Orca Introduces Bitbucket App
April 10, 2025

Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.

The new capability enables security teams to automatically scan Bitbucket repositories for misconfigurations, exposed secrets, and vulnerabilities without disrupting developer workflows, improving the security of application delivery pipelines without compromising speed.

“Code repositories like Bitbucket are critical enablers for development teams,” said Arie Teter, chief product officer, Orca Security. “Relying on popular public code rather than reinventing the wheel for each development lifecycle is crucial for developers who want to move at the speed of business. The trouble is that code repositories are often riddled with vulnerabilities, and that risk must be managed without slowing down DevOps teams. The Orca Bitbucket app provides a necessary layer of security that does not impede the CI/CD pipeline, enabling developers to ship more secure code faster.”

The Orca Bitbucket App requires nothing but a one-time authentication to centrally manage and enforce policies across all existing and future repositories without manual setup. The Code Security dashboard within Orca delivers comprehensive visibility for all repositories across different SCM platforms, giving security teams a complete understanding of all application risks.

Key features of the Orca Bitbucket App include:

- Automated security scans on every merge: Protected branches are continuously scanned, with contextual alerts and actionable insights to help teams quickly identify and remediate security issues.

- Configurable pull request scans: Orca scans every pull request, detecting newly introduced issues and alerting developers in real time. This proactive approach helps prevent problematic code from being merged until all detected issues are resolved.

- Periodic scans for inactive repositories: Even rarely updated repositories are monitored, ensuring that newly discovered vulnerabilities don’t go unnoticed.

With the Orca Bitbucket app, security teams may embed automatic security scanning directly into the development pipeline, enabling faster and more secure application development. Adding Bitbucket to Orca’s existing coverage for other Atlassian tools including Jira, as well as GitHub, GitLab, and Azure DevOps, expands upon the company’s commitment to security the entire software development lifecycle.

Share this

Industry News

April 23, 2025

Kubernetes 1.33 was released today.

Kubernetes 1.33 Release Information

April 23, 2025

Docker announced a major expansion of its AI initiative with the upcoming Docker MCP Catalog and Docker MCP Toolkit.

April 23, 2025

Perforce Software announced the release of its latest platform update for Puppet Enterprise Advanced, designed to streamline DevSecOps practices and fortify enterprise security postures.

April 23, 2025

Azul announced JVM Inventory, a new feature of Azul Intelligence Cloud designed to address the complexity and risk of migrating off Oracle Java.

April 23, 2025

LaunchDarkly announced the acquisition of Highlight, a powerful, open source, full-stack application monitoring platform known for its error monitoring, logging, distributed tracing and session replay capabilities.

April 22, 2025

O’Reilly announced AI Codecon—a groundbreaking virtual conference series dedicated to exploring the rapidly evolving world of AI-assisted software development.

April 22, 2025

Veracode unveiled new capabilities offering proactive risk mitigation and automated security at enterprise scale.

April 22, 2025

Snyk launched Snyk API & Web, delivering a dynamic application security testing (DAST) solution designed to meet the growing demands of modern and increasingly AI-powered software development.

April 21, 2025

Postman announced new releases designed to help organizations build APIs faster, more securely, and with less friction.

April 21, 2025

SnapLogic announced AgentCreator 3.0, an evolution in agentic AI technology that eliminates the complexity of enterprise AI adoption.

April 17, 2025

GitLab announced the general availability of GitLab Duo with Amazon Q.

April 17, 2025

Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.

April 17, 2025

Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.

April 16, 2025

CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.