Progress announced new powerful capabilities and enhancements in the latest release of Progress® Sitefinity®.
WhiteSource released an Azure DevOps repository integration, allowing Azure DevOps users to detect all open source components and automatically enforce security policies directly from their repository.
Users can now receive alerts on vulnerabilities along with detailed remediation information, including suggested fixes and prioritization advice, all in the comfort of their native environment, free from the burden of learning a new user interface (UI).
As the time-to-market for applications becomes shorter each year, software development teams are challenged with accelerating their processes without compromising on security. Many Software Composition Analysis (SCA) vendors scan for vulnerabilities in the repository, but only provide results exclusively in their own UI, which slows the development process down. The WhiteSource for Azure Repos integration automatically scans open source code for security vulnerabilities or license violations on every merge request, before the code is merged. If a merge request introduces a new error, the developer is given immediate feedback to resolve any newly introduced vulnerabilities. Positive feedback is given when a pull request resolves vulnerabilities. This differential view between feature branches and mainline branches prevents interruptions to workflows. In addition to WhiteSource's existing integrations with all major code repositories, including GitHub, GitHub Packages, JFrog, Bitbucket, and GitLab, the new WhiteSource for Azure Repos integration allows users to generate inventory, security, and compliance reports.
With the WhiteSource for Azure Repos cloud-based integration, users can:
- View automated remediation suggestions — WhiteSource Enterprise automatically generates pull requests in the repository to update vulnerable open source components to the lowest non-vulnerable version.
- Enforce policies – policies are automatically enforced in the repository for each merge request. The status and results of each scan appear on the Commits page.
- Merge with confidence – WhiteSource's "Merge Confidence" feature uses crowdsourced data to show how likely an open source component can be updated without breaking the build. Merge Confidence includes data on upgrade age, adoption, and compatibility to create a confidence score.
- Scan for IaC misconfigurations – Protect production environments and provide security for the cloud, containers, and Kubernetes directly from Azure Repos.
"Scanning for vulnerabilities within the repository is the 'furthest left' organizations can shift their security efforts while still enforcing policies and requiring all developers to scan their code," said Ori Bach, EVP of Product at WhiteSource. "The cost of remediating vulnerabilities is higher the further you progress into your software development life cycle. With the WhiteSource for Azure Repos integration, developers can receive feedback on their code when it is fresh in their minds, making it easier to remediate vulnerabilities while helping organizations ultimately save time and money."
Industry News
Red Hat announced the general availability of Red Hat Enterprise Linux 9.5, the latest version of the enterprise Linux platform.
Securiti announced a new solution - Security for AI Copilots in SaaS apps.
Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.
The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:
Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.
Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.
OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.
Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.
Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.
Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.
Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.
Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.
Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.
MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.