StackHawk Releases GitHub Insights
October 31, 2023

StackHawk announced the release of a new code-based API discovery capability, GitHub Insights.

StackHawk's latest capability offers security teams continuous discovery and visibility of their organization's attack surface, allowing them to identify gaps in coverage, align security testing with the rapid pace of software development, and work more closely with the engineers writing the code. By seamlessly integrating with GitHub repositories, this new feature eliminates blind spots and fosters efficient collaboration between security and engineering teams.

StackHawk's GitHub Insights offers:

- Code-based API discovery: Everything a modern organization releases is documented in code, but traditional discovery tools have to rely on web traffic to identify API routes. StackHawk's GitHub Insights discovers APIs at the source code level allowing security teams to identify their entire API inventory before they're released to production.

- Continuous visibility: StackHawk's GitHub Insights tests the API layer and maps the findings back to the source code to provide comprehensive insights into what's being developed, by whom, and how often it's being tested to ensure that security coverage aligns with the rapid pace of software development, providing organizations with full visibility into their attack surfaces as well as API security posture.

- Bridging the gap between developers and security experts: StackHawk's GitHub Insights promotes collaboration between security and developer teams by connecting testable APIs to their corresponding code bases and teams. This ensures that security teams can quickly identify the person responsible for addressing issues when they arise and who to collaborate with when testing new APIs.

"Code is the source of truth for applications, APIs, infrastructure, and policies in today's new development era. But, security teams struggle with limited visibility into what's happening in the code base and how it impacts them," said Scott Gerlach, CSO and Co-Founder of StackHawk. "StackHawk's GitHub Insights helps security practitioners map the applications and APIs they are testing back to code, so they can answer important questions about where a certain API lives, what team it belongs to, who's responsible for fixing an issue, and how often an asset has been tested."

StackHawk's modernized DAST approach with an emphasis on shifting security left has redesigned the way organizations develop and test applications today. An essential next step to helping security teams shift left, is understanding what APIs they have, where they live, and who they belong to. Code-based discovery with StackHawk's GitHub Insights bridges that gap between security and engineering teams, fostering stronger collaboration and more informed decision making.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.