Synopsys Announces Polaris Software Integrity Platform
February 26, 2019

Synopsys introduce the new Polaris Software Integrity Platform, which brings the power of Synopsys Software Integrity products and services together into an integrated solution that enables security and development teams to build secure, high-quality software faster.

Synopsys' Polaris Software Integrity Platform is a cloud-based platform that simplifies and enables comprehensive application security from developer to deployment through the combination of the Synopsys Code Sight IDE plugin and a central analysis server, which share the same powerful analysis engines; a broad set of integrations with popular development and operations tools; and reports, dashboards, and APIs that provide a consolidated view of application security risks. With the Polaris Software Integrity Platform, teams can detect and remediate vulnerabilities earlier in software development, integrate and automate comprehensive security analysis throughout the software development lifecycle (SDLC), and manage application security risks holistically across their application portfolio.

"To effectively secure their applications against increasingly sophisticated attacks, organizations need to employ a combination of security testing techniques at multiple points within the SDLC," said Andreas Kuehlmann, GM of the Synopsys Software Integrity Group. "But, to maintain the velocity required to be competitive, they also need application security solutions that can match the accelerating pace of software development, can scale, and can integrate seamlessly with their existing development infrastructure. Over the past several years, we have developed a portfolio of differentiated products and services that address the gamut of security testing needs in the market, and with the Polaris Software Integrity Platform we're delivering on our vision to drive synergy and efficiency across these solutions."

The benefits of the Polaris Software Integrity platform include:

- Early Risk Discovery and Mitigation – The platform helps developers remediate security vulnerabilities early in development, when it is most efficient and cost-effective. The new Code Sight IDE plugin, a key component of the Polaris Software Integrity Platform, extends the power of Synopsys' solutions to the developers' native work environment, enabling them to easily find and fix security vulnerabilities in their code as they write. Initially available for IntelliJ, Visual Studio, and Eclipse, the Code Sight plugin combines the same powerful analysis engines as the platform's central server with fast incremental analysis, ensuring thorough and consistent results without hindering productivity. Code Sight also provides context-sensitive eLearning modules that help developers fix issues quickly and train them to write more secure code going forward.

- Shift Left from Detection to Prevention – the Polaris Software Integrity Platform is the only solution to use the same powerful analysis engines both on a central server as part of the CI/CD pipeline and on the developer desktop for fast, incremental scanning. It enables developers to address vulnerabilities while they are coding and therefore produce a more secure codebase prior to checking it into their repository. This dual workflow significantly increases developer productivity, while the central analysis catches any remaining defects before they can make it to production.

- Simple and Flexible Operation – The cloud-based central server of the Polaris Software Integrity Platform provides the flexibility to manage deployments, initiate security scans, analyze results, and coordinate remediation activities using multiple Synopsys analysis engines, such as Coverity and Black Duck, through an intuitive web-based management user interface. The platform also gives teams the flexibility to integrate and automate application security analysis across the SDLC using their existing development and DevOps tools, including Jenkins, Jira, Slack, Red Hat OpenShift, and Kubernetes.

- Consolidated Risk Reporting – The Polaris Software Integrity Platform helps security teams view application security risk holistically with consolidated reports and interactive dashboards that combine information from multiple security analysis engines, across their entire application portfolio, with results over time. In addition, the Polaris Software Integrity Platform APIs make it easy for teams to integrate Synopsys security testing results into third-party security and risk reporting solutions.

Share this

Industry News

November 14, 2019

Raytheon Company is collaborating with Red Hat to develop a new, security-focused software development solution, known as DevSecOps, for enterprise environments.

November 14, 2019

Fugue has open sourced the Fugue Rego Toolkit (Fregot) to enhance the experience working with the Rego policy language.

November 14, 2019

Sysdig announced Sysdig Secure 3.0 to provide enterprises with threat prevention at runtime using Kubernetes-native Pod Security Policies (PSP).

November 13, 2019

Testim introduced the Testim Development Kit, a new way for developers to quickly create resilient tests directly in code.

November 13, 2019

Rollbar announced an error monitoring solution for Salesforce’s Apex platform.

November 13, 2019

StackRox announced version 3.0 of the StackRox Kubernetes Security Platform.

November 12, 2019

VMware announced rapid advancement of VMware Tanzu, a new portfolio of products and services designed to transform the way enterprises build, run and manage software on Kubernetes.

November 12, 2019

SmartBear released ReadyAPI 3.0. This latest release addresses the increasing requirement for organizations to consistently deliver high-quality APIs in order to meet accelerated business demands within compressed release cycles.

November 12, 2019

Aqua Security announced its expansion into cloud security posture management (CSPM) with its acquisition of CloudSploit.

November 07, 2019

To help developers increase the speed and quality of their SQL coding, enhance efficiency, and take advantage of the latest improvements in SQL Server, Redgate has released a major upgrade for its most popular tool, SQL Prompt.

November 07, 2019

CloudBees announced a partnership with Atos and VMware surrounding a solution to help customers adopt DevOps best practices at scale on Atos’ recently announced Atos Digital Hybrid Cloud (DHC) powered by VMware Tanzu and CloudBees cloud native continuous integration/continuous delivery (CI/CD) enterprise solution.

November 07, 2019

Fugue announced the release of the Fugue Best Practices Framework to help cloud engineering and security teams identify and remediate dangerous cloud resource misconfigurations that aren’t addressed by common compliance frameworks.

November 06, 2019

Red Hat and the Quarkus community announced Quarkus 1.0.

November 06, 2019

Copado announced its Winter 20 release to provide Salesforce customers the fastest path to continuous innovation.

November 06, 2019

Applause announced its new solution for AI training and testing.