Checkmarx announced a new generation in software supply chain security with its Secrets Detection and Repository Health solutions to minimize application risk.
The Software Engineering Institute at Carnegie Mellon University announced the release of a tool to give a comprehensive visualization of the complete DevSecOps pipeline.
The tool, called Polar, is an observability framework that provides a comprehensive picture of a software system's deployment platform. Polar unlocks data that is captured by disparate tools within an organization, helping to answer complex questions about performance and security that are crucial for real-time decision-making and agility in the face of threats.
"Today's DevSecOps pipelines are complex, and every environment is different," said Morgan Farrah, assistant technical engagement lead in the SEI Software Solutions Division. "A common problem many DevSecOps users face is figuring out the relationships and integrations among all the disparate and changing components of their systems. Polar brings visibility into these systems by communicating with and building a graph model of any networked data source that is useful for decision making. This means users can make decisions using real-time information from the components of their entire DevSecOps organization."
The number and types of stakeholders that require information about the DevSecOps pipeline can be broad. On a technology level, visibility into the pipeline is difficult because the data needed by different stakeholders is often held in many different systems, with many different means for accessing it, and no obvious way to use the information in one system to help answer questions and solve problems.
The Polar tool dynamically maps the relationships in this complex infrastructure and provides visibility into components that previously seemed unrelated. This kind of visibility can help users diagnose and track down problems when they arise.
"Polar adapts to changing data sources and represents the interconnected data in a central knowledge graph that closely models the way the organization thinks about its own data, unlike many representations created by product vendors," said Joseph Yankel, senior engineer at the SEI. "This means queries return information about the real-time state of the organization's data. The information graphs Polar provides can be used to build automation, monitoring, and alerting; to discover cost centers, reduce duplication, visualize end-to-end tool integration, and manage licensing; and to provide many more insights."
Industry News
SmartBear has appointed Dan Faulkner, the company’s Chief Product Officer, as Chief Executive Officer.
Horizon3.ai announced the release of NodeZero™ Kubernetes Pentesting, a new capability available to all NodeZero users.
Veracode acquired certain assets of Phylum, including its malicious package analysis, detection, and mitigation technology.
AppViewX announced the completion of its acquisition by Haveli Investments.
Check Point® Software Technologies Ltd. has been recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for Email Security Platforms (ESP).
Progress announced its partnership with the American Institute of CPAs (AICPA), the world’s largest member association representing the CPA profession.
Kurrent announced $12 million in funding, its rebrand from Event Store and the official launch of Kurrent Enterprise Edition, now commercially available.
Blitzy announced the launch of the Blitzy Platform, a category-defining agentic platform that accelerates software development for enterprises by autonomously batch building up to 80% of software applications.
Sonata Software launched IntellQA, a Harmoni.AI powered testing automation and acceleration platform designed to transform software delivery for global enterprises.
Sonar signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software.
Kindo formally launched its channel partner program.
Red Hat announced the latest release of Red Hat Enterprise Linux AI (RHEL AI), Red Hat’s foundation model platform for more seamlessly developing, testing and running generative artificial intelligence (gen AI) models for enterprise applications.
Fastly announced the general availability of Fastly AI Accelerator.