Kubernetes 1.33 was released today.
Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.
The new capability enables security teams to automatically scan Bitbucket repositories for misconfigurations, exposed secrets, and vulnerabilities without disrupting developer workflows, improving the security of application delivery pipelines without compromising speed.
“Code repositories like Bitbucket are critical enablers for development teams,” said Arie Teter, chief product officer, Orca Security. “Relying on popular public code rather than reinventing the wheel for each development lifecycle is crucial for developers who want to move at the speed of business. The trouble is that code repositories are often riddled with vulnerabilities, and that risk must be managed without slowing down DevOps teams. The Orca Bitbucket app provides a necessary layer of security that does not impede the CI/CD pipeline, enabling developers to ship more secure code faster.”
The Orca Bitbucket App requires nothing but a one-time authentication to centrally manage and enforce policies across all existing and future repositories without manual setup. The Code Security dashboard within Orca delivers comprehensive visibility for all repositories across different SCM platforms, giving security teams a complete understanding of all application risks.
Key features of the Orca Bitbucket App include:
- Automated security scans on every merge: Protected branches are continuously scanned, with contextual alerts and actionable insights to help teams quickly identify and remediate security issues.
- Configurable pull request scans: Orca scans every pull request, detecting newly introduced issues and alerting developers in real time. This proactive approach helps prevent problematic code from being merged until all detected issues are resolved.
- Periodic scans for inactive repositories: Even rarely updated repositories are monitored, ensuring that newly discovered vulnerabilities don’t go unnoticed.
With the Orca Bitbucket app, security teams may embed automatic security scanning directly into the development pipeline, enabling faster and more secure application development. Adding Bitbucket to Orca’s existing coverage for other Atlassian tools including Jira, as well as GitHub, GitLab, and Azure DevOps, expands upon the company’s commitment to security the entire software development lifecycle.
Industry News
Docker announced a major expansion of its AI initiative with the upcoming Docker MCP Catalog and Docker MCP Toolkit.
Perforce Software announced the release of its latest platform update for Puppet Enterprise Advanced, designed to streamline DevSecOps practices and fortify enterprise security postures.
Azul announced JVM Inventory, a new feature of Azul Intelligence Cloud designed to address the complexity and risk of migrating off Oracle Java.
LaunchDarkly announced the acquisition of Highlight, a powerful, open source, full-stack application monitoring platform known for its error monitoring, logging, distributed tracing and session replay capabilities.
O’Reilly announced AI Codecon—a groundbreaking virtual conference series dedicated to exploring the rapidly evolving world of AI-assisted software development.
Veracode unveiled new capabilities offering proactive risk mitigation and automated security at enterprise scale.
Snyk launched Snyk API & Web, delivering a dynamic application security testing (DAST) solution designed to meet the growing demands of modern and increasingly AI-powered software development.
Check Point® Software Technologies Ltd. announced that it has ranked as a Leader and the only Outperformer for its Check Point Quantum Security Solutions in GigaOm’s latest Radar for Enterprise Firewall report.
Postman announced new releases designed to help organizations build APIs faster, more securely, and with less friction.
SnapLogic announced AgentCreator 3.0, an evolution in agentic AI technology that eliminates the complexity of enterprise AI adoption.
GitLab announced the general availability of GitLab Duo with Amazon Q.
Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.
Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.
CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.