Couchbase announced a broad range of enhancements to its Database-as-a-Service Couchbase Capella™.
Only half of CI/CD workflows include application security testing elements despite respondents citing awareness of the importance and advantages of doing so, according to DevSecOps Realities and Opportunities, a survey conducted by 451 Research, commissioned by Synopsys.
DevSecOps is an emerging paradigm in which DevOps teams incorporate application security into their continuous integration and continuous delivery (CI/CD) workflows.
"While some DevOps teams are starting to incorporate application security into their CI/CD workflows, driven by factors such as improved software quality, compliance, and risk avoidance, there is ample room for improvement," said Jay Lyman, Principal Analyst at 451 Research. "In many cases, security testing is not being integrated often or early enough in the process for organizations to fully benefit from reduced risk and rework headaches."
DevOps teams today are working with large-scale infrastructures, releasing software faster, and doing so with significant code changes in each release.
63% of respondents say they expect to deploy software at least four times faster in a DevOps model. Without a clear and informed strategy, this can make establishing and scaling application security testing within these processes complex and difficult.
While organizations cited a lack of automation and consistency, reduced speed, and the noise of false positives as the primary challenges of DevSecOps, the survey showed that the use of automated tools integrated early in the software development life cycle can have a positive impact on both the speed and the overall quality and security of software.
The survey also revealed that software composition analysis (SCA), or the identification of open source software components affected by known vulnerabilities, is the most critical application security element that needs to be incorporated into CI/CD workflows. Interestingly, the survey also showed that nearly 40% of organizations either do not perform SCA or claim not to use any open source components – which may represent a lack of awareness given that a previous Open Source Security and Risk Analysis report by Black Duck Software found that over 95% of applications contain open source.
"DevSecOps presents an opportunity to make application security part of the cultural and technological fabric of modern, high-velocity development and deployment models," said Andreas Kuehlmann, GM of the Synopsys Software Integrity Group. "This study validates that automation, speed, accuracy, and CI/CD integration are critical to making DevSecOps successful."
Industry News
Remote.It release of Docker Network Jumpbox to enable zero trust container access for Remote.It users.
Platformatic launched a suite of new enterprise-grade products that can be self-hosted on-prem, in a private cloud, or on Platformatic’s managed cloud service:
Parasoft announced the release of C/C++test 2023.1 with complete support of MISRA C 2023 and MISRA C 2012 with Amendment 4.
Rezilion announced the release of its new Smart Fix feature in the Rezilion platform, which offers critical guidance so users can understand the most strategic, not just the most recent, upgrade to fix vulnerable components.
Zesty has partnered with skyPurple Cloud, the public cloud operations specialists for enterprises.
With Zesty, skyPurple Cloud's customers have already reduced their average monthly EC2 Linux On-Demand costs by 44% on AWS.
Red Hat announced Red Hat Trusted Software Supply Chain, a solution that enhances resilience to software supply chain vulnerabilities.
Mirantis announced Lens Control Center, to enable large businesses to centrally manage Lens Pro deployments by standardizing configurations, consolidating billing, and enabling control over outbound network connections for greater security.
Red Hat announced new capabilities for Red Hat OpenShift AI.
Pipedrive announced the launch of Developer Hub, a centralized online app development platform for technology partners and developers.
Delinea announced the latest version of Cloud Suite, part of its Server PAM solution, which provides privileged access to and authorization for servers.
Red Hat announced Red Hat Service Interconnect, simplifying application connectivity and security across platforms, clusters and clouds.
Teleport announced Teleport 13, the latest version of its Teleport Access Platform to enhance security and reduce operational overhead for DevOps teams responsible for securing cloud infrastructure.
Kasten by Veeam announced the release of its new Kasten K10 V6.0 Kubernetes data protection platform.
Red Hat announced Red Hat Developer Hub, an enterprise-grade, unified and open portal designed to streamline the development process through a supported and opinionated framework.