GitGuardian Announces New Software Composition Analysis Module
March 26, 2024

GitGuardian released its Software Composition Analysis (SCA) module.

GitGuardian SCA is designed for use in fast-paced DevSecOps environments. The latest addition to GitGuardian's code security platform equips security and developer teams with a unified vulnerability remediation solution, capitalizing on cross-team collaboration, incident visibility, and context.

It enables security engineers to swiftly identify all applications with unsafe dependencies, automatically prioritize incidents by severity, and prompt developers to fix them. Software engineers are provided with remediation guidance to maintain delivery speed and agility while elevating their security posture.

SCA detailed analytics allow application security teams to monitor their vulnerability exposure and track their remediation performance. GitGuardian empowers them to identify and eliminate bottlenecks for a streamlined development process.

Furthermore, the SCA module evaluates and communicates the legal risks in the software supply chain. This information is crucial to prevent threats to organizations’ intellectual property and ensure compliance with license and security policies.

To adhere to constantly evolving government regulations on software, legal counsel can generate comprehensive SBOM of applications' open-source and third-party components, along with their nested dependencies.

GitGuardian’s constant support of shift-left practices helps reconcile software and security engineer teams without sacrificing execution speed. In its ongoing efforts to reduce organizations' attack surface, GitGuardian extends SCA capabilities to its CLI tool ggshield. It adds layers of verifications at each step of the development process, from local developer environments to continuous integration (CI) pipelines.

Share this

Industry News

July 25, 2024

Backslash Security introduced its Fix Simulation and AI-powered Attack Path Remediation capabilities.

July 25, 2024

Check Point® Software Technologies Ltd. announced the appointment of Nadav Zafrir as Check Point Chief Executive Officer.

July 25, 2024

Sonatype announced that Sonatype SBOM Manager, its Enterprise-Class Software Bill of Materials (SBOM) solution, and its artifact repository manager, Nexus Repository, are now available in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS).

July 24, 2024

Broadcom unveiled the latest updates to VMware Cloud Foundation (VCF), the company’s flagship private cloud platform.

July 24, 2024

CAST launched CAST SBOM Manager, a new freemium product designed for product owners, release managers, and compliance specialists.

July 24, 2024

Zesty announced the launch of its Insights and Automation Platform.

July 23, 2024

Progress announced the availability of Progress® MarkLogic® FastTrack™, a UI toolkit for building data- and search-driven applications to visually explore complex connected data stored in Progress® MarkLogic® platform.

July 23, 2024

Snowflake will host the Llama 3.1 collection of multilingual open source large language models (LLMs) in Snowflake Cortex AI for enterprises to easily harness and build powerful AI applications at scale.

July 23, 2024

Secure Code Warrior announced the availability of SCW Trust Agent – a solution that assesses the specific security competencies of developers for every code commit.

July 23, 2024

GFT launched AI Impact, a new solution that leverages artificial intelligence to eliminate technical debt, increase developer efficiency and automate critical software development processes.

July 23, 2024

Code Metal announced a $13M seed, led by Shield Capital.

July 22, 2024

Atlassian Corporation has achieved Federal Risk and Authorization Management Program (FedRAMP) “In Process” status and is now listed on the FedRAMP marketplace.

July 18, 2024

Mission Cloud announced the launch of Mission Cloud Engagements - DevOps, a platform designed to transform how businesses manage and execute their AWS DevOps projects.

July 18, 2024

Accelario announces the release of its free TDM solution, including database virtualization and data anonymization.