Simplifying Software Security: Veracode Enhances Frictionless Experience for Developers
14.9.2022 21:33:00 EEST | Business Wire | Press release
Black Hat (booth #2428) – Veracode, a leading global provider of application security testing solutions, today announced the enhancement of its Continuous Software Security Platform with substantial improvements to its integrated developer experience. New features include extended integrations to support software composition analysis (SCA), a software bill of materials (SBOM) Application Programming Interface (API), and additional language and framework support for static analysis, further enhancing developers’ ability to secure software in the environments where they work.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20220809005141/en/
Fig. 1 Veracode “Beat the Heat” security flaw heat map, State of Software Security Report v12 (Graphic: Business Wire)
Brian Roche, Chief Product Officer at Veracode, said, “Modern applications are mostly assembled, not written from scratch. Open-source code makes up a significant proportion of audited code bases—for example, 97 percent of the typical Java application is made up of open-source libraries*—increasing security risk and the need to identify supply chain risk. Our SBOM API, is designed to make it easier for developers to inventory their code base, including third-party components, allowing them to act quickly if new vulnerabilities emerge. Since the launch of our Continuous Software Security Platform in May, we have introduced additional capabilities that meet developers right where they work: in the integrated developer environment (IDE), code repository, and command line interface. These innovations are designed to drive adoption by making the platform even more developer friendly.”
Facilitating DevSecOps
Veracode’s platform supports 100+ languages and frameworks, including those for cloud-native application development and older languages used with legacy assets, like COBOL. Large enterprises have applications across myriad languages and being able to deploy a continuous security testing solution across them simplifies the process, while providing consistent results. The company’s latest State of Software Security (SoSS) 12 research analyzed the most common flaws by language and revealed that a prevalent flaw for one language may not be of any concern for another. For example, cross-site scripting (XSS) is the most common flaw for PHP, at 77 percent, but doesn’t even make the top 10 for C++*. Moreover, flaws change constantly, meaning that even if a flaw isn’t prevalent in a programming language, practitioners should still take active steps to prevent it from impacting their code. Since remediation tactics vary by flaw and programming language, having a broad array of language support in one place makes developers’ jobs easier by freeing up their time to focus on meeting tight deployment deadlines.
Frequent scanning of first- and third-party code mitigates the risk from both proprietary and open-source vulnerabilities, such as Log4j. Veracode’s new developer-centric tools and services are designed to make this a quicker and easier process, particularly with the additional capability of third-party proprietary library scanning.
Peter Evans, Engineering Director at QAD Precision GTTE, said, “Veracode brought a complete platform for us to build security tools into our development pipelines, as well as helped us grow our knowledge to keep getting better at security. Veracode was also a good fit because the platform can scan Java code in the Spring framework where we develop our software. We’ve gone from reviewing code to integrating continuous scans into our daily pipelines. Security threats don’t stand still and Veracode provides us the tools to keep up with the latest vulnerabilities and rules.”
Notable updates to the Veracode Continuous Software Security platform include:
SBOM for SCA
- With government regulations driving standards for securing software supply chains, having an SBOM is increasingly important for organizations. Veracode’s SBOM API in SCA enables developers to easily generate an SBOM in CycloneDX JSON format—one of the approved formats for compliance with the U.S. Executive Order. This helps confirm the code they’re using, or building, is free from vulnerabilities.
IDE and Integrations for SCA
To make software security a seamless experience, Veracode continues to introduce integrations that meet developers where they work.
- The Veracode Azure DevOps Extension has a new “SCA Flaw Importer” to automatically import SCA flaws into Azure DevOps Boards and Work Items
- The soon-to-be-released Veracode for Visual Studio Code extension provides detailed information on vulnerabilities, licence risks, and recommended versions of open-source libraries and transitive dependencies so developers can rapidly respond to any risks
Expanded Frameworks and Languages Support for Static Analysis
- The company is committed to keeping up with the latest language and frameworks with which developers work, adding support for Rails 7.0, Ruby 3.x, and PHP Symfony
Roche concluded, “As a pioneer of application security, we are uniquely positioned to combine unrivalled experience with the latest innovations in cloud development. Unlike on-premise vendors, our SaaS solution is both scalable and elastic, meaning customers are always prepared to meet unexpected demand. Powered by nearly two decades of cumulative data, our platform provides detailed comparative historical reviews against industry benchmarks and peers—a level of insight highly relevant for leadership teams and the board. Our platform also saves developers time by delivering highly accurate results and enabling them to find and fix vulnerabilities in minutes, meaning they can ship code quickly with the confidence that it is secure.”
Developers can learn more about Veracode’s platform, the frictionless developer experience, and how to simply and maturely secure their SDLC by visiting Veracode’s booth #2428 at Black Hat USA.
*Veracode State of Software Security Report v12, February 2022
About Veracode
Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities.
Learn more at www.veracode.com, on the Veracode blog and on Twitter.
Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220809005141/en/
Contact information
Press and Media
Katy Gwilliam
Head of Global PR, Veracode
kgwilliam@veracode.com
+44.7584.341.110
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Exeon Analytics expands management team for next growth phase2.9.2026 11:00:00 EEST | Press release
Exeon Analytics is expanding its management team with two new roles. Wayne Jennings takes on the newly created position of Chief Solutions Officer, and Johan Roman becomes Chief Revenue Officer. The appointments fall in the company’s anniversary year, ten years after its founding as an ETH Zurich spin-off, and create the structure for the next growth phase. Exeon Analytics delivers holistic security analytics for organizations facing growing blind spots, encrypted traffic and regulatory pressure. Wayne Jennings joined Exeon Analytics in July 2024 and initially led Support and Engineering. As Chief Solutions Officer, he is responsible for the technical customer lifecycle, from pre-sales and proof of concept through implementation to long-term technical account management, and for the technical enablement of partners. Before joining Exeon Analytics, he was a Senior Manager in Cybersecurity & Privacy at PwC Switzerland, focusing on threat intelligence and incident response. Johan Roman br
euroAtlantic Airways Expands Long-Haul Fleet With a New Airbus A330-300 Aircraft2.9.2026 10:00:00 EEST | Press release
euroAtlantic Airways (“EAA”), a Njord Partners portfolio company and a leading Portuguese aircraft wet-leasing and charter business, is pleased to announce the induction of a new Airbus A330-300 aircraft into its fleet, further strengthening its long-haul widebody capabilities and reinforcing the Company's growth trajectory in the ACMI and charter markets. The Airbus A330-300 is leased from Jackson Square Aviation (JSA). Only 15 years old, the aircraft is configured in a three-class layout of Business, Premium Economy and Economy, accommodating a total of 290 passengers, and features full lie-flat seating in Business Class along with personal in-seat entertainment monitors fitted across the entire cabin. The aircraft, which will be registered as CS-TGI after completing its normal process of approval with authorities, has already completed its delivery journey, departing Kuala Lumpur (KUL) and arriving into Beja, Portugal (BYJ) on 17 August 2026. This aircraft type is known for its effi
Interoperability and Trust Key to AI Commerce: Alipay+ and S&P Global Report2.9.2026 09:33:00 EEST | Press release
A new report by Alipay+, the unified wallet gateway of Ant International, in partnership with S&P Global, reveals a growing "commerce digitalisation gap", with people increasingly expecting seamless mobile payments and intelligent digital assistance, yet friction – from inconsistent payment acceptance to trust in AI – still define their experience. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260901394299/en/ The study, which surveyed 6,000 consumers across nine markets in Asia, Europe and the US on their cross-border spending habits, points to a major shift underway in global commerce — one where e-wallets, AI and interoperable digital ecosystems are becoming foundational to how consumers discover, transact and engage across borders. Key findings: Travel exposes gaps in global commerce infrastructure: More than half of consumers cite uncertainty around merchant acceptance (53%) or lack of access to preferred payment metho
Kontoor Brands Unveils Helly Hansen Growth Strategy and 2030 Financial Targets2.9.2026 09:30:00 EEST | Press release
Kontoor Brands, Inc. (NYSE: KTB) today announced Helly Hansen’s long-term growth strategy and 2030 financial targets, which Kontoor Brands will present at the Helly Hansen® Investor Day later today. The plan is designed to scale Helly Hansen globally while significantly expanding its profitability through 2030. "With 150 years of technical heritage and an authentic right to win globally, Helly Hansen is a brand with tremendous long-term growth potential," said Scott Baxter, Chief Executive Officer and Chairman of the Board of Kontoor Brands. "Strong alignment between our teams has allowed us to integrate quickly and move straight to executing against the opportunity ahead. Our sustained investment in Helly Hansen will be a catalyst for its next phase of growth, and we are confident in our ability to deliver significant value for our consumers, employees and shareholders for years to come." A Focused Growth Strategy: To deliver against these targets, Helly Hansen’s growth is anchored in
Axelspace Announces Partnership with Airbus Defence and Space to Deliver Satellite Imagery to a Broader Market2.9.2026 09:30:00 EEST | Press release
Axelspace Corporation (“Axelspace”), a leading microsatellite company committed to making “Space within Your Reach,” announced today a new agreement with Airbus Defence and Space, a global leader in Earth observation including optical and radar satellite imagery, to provide mid-resolution optical images captured by Axelspace’s Earth observation microsatellites “GRUS.” Under this strategic partnership, we will develop and deliver innovative solutions that meet long-term customer needs for utilizing satellite imagery. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260901360086/en/ GRUS is Axelspace's series of approximately 100 kg-class optical Earth observation microsatellites. GRUS-1 is currently operated as a four-satellite constellation, delivering high-frequency, wide-area imagery. This imagery, together with value-added solutions derived through processing and analysis, supports a broad range of industries, including agr
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
