docker add additional layers of runtime security that bring better visibility while empowering development and security teams to target real, imminent risk.
Benefits of Sysdig Runtime Insights Integration with Docker Scout
- Ship more secure images: Developers can compare images during the build phase with those running in production to easily identify risk, eliminate unnecessary packages, and build leaner container images with a smaller attack surface. Integration with the Docker Build and Push GitHub Action provide insight directly within GitHub to avoid committing risky images.
- Avoid shift-left security gaps: Shift-left security empowers teams to make better-informed decisions earlier in the development process. With Docker and Sysdig, it is possible to correlate image analysis with runtime context to generate actionable insights for securing the software supply chain.
- Accelerate cloud-native application delivery: Software validation processes are faster when informed by Sysdig runtime insights. By quickly identifying imminent risks that require immediate remediation, developers can focus on innovation and deliver cloud-native applications faster.
- Reduce monitoring noise: Joint customers can reduce monitoring noise by up to 95%, separating which vulnerabilities are in use and which are not. This helps security teams focus on what is most important and saves time for developers.
“Organizations need to strengthen security across the entire software life cycle. With Docker Scout, Docker is giving developers the power to build more secure images from the start. Incorporating Sysdig runtime insights means that users can save time by focusing on the real risks exposed in production. Our partnership will help teams to both shift left and shield right to protect against breaches without slowing innovation,” said Bryan Smoltz, Vice President of Technology Alliances at Sysdig.
“Docker Scout proactively provides actionable insights across the secure software supply chain,” said Julien Faure, General Manager for Software Supply Chain at Docker. “With the Sysdig integration, we’re able to cut through the noise using runtime context. Knowing which packages are in use allows developers to prioritize what matters and deliver secure software faster.”
Industry News
Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).
Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.
Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.
BrowserStack and Bitrise announced a strategic partnership to revolutionize mobile app quality assurance.
Mendix, a Siemens business, announced the general availability of Mendix 10.18.
Red Hat announced the general availability of Red Hat OpenShift Virtualization Engine, a new edition of Red Hat OpenShift that provides a dedicated way for organizations to access the proven virtualization functionality already available within Red Hat OpenShift.
Contrast Security announced the release of Application Vulnerability Monitoring (AVM), a new capability of Application Detection and Response (ADR).
Red Hat announced the general availability of Red Hat Connectivity Link, a hybrid multicloud application connectivity solution that provides a modern approach to connecting disparate applications and infrastructure.
Appfire announced 7pace Timetracker for Jira is live in the Atlassian Marketplace.
SmartBear announced the availability of SmartBear API Hub featuring HaloAI, an advanced AI-driven capability being introduced across SmartBear's product portfolio, and SmartBear Insight Hub.
Azul announced that the integrated risk management practices for its OpenJDK solutions fully support the stability, resilience and integrity requirements in meeting the European Union’s Digital Operational Resilience Act (DORA) provisions.
OpsVerse announced a significantly enhanced DevOps copilot, Aiden 2.0.