StackHawk Releases Dynamic Application and API Security Testing Solution for GitHub Advanced Security
August 16, 2021

StackHawk announced an integration of Dynamic Application and API Security Testing into GitHub Code Scanning.

Engineering teams can now leverage StackHawk to test their running applications and APIs for the same vulnerabilities an attacker would exploit, with results available directly in GitHub.

GitHub Code Scanning, part of it's Advanced Security offering, is a vulnerability detection and reporting offering that brings application security into developer's existing toolset. StackHawk is a natively accessible Dynamic Application Security Testing (DAST) and API security testing offering available in Code Scanning. StackHawk can be leveraged alongside GitHub-native security products, such as CodeQL for static analysis (SAST) and Dependabot for software composition analysis (SCA), or other third-party SAST and SCA offerings. Instrumenting these tools together creates a comprehensive application security testing suite within the tooling developers use every day.

DAST has long been a leading method of testing for potential vulnerabilities. By executing security tests against the running application and services, this form of testing surfaces exploitable vulnerabilities in the same way an attacker or security researcher would uncover them. With the advent of DevOps, however, DAST tools have not kept pace with the speed of modern software delivery. StackHawk has revolutionized DAST, bringing this proven security testing approach to CI/CD automation and developer workflows.

With StackHawk integrated into GitHub Code Scanning, engineering teams can now automate testing of REST, SOAP, and GraphQL APIs before releasing to production and see findings within their GitHub repositories.

"GitHub is the central tool for developers and engineering teams," says Joni Klippert, StackHawk's Founder & CEO. "We built StackHawk to bring application and API security testing into the hands of developers. Our integration with GitHub Advanced Security simply furthers this mission, making it easier for teams to efficiently deliver secure applications."

Share this

Industry News

February 13, 2025

LaunchDarkly announced the private preview of Warehouse Native Experimentation, its Snowflake Native App, to offer Data Warehouse Native Experimentation.

February 13, 2025

SingleStore announced the launch of SingleStore Flow, a no-code solution designed to greatly simplify data migration and Change Data Capture (CDC).

February 13, 2025

ActiveState launched its Vulnerability Management as a Service (VMaas) offering to help organizations manage open source and accelerate secure software delivery.

February 12, 2025

Genkit for Node.js is now at version 1.0 and ready for production use.

February 12, 2025

JFrog signed a strategic collaboration agreement (SCA) with Amazon Web Services (AWS).

February 12, 2025

mabl launched of two new innovations, mabl Tools for Playwright and mabl GenAI Test Creation, expanding testing capabilities beyond the bounds of traditional QA teams.

February 11, 2025

Check Point® Software Technologies Ltd. announced a strategic partnership with leading cloud security provider Wiz to address the growing challenges enterprises face securing hybrid cloud environments.

February 11, 2025

Jitterbit announced its latest AI-infused capabilities within the Harmony platform, advancing AI from low-code development to natural language processing (NLP).

February 11, 2025

Rancher Government Solutions (RGS) and Sequoia Holdings announced a strategic partnership to enhance software supply chain security, classified workload deployments, and Kubernetes management for the Department of Defense (DOD), Intelligence Community (IC), and federal civilian agencies.

February 10, 2025

Harness and Traceable have entered into a definitive merger agreement, creating an advanced AI-native DevSecOps platform.

February 10, 2025

Endor Labs announced a partnership with GitHub that makes it easier than ever for application security teams and developers to accurately identify and remediate the most serious security vulnerabilities—all without leaving GitHub.

February 07, 2025

Are you using OpenTelemetry? Are you planning to use it? Click here to take the OpenTelemetry survey.

February 06, 2025

GitHub announced a wave of new features and enhancements to GitHub Copilot to streamline coding tasks based on an organization’s specific ways of working.

February 06, 2025

Mirantis launched k0rdent, an open-source Distributed Container Management Environment (DCME) that provides a single control point for cloud native applications – on-premises, on public clouds, at the edge – on any infrastructure, anywhere.

February 06, 2025

Hitachi Vantara announced a new co-engineered solution with Cisco designed for Red Hat OpenShift, a hybrid cloud application platform powered by Kubernetes.