New ThreadFix Release Provides Application Security at DevOps Speed
April 18, 2017

Denim Group announced the release of the latest version of ThreadFix, the company’s application vulnerability resolution platform for developers and security professionals.

ThreadFix 2.5 automates application security in the DevOps Continuous Integration/Continuous Delivery (CI/CD) pipeline, enabling applications to be delivered more rapidly without sacrificing security. The upgrades in this release make it possible for security teams to centrally enforce pre-defined application security policies, and development teams to automatically orchestrate application testing resulting in seamless incorporation of security testing into the CI/CD pipeline.

Businesses and development teams are driven to embrace DevOps so they can be more agile, deploy code more quickly, and provide more value to their customers. To that end, it is incredibly important for DevOps teams to have up-to-the-minute feedback on the status of their development efforts so they know if a build is ready for production. The feedback cycle should include testing quality, performance, and security. By incorporating application security testing into the DevOps CI/CD pipeline, security vulnerabilities are found quickly and reported to developers in the issue and project tracking tools they’re already using, ultimately removing friction from the remediation process and keeping costs down.

“It’s our goal to take the pressure off DevOps teams,” said Dan Cornell, CTO, Denim Group. “Regardless of the timeline to which they are held, ThreadFix allows them to have a clear path towards securing their new releases. No other platform ingests existing application security testing tools that are prevalent in enterprises and makes them accessible to software development teams to ensure that application security is a part of every build.”

ThreadFix 2.5 provides the ability for development teams to take advantage of application security testing tools in their CI/CD pipelines by orchestrating both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools, automatically making pass/fail decisions for builds based on the results of application security testing and creating software defects in defect tracking systems. This allows for development teams to easily access and control application security testing capabilities through existing tools and platforms to run their CI/CD pipelines resulting in vulnerabilities being found earlier in the application security process.

As executives drive enterprises to adopt DevOps to support innovation and keep pace with customer and stakeholder requirements, the need for security to be included in the DevOps process is at an all-time high. ThreadFix 2.5 provides enhanced integrations based on the ongoing feedback from enterprises deploying and extending their ThreadFix installations. These enhanced integrations include HPE Fortify on Demand and HPE Fortify Software Security Center (SSC).

The Latest

October 19, 2017

In light of the recent Equifax breach, Gene Kim and speakers from the upcoming DevOps Enterprise Summit San Francisco (DOES17) dissected the situation and discussed the technical leadership lessons learned while offering their own expert advice for handling crisis situations. The following are more highlights from the discussion ...

October 18, 2017

In light of the recent Equifax breach, Gene Kim and speakers from the upcoming DevOps Enterprise Summit San Francisco (DOES17) dissected the situation and discussed the technical leadership lessons learned while offering their own expert advice for handling crisis situations ...

October 16, 2017

A survey of more than 750 development team leaders in the US and UK, revealed that 68 percent plan to build more apps during the next 12 months. At the same time as reporting increased volumes of development, 91 percent of developers surveyed agree that user expectations for innovation and quality have increased, but app deliveries continue to fail ...

October 12, 2017

Today, organizations must digitally evolve or they risk becoming irrelevant. One area that’s been growing in adoption is a shift to developing and deploying modern applications in the cloud, which requires software and IT architects to rethink how to architect and manage these apps ...

October 10, 2017

Designing and deploying complete software-defined data centers (SDDCs) can be complicated because each implementation requires a broad range of infrastructure to support heavy demands for compute, networking, storage, applications and security ...

October 05, 2017

According to LogiGear's State of Software Testing Survey, almost one-third of the respondents are experiencing classic test automation issues. One problem commonly cited among respondents was that management didn’t fully understand what it takes to have a successful automation program ...

October 04, 2017

Load balancing at the DNS (Domain Name System) level has been around for a few decades now, but it didn't become crucial until recently as technology is moving to the cloud. DNS is the perfect solution for managing cloud systems ...

October 02, 2017

QualiTest recently compiled a data report analyzing software testers globally. The report details the Quality Assurance and Software Testing job market, one of the fastest growing job markets and a bellwether of tech employment due to QA's involved in nearly every conceivable industry ...

September 28, 2017

API use is exploding among developers, as APIs are an essential part of software development for the web, IoT, mobile and AI applications. APIs allow a developer to create programs or apps that can successfully request services or data from other applications or operating system. This connectivity, though powerful, is complex, and that complexity grows with new apps, new hardware such as the new iPhone and Echo, and the creation of new APIs ...

September 26, 2017

Companies are placing a greater value on high performing IT professionals as IT demands continue to escalate, according to Puppet's DevOps Salary Report ...

Share this