Check Point® Software Technologies Ltd. has been recognized as a leader in The Forrester Wave™: Zero Trust Platform Providers, Q3 2023 report.
Semgrep announced that Semgrep Supply Chain is now free for all to use, up to a 10-contributor limit.
Semgrep Supply Chain scans your dependencies and helps you get rid of the 98% false positives that aren’t reachable within your code (i.e., places that don’t use both a vulnerable dependency and its vulnerable functions). This saves substantial time and was previously exclusively available to paying Team tier customers. All new users now run Supply Chain by default. Existing users need to toggle on Supply Chain in Settings.
Semgrep Code's Team tier features are also available for free for teams of up to 10 monthly contributors. This includes advanced code scanning that looks across file and function boundaries to find vulnerabilities via the Pro Engine and high-confidence Pro rules written by Semgrap's Security Research team.
Additional improvements:
- Semgrep is even faster — set up GitHub.com scanning in a minute, scan on every keystroke in the Semgrep Playground and VS Code.
- Expanded language support for Semgrep Code: Semgrep Pro Engine now supports Go, and Semgrep OSS Engine’s Kotlin support is now generally available. Semgrep also added over 100+ new Pro rules across both languages.
- Private beta of config-less scanning for GitHub.com users to make setting up Semgrep scans faster.
Industry News
Red Hat and Oracle announced the expansion of their alliance to offer customers a greater choice in deploying applications on Oracle Cloud Infrastructure (OCI). As part of the expanded collaboration, Red Hat OpenShift, the industry’s leading hybrid cloud application platform powered by Kubernetes for architecting, building, and deploying cloud-native applications, will be supported and certified to run on OCI.
Harness announced the availability of Gitness™, a freely available, fully open source Git platform that brings a new era of collaboration, speed, security, and intelligence to software development.
Oracle announced new application development capabilities to enable developers to rapidly build and deploy applications on Oracle Cloud Infrastructure (OCI).
Sonar announced zero-configuration, automatic analysis for programming languages C and C++ within SonarCloud.
DataStax announced a new JSON API for Astra DB – the database-as-a-service built on the open source Apache Cassandra® – delivering on one of the most highly requested user features, and providing a seamless experience for Javascript developers building AI applications.
Mirantis launched Lens AppIQ, available directly in Lens Desktop and as (Software as a Service) SaaS.
Buildkite announced the company has entered into a definitive agreement to acquire Packagecloud, a cloud-based software package management platform, in an all stock deal.
CrowdStrike has agreed to acquire Bionic, a provider of Application Security Posture Management (ASPM).
Perforce Software announces BlazeMeter's Test Data Pro, the latest addition to its continuous testing platform.
CloudBees announced a new cloud native DevSecOps platform that places platform engineers and developer experience front and center.
Akuity announced a new open source tool, Kargo, to implement change promotions across many application life cycle stages using GitOps principles.
Check Point® Software Technologies Ltd. announced that it has been recognized on Newsweek’s inaugural list of the World’s Most Trustworthy Companies 2023.
CloudBees announced significant performance and scalability breakthroughs for Jenkins® with new updates to its CloudBees Continuous Integration (CI) software.