Veracode Releases Platform Enhancements as Software Supply Chain Attacks Surge
28.1.2026 14:50:00 EET | Business Wire | Press release
Veracode, the global leader in application risk management, today announced significant platform innovations introduced through the second half of 2025. Headlining the release is Package Firewall, an industry-leading preventive control for software supply chains, advancing the company’s mission to help organizations run secure software from code to cloud. With supply chain-related third-party breaches doubling year over year— from 15 to 30 percent according to the Verizon 2025 Data Breach Investigations Report— the need to strengthen security across the software ecosystem has never been greater.
“The growing attack surface has created an unprecedented level of complexity for security and development teams,” said Tim Jarrett, Vice President of Product at Veracode. “The latest enhancements to our platform empower organizations to stop third-party risk from ever entering their software code, providing them with a prevention-first approach.”
Package Firewall Enhancement: Preventing Supply Chain Attacks at the Source
Package Firewall, originally launched in June 2025, provides organizations with preventive control over their software supply chains by blocking malicious and risky packages before they enter the development environment. While traditional Software Composition Analysis (SCA) tools identify vulnerabilities in packages that are already in use, Veracode Package Firewall stops threats at the point of ingestion.
The solution now integrates with Azure Artifacts and deploys in seconds with integrations into package managers and repositories, like NPM, PyPI, Maven, Nexus, and Artifactory. It also supports custom policies that enable organizations to enforce security standards while maintaining developer productivity. Organizations can configure policies based on package risk profiles, vulnerability thresholds, and specific security requirements.
Expanded Platform Capabilities and Developer Experience
Veracode continued to expand and enhance its platform capabilities and developer experience throughout the year, with each release improving detection accuracy. Dynamic Application Security Testing (DAST) Essentials gained manual application linking, enabling policy evaluation and consolidated reporting. Software Composition Analysis (SCA) was upgraded with intelligent policies that only fail builds when fixes are available for vulnerable components, reducing developer friction. Static Analysis support was added for cutting-edge frameworks, including .NET Semantic Kernel, Python frameworks like AWS Glue and FastAPI, Java JDK 25 (LTS), and Node.js 22.x.
The platform also saw significant updates to developer integrations for Visual Studio, JetBrains, Azure DevOps, and GitHub, alongside expansions to Veracode Security Labs, with training modules in container security content and the latest OWASP Top 10.
Enterprise-Grade Authentication for Developer Tools
The most recent platform update saw Veracode introduce the advanced enterprise-grade security required by modern organizations. The company added more thorough platform integration and deeper role-based access control to Veracode Risk Manager (VRM), and OAuth-based single sign-on (SSO) authentication across its entire Integrated Development Environment (IDE) plugin portfolio, including Visual Studio Code, Visual Studio, Eclipse, and JetBrains platforms. The integration eliminates Application Programming Interface (API) key management and delivers secure, enterprise-grade authentication with centralized access control.
Jarrett closed, “Our mission is to empower organizations to enhance their security posture, bridge critical skills gaps, and accelerate remediation—all within a unified, integrated platform. By listening closely to our customers, we continuously evolved Veracode’s platform in 2025 to meet their needs, enabling them to drive faster, more secure DevSecOps practices.”
To learn more about Veracode’s products and platform enhancements, visit the website.
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, Package Firewall, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260128773416/en/
Contacts
Press and Media Contacts
Katy Gwilliam
Head of Global Communications, Veracode
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Axelspace Announces Launch of Seven GRUS-3 Earth Observation Microsatellites, No Earlier Than July 202619.5.2026 11:30:00 EEST | Press release
Axelspace Corporation, a leading developer and operator of microsatellites dedicated to realizing its vision of “Space within Your Reach,” announced today that GRUS-3, a set of seven next-generation Earth observation microsatellites, is scheduled to be launched no earlier than July 2026. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260519449959/en/ Seven flight model of GRUS-3 next-generation Earth observation microsatellites ©Axelspace The seven GRUS-3 microsatellites will launch aboard the Transporter-17 rideshare mission via Exolaunch, a global leader in launch mission management, satellite integration, and deployment services, from Vandenberg Space Force Base in California, USA. We currently operate five optical Earth observation microsatellites, GRUS-1, under our Earth observation data service, AxelGlobe. With the launch of its successor, GRUS-3, it will expand its satellite constellation to more than 10 satellites. E
Money20/20 Europe Announces Powerhouse Speaker Lineup Featuring Leaders from Klarna, BBVA, ABN AMRO, Mastercard, eToro, and Revolut19.5.2026 11:10:00 EEST | Press release
Money20/20, the world’s leading fintech show and the place where money does business, today announced a stellar line-up of speakers for Money20/20 Europe happening on June 2-4 at the RAI in Amsterdam. The show will feature 450+ speakers across six stages, exploring the forces redefining global finance through AI innovation, digital assets, and regulatory transformation. Newly confirmed speakers include some of the most influential voices shaping the future of payments, banking, and financial services: Sebastian Siemiatkowski, Co-Founder and CEO, Klarna. A pioneer in the buy now, pay later revolution, Siemiatkowski has transformed consumer payments and continues to drive innovation in embedded finance and AI-powered shopping experiences. Onur Genç, CEO, BBVA. Leading one of Europe's most digitally advanced banks, Genç is at the forefront of banking transformation, leveraging data, technology, and customer-centric strategies to redefine financial services. Marguerite Bérard, Chief Execut
Mythic Acquires Videantis, One of Europe’s Leading Digital Processor IP Companies, to Build the World’s Most Energy-Efficient AI Compute Platform19.5.2026 11:00:00 EEST | Press release
Mythic, a pioneer in analog compute-in-memory and architect of the industry’s most energy-efficient AI acceleration technology, today announced it has acquired Videantis GmbH, one of Europe’s leading digital processor IP companies. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260519255958/en/ The transaction unites Mythic’s breakthrough analog compute platform with Videantis’ highly differentiated, unified digital processor architecture and production-proven software stack — accelerating Mythic’s delivery of a new class of hybrid AI compute platform with a 100x energy efficiency advantage over conventional GPU-based systems. This deal builds on Mythic’s recently announced agreement with Honda to co-develop next-generation AI chips for future vehicles — a validation of Mythic’s game-changing architecture in one of the world’s most demanding production environments. Together, the Honda collaboration and the Videantis acquisi
Splio Enters a New Phase of Its Regional Development in Southern Europe19.5.2026 10:00:00 EEST | Press release
A few months after launching its AI-first CRM, Splio is entering a new phase of its development in Southern Europe. Already established for more than 12 years in Spain, Portugal and Italy, the company has chosen to invest further in the region, convinced that it combines economic potential with rapidly evolving digital usage. Antoine Parizot, Splio’s co-CEO, is relocating to Barcelona, where the company’s historic office is based. At the same time, Donald Pontabry, COO and based in Spain for more than eight years, is taking responsibility for Southern Europe in addition to his current role. This development is supported by a regional team of around thirty people, spanning partnerships, business development, customer success and support. The team already works with around one hundred local clients, including Bodeboca, QVC, GoodNews, Gocco, Equivalenza, Lola Casademunt, Casa Viva, Piazza Italia, Conforama and Gaudi. “We see Southern Europe as much more than a region where we have a long-
KfW, Germany’s largest national promotional bank, future-proofs regulatory reporting, by migrating to Regnology Reporting Hub (RRH)19.5.2026 09:33:00 EEST | Press release
Regnology, a leading provider at the intersection of regulatory, risk, and supervisory technology, today announced that KfW Bankengruppe (KfW) is advancing its long-term partnership with the company by electing to migrate to the next-generation Regulatory Reporting Hub (RRH). The solution will be delivered as a cloud-native service on Rcloud, Regnology’s high-performance cloud architecture layer. This strategic move to the modern RRH platform future-proofs the mission-critical reporting functions for one of the world's leading promotional banks. Headquartered in Frankfurt am Main, KfW is a public‑law institution dedicated to supporting sustainable economic, social and ecological development in Germany, across Europe and globally. Regnology’s foresight led to the 2023 launch of Rcloud, its state-of-the-art architecture layer built on Google Cloud, enabling next‑generation solutions like RRH to operate with the full power of cloud-native design delivering the clear operational and strate
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom