Veracode Introduces New GitHub Action
October 05, 2020

Veracode announced a new GitHub Action to provide developers with an easy and familiar way to ensure that the code they are writing is secure – as they write it. The action enables developers to perform Veracode’s Static Policy Scan workflow, initiate a pipeline scan, and consume pipeline scan results all within GitHub’s code scanning UI.

GitHub Actions CI/CD helps developers improve time to market by allowing them to build, test and deploy code directly from within GitHub. Developers can invoke Veracode’s Static Analysis (SAST) scans from GitHub Actions, significantly expanding the security testing capabilities for developers leveraging GitHub workflows, and allowing them to build security directly into their DevOps processes and scale development across the team.

John Leon, VP of Business Development at GitHub, said, “Veracode understands the importance of shifting left in the development lifecycle to enable teams to find and fix flaws at scale. With software development moving at breakneck speed, this new GitHub Action further enables our joint customers to develop secure software, without compromising speed or quality – all within a familiar interface.”

Veracode’s Static Analysis solution enables DevSecOps by providing fast, automated and actionable security feedback to developers in their pipeline – when they compile their code or when they check in their code - and conducting a full policy scan before deployment. With the new GitHub Action, developers can control Veracode scans as they write code within the GitHub environment and get clear guidance on how to remediate issues. Scan results are converted into GitHub code scanning alerts. When code is ready for deployment, developers can conduct the Veracode Policy Scan for a full assessment of the code, with an audit trail for compliance that can be previewed before triggering alerts. Veracode results have high accuracy without manual tuning as a result of the intelligence of Veracode’s SaaS platform which has scanned more than 21 trillion lines of code, to date.

Ian McLeod, Chief Product Officer at Veracode, said, “Secure development at scale is only possible if developers assume ownership of ensuring that the code they are writing is secure from the start. It’s therefore critical that we provide tools and integrations that simplify the job for the developer and make the capabilities available in the tools they use every day. Our new GitHub Action provides a seamless experience that saves developers time, while giving them the confidence that the code they’re writing is secure.”

Veracode tools are available as GitHub Actions in the GitHub Marketplace.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.