GrammaTech Announces GitLab Partnership for CodeSonar SAST Product
March 04, 2021

GrammaTech announced a technology partnership with GitLab, the single application for the DevOps lifecycle.

As part of the alliance, the GrammaTech CodeSonar Static Application Security Testing (SAST) product is now integrated with GitLab’s Ultimate DevSecOps platform allowing customers to implement code analysis early and directly within CI/CD pipelines.

Development teams are under constant pressure to meet aggressive deadlines for delivering new software, with rolling releases and agile development practices that are pushing new features and code quickly into production. GrammaTech CodeSonar is designed to shift security left in DevSecOps by detecting and eliminating bugs and vulnerabilities at the earliest stages of the development cycle. The integration of CodeSonar with GitLab enables organizations to develop and release high quality and secure software that is free from harmful defects and exploitable weaknesses which can cause system failures, enable data breaches and increase liability.

“Through this strategic partnership and integration, GrammaTech CodeSonar and its unique static application security testing capabilities are now natively available to development teams from within the GitLab CI/CD pipeline,” said Vince Arneja, Chief Product Officer at GrammaTech. “This enables security to move seamlessly from testing into development workflows, allowing enterprises to transform secure coding and accelerate software delivery.”

The GrammaTech module for GitLab provides native SAST capabilities that scan code for defects within CI/CD pipelines, and eliminates the need for any integration and maintenance by users. It enables customers to assess code continuously, avoiding costly mistakes and rework associated with waiting until the testing phase to scan for security problems.

CodeSonar SAST GitLab Integration is available immediately from GrammaTech and its business partners worldwide.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.