The Open Source Security Foundation (OpenSSF) announced an expansion of its free course “Developing Secure Software” (LFD121).
Sonar has expanded its SonarCloud offering with the availability of two new plans, SonarCloud Enterprise and SonarCloud Team.
SonarCloud is the company’s fully managed SaaS solution for improving the quality and security of human-developed and AI-assisted code at scale.
With the new Enterprise and Team plans for SonarCloud, Sonar empowers development teams of all sizes to deliver Clean Code with confidence.
Sonar’s Clean Code solutions help developers catch bugs, quality concerns, and security flaws early in the development process, as code is being created. This allows them to find and resolve issues before they can make it through to production, improving developer productivity, software quality, and business performance.
The new SonarCloud plans ensure developer teams can leverage SonarCloud as their needs grow, to continuously reduce exposure to risk at all levels and sustain the performance of their software, growing business through systematic development and delivery.
“The adoption of AI coding assistants and the push for faster software development have increased code volume and raised reliability concerns. However, most code scanning tools are just adding to the growing list of issues that are potential threats to business, most of which are false positives. Developers need to be empowered to find issues early and be motivated to fix them with the tools they love and have confidence in. Development teams who use SonarCloud are able to pinpoint and remediate as early in the development process as possible,” said Fabrice Bellingard, VP of Product at Sonar.
SonarCloud Enterprise offers organization-wide portfolio management, new authentication and security features, executive reporting functionality, simplified administration, enterprise service-level agreements, and dedicated commercial support for all customers. Additionally, SonarCloud Enterprise is available on AWS Marketplace, ensuring simplified procurement and onboarding.
- Centralizing Controls: Specific features include enterprise hierarchy, portfolio creation, organization-wide configurable settings, project PDF reporting for technology leads and managers, and security standard reports for IT security teams.
- Authentication and Security: Features that support ongoing security assurance include Single Sign-On (SSO), synchronized access management, and more scalable token management.
- Simplified Administration: At onboarding, default settings can be prepared and applied to all projects with organization-wide project configuration. This relieves the tedious and slow task that large enterprises face of configuring a high number of projects, project by project. Automated project creation at scale also supports ease in standing up SonarCloud. It enables the auto-creation of projects in SonarCloud that were initially built in an enterprise DevOps platform. Additionally, enterprise billing means that billing can be done as a single entity while being applied to multiple organizations.
- Flexible plans to meet the needs of all organizations: SonarCloud’s existing Private Repo plan has been replaced by SonarCloud Team and will continue to provide the reliable, SaaS solution that users trust and rely on today. At an affordable price, SonarCloud Team provides all the benefits of the SonarQube Community Edition plus additional features like branch analysis, pull request decoration, and injection flow detection. With the Team plan, developers can scan both public and private projects for actionable insights that enable consistent and efficient Clean Code delivery all in a simple, fast time-to-value SaaS model hosted by Sonar. Teams also have control to define the quality standard they want their codebase to follow.
The Free plan of SonarCloud will continue to be available and will evolve through the year.
Features described in this release will be made available throughout 2024.
Industry News
Redgate announced that its core solutions are listed in Amazon Web Services (AWS) Marketplace.
LambdaTest introduced a suite of new features to its AI-powered Test Manager, designed to simplify and enhance the test management experience for software development and QA teams.
StackHawk launched Oversight to provide security teams with a birds-eye view of their API security program.
DataStax announced the enhancement of its GitHub Copilot extension with its AI Platform-as-a-Service (AI PaaS) solution.
Opsera partnered with Databricks to empower software and DevOps engineers to deliver software faster, safer and smarter through AI/ML model deployments and schema rollback capabilities.
GitHub announced the next evolution of its Copilot-powered developer platform.
Crowdbotics released an extension for GitHub Copilot, available now through the GitHub and Azure Marketplaces.
Copado has integrated Copado AI into its Community to streamline support and accelerate issues resolution.
Mend.io and HeroDevs have forged a new partnership allowing Mend.io to offer HeroDevs support for deprecated packages.
Synechron has acquired Cloobees, a Salesforce implementation partner.
Check Point® Software Technologies Ltd. has been named as one of the World’s Best Employers by Forbes for the fifth year in a row.
Opsera announced its AI Code Assistant Insights.
Gearset released its latest innovation for Salesforce DevOps: Dev Sandbox Syncing.
Treblle announced the release of Treblle 3.0, its AI-enhanced API intelligence platform.