Veracode Introduces DAST Essentials and Veracode GitHub App
November 27, 2023

Veracode announced product innovations to enhance the developer experience. The new features integrate security into the software development lifecycle (SDLC) and drive adoption of application security techniques in the environments where developers work.

Veracode’s latest innovations redefine the approach to securing cloud-native applications throughout the SDLC, reinforcing the company’s commitment to providing a unified platform for comprehensive security risk management.

Brian Roche, Chief Product Officer at Veracode said, “Developers face immense pressure to rapidly deliver innovations, often resorting to mechanisms such as LLMs and open source to expedite the process. Unfortunately, this approach can result in insecure code consumption and solutions that exacerbate security risks rather than mitigate them. The situation is compounded by existing security tools that add complexity rather than simplifying the process for developers.

Veracode addresses this challenge by providing a unified platform that not only monitors and mitigates risk but also streamlines developer workflows across repositories, IDEs, and the cloud. By delivering developer-friendly security tools, we empower organizations to deliver secure software faster, eliminating the need to compromise between security and speed.”

Veracode’s DAST Essentials is an agile solution that empowers developers and security teams to address risk easily at speed and scale. Veracode DAST Essentials scans and tests multiple web applications and APIs (Application Programming Interfaces) simultaneously. Veracode’s State of Software Security research found 80 percent of web applications have critical vulnerabilities that can only be identified through dynamic scanning. This emphasizes the critical role DAST (Dynamic Application Security Testing) plays in a robust application security program, ensuring organizations can address exploitable vulnerabilities in cloud-native software accurately and swiftly.

The Veracode GitHub App facilitates developer adoption, allowing application security teams to configure once and seamlessly onboard developers. This integration enables developers to fix code quickly in the environments where they work with a single tool for static, software composition analysis (SCA), and container security scanning. The result is a faster, frictionless development process that doesn’t compromise security.

The Veracode GitHub App simplifies this by providing developers with frustration-free scan results in their preferred environment. DevOps teams can easily onboard repositories without manual setup, maintaining development velocity and streamlining scan processes. With the ability to standardize scan configurations across hundreds of repositories using a single click, DevOps teams can reduce friction and integrate cloud-native security much earlier in the development cycle.

Roche closed, “Ensuring the security of cloud-native applications has never been more crucial. Developers are assembling code just as much as they’re writing it, meaning even the most meticulously built applications are susceptible to threat. To protect the software supply chain, modern application development demands a paradigm shift in security practices. As distributed cloud app development methods take hold, these latest product innovations demonstrate Veracode is embracing the dynamic nature of the cloud-native landscape to lead the charge in securing our digital future."

Share this

Industry News

May 22, 2025

Red Hat announced enhanced features to manage Red Hat Enterprise Linux.

May 22, 2025

StackHawk has taken on $12 Million in additional funding from Sapphire and Costanoa Ventures to help security teams keep up with the pace of AI-driven development.

May 21, 2025

Red Hat announced jointly-engineered, integrated and supported images for Red Hat Enterprise Linux across Amazon Web Services (AWS), Google Cloud and Microsoft Azure.

May 21, 2025

Komodor announced the integration of the Komodor platform with Internal Developer Portals (IDPs), starting with built-in support for Backstage and Port.

May 21, 2025

Operant AI announced Woodpecker, an open-source, automated red teaming engine, that will make advanced security testing accessible to organizations of all sizes.

May 21, 2025

As part of Summer '25 Edition, Shopify is rolling out new tools and features designed specifically for developers.

May 21, 2025

Lenses.io announced the release of a suite of AI agents that can radically improve developer productivity.

May 20, 2025

Google unveiled a significant wave of advancements designed to supercharge how developers build and scale AI applications – from early-stage experimentation right through to large-scale deployment.

May 20, 2025

Red Hat announced Red Hat Advanced Developer Suite, a new addition to Red Hat OpenShift, the hybrid cloud application platform powered by Kubernetes, designed to improve developer productivity and application security with enhancements to speed the adoption of Red Hat AI technologies.

May 20, 2025

Perforce Software announced Perforce Intelligence, a blueprint to embed AI across its product lines and connect its AI with platforms and tools across the DevOps lifecycle.

May 20, 2025

CloudBees announced CloudBees Unify, a strategic leap forward in how enterprises manage software delivery at scale, shifting from offering standalone DevOps tools to delivering a comprehensive, modular solution for today’s most complex, hybrid software environments.

May 20, 2025

Azul and JetBrains announced a strategic technical collaboration to enhance the runtime performance and scalability of web and server-side Kotlin applications.

May 19, 2025

Docker, Inc.® announced Docker Hardened Images (DHI), a curated catalog of security-hardened, enterprise-grade container images designed to meet today’s toughest software supply chain challenges.

May 19, 2025

GitHub announced that GitHub Copilot now includes an asynchronous coding agent, embedded directly in GitHub and accessible from VS Code—creating a powerful Agentic DevOps loop across coding environments.