Simplifying Software Security: Veracode Enhances Frictionless Experience for Developers
Black Hat (booth #2428) – Veracode, a leading global provider of application security testing solutions, today announced the enhancement of its Continuous Software Security Platform with substantial improvements to its integrated developer experience. New features include extended integrations to support software composition analysis (SCA), a software bill of materials (SBOM) Application Programming Interface (API), and additional language and framework support for static analysis, further enhancing developers’ ability to secure software in the environments where they work.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20220809005141/en/
Fig. 1 Veracode “Beat the Heat” security flaw heat map, State of Software Security Report v12 (Graphic: Business Wire)
Brian Roche, Chief Product Officer at Veracode, said, “Modern applications are mostly assembled, not written from scratch. Open-source code makes up a significant proportion of audited code bases—for example, 97 percent of the typical Java application is made up of open-source libraries*—increasing security risk and the need to identify supply chain risk. Our SBOM API, is designed to make it easier for developers to inventory their code base, including third-party components, allowing them to act quickly if new vulnerabilities emerge. Since the launch of our Continuous Software Security Platform in May, we have introduced additional capabilities that meet developers right where they work: in the integrated developer environment (IDE), code repository, and command line interface. These innovations are designed to drive adoption by making the platform even more developer friendly.”
Facilitating DevSecOps
Veracode’s platform supports 100+ languages and frameworks, including those for cloud-native application development and older languages used with legacy assets, like COBOL. Large enterprises have applications across myriad languages and being able to deploy a continuous security testing solution across them simplifies the process, while providing consistent results. The company’s latest State of Software Security (SoSS) 12 research analyzed the most common flaws by language and revealed that a prevalent flaw for one language may not be of any concern for another. For example, cross-site scripting (XSS) is the most common flaw for PHP, at 77 percent, but doesn’t even make the top 10 for C++*. Moreover, flaws change constantly, meaning that even if a flaw isn’t prevalent in a programming language, practitioners should still take active steps to prevent it from impacting their code. Since remediation tactics vary by flaw and programming language, having a broad array of language support in one place makes developers’ jobs easier by freeing up their time to focus on meeting tight deployment deadlines.
Frequent scanning of first- and third-party code mitigates the risk from both proprietary and open-source vulnerabilities, such as Log4j. Veracode’s new developer-centric tools and services are designed to make this a quicker and easier process, particularly with the additional capability of third-party proprietary library scanning.
Peter Evans, Engineering Director at QAD Precision GTTE, said, “Veracode brought a complete platform for us to build security tools into our development pipelines, as well as helped us grow our knowledge to keep getting better at security. Veracode was also a good fit because the platform can scan Java code in the Spring framework where we develop our software. We’ve gone from reviewing code to integrating continuous scans into our daily pipelines. Security threats don’t stand still and Veracode provides us the tools to keep up with the latest vulnerabilities and rules.”
Notable updates to the Veracode Continuous Software Security platform include:
SBOM for SCA
- With government regulations driving standards for securing software supply chains, having an SBOM is increasingly important for organizations. Veracode’s SBOM API in SCA enables developers to easily generate an SBOM in CycloneDX JSON format—one of the approved formats for compliance with the U.S. Executive Order. This helps confirm the code they’re using, or building, is free from vulnerabilities.
IDE and Integrations for SCA
To make software security a seamless experience, Veracode continues to introduce integrations that meet developers where they work.
- The Veracode Azure DevOps Extension has a new “SCA Flaw Importer” to automatically import SCA flaws into Azure DevOps Boards and Work Items
- The soon-to-be-released Veracode for Visual Studio Code extension provides detailed information on vulnerabilities, licence risks, and recommended versions of open-source libraries and transitive dependencies so developers can rapidly respond to any risks
Expanded Frameworks and Languages Support for Static Analysis
- The company is committed to keeping up with the latest language and frameworks with which developers work, adding support for Rails 7.0, Ruby 3.x, and PHP Symfony
Roche concluded, “As a pioneer of application security, we are uniquely positioned to combine unrivalled experience with the latest innovations in cloud development. Unlike on-premise vendors, our SaaS solution is both scalable and elastic, meaning customers are always prepared to meet unexpected demand. Powered by nearly two decades of cumulative data, our platform provides detailed comparative historical reviews against industry benchmarks and peers—a level of insight highly relevant for leadership teams and the board. Our platform also saves developers time by delivering highly accurate results and enabling them to find and fix vulnerabilities in minutes, meaning they can ship code quickly with the confidence that it is secure.”
Developers can learn more about Veracode’s platform, the frictionless developer experience, and how to simply and maturely secure their SDLC by visiting Veracode’s booth #2428 at Black Hat USA.
*Veracode State of Software Security Report v12, February 2022
About Veracode
Veracode is a leading AppSec partner for creating secure software, reducing the risk of security breach, and increasing security and development teams’ productivity. As a result, companies using Veracode can move their business, and the world, forward. With its combination of process automation, integrations, speed, and responsiveness, Veracode helps companies get accurate and reliable results to focus their efforts on fixing, not just finding, potential vulnerabilities.
Learn more at www.veracode.com, on the Veracode blog and on Twitter.
Copyright © 2022 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220809005141/en/
Contact information
Press and Media
Katy Gwilliam
Head of Global PR, Veracode
kgwilliam@veracode.com
+44.7584.341.110
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Belkin Unveils Next-Generation Chargers, Gaming Power Accessories and More at CES 20264.1.2026 19:00:00 EET | Press release
Belkin, a leading consumer electronics brand for over 40 years, today announced a bold new lineup of accessories designed to power, protect, and enhance the way people work, play, and connect. The new collection, debuting at CES 2026, includes advanced power banks, Qi2 25W wireless chargers, a wireless HDMI dongle for seamless content sharing, and a next gen charging case for the Nintendo Switch 2. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260104976028/en/ Belkin unveils new products at CES 2026 Gaming Charging Case Pro for Nintendo Switch 2 (Model ENA003) Engineered for the ultimate on-the-go gaming experience, the Pro case delivers power, protection, and portability in one premium package. A removable 10,000 mAh power bank delivers up to 30W fast charging and features an LCD screen to display remaining battery life. The Pro version builds on the standard model’s safe in‑case charging with a sleeker, integrated power b
Belkin Elevates Everyday Device Protection with a New Lineup of Screen Protectors and a Wear & Tear Program4.1.2026 19:00:00 EET | Press release
Belkin, a leading consumer electronics brand for over 40 years, today announces a new class of screen protection solutions, a strategic partnership, and an all-new wear-and-tear program; advancing its commitment to keeping devices protected and consumers confident. The launch includes seven new screen protectors, a customization partnership with ScreenSkinz, and a screen protection replacement program designed to give users lasting peace of mind and ensure the products they love stay safe, secure, and in the best shape. Meet the ScreenForce Titan Lineup: The Ultimate in Full-Screen Protection Titan SmartShield Titan SmartShield serves as the premium rigid protector in the lineup, delivering aerospace-grade impact resistance and up to 18x the strength of traditional glass*. Engineered with a 9H surface hardness and rated for up to 6.5 ft / 2 m of drop protection**, Titan SmartShield offers exceptional durability without compromising clarity. An advanced anti-reflective coating preserves
SINOVAC Provides Update on Antigua High Court Order and Auditor Engagement4.1.2026 17:13:00 EET | Press release
Sinovac Biotech Ltd. (NASDAQ: SVA) (“SINOVAC” or the “Company”), a leading provider of biopharmaceutical products in China, today provided an update on the Antigua High Court’s interlocutory order governing the Company’s board composition and corporate actions pending trial, and announced the engagement of Zhonghua Certified Public Accountants LLP (“Zhonghua”), an affiliate of the global accounting network UHY International, as the Company’s independent auditor and registered public accounting firm. Update on Antigua High Court Order Further to the order issued by the Antigua High Court (the “Court”) previously disclosed by the Company in a press release dated December 17, 2025, the Court has updated its order to provide that directors Mr. Simon Anderson, Mr. Shan Fu, Mr. Shuge Jiao, Dr. Chiang Li, Mr. Yuk Lam Lo, Mr. Yumin Qiu, Mr. Yu Wang, Ms. Rui-Ping Xiao, Mr. Andrew Y. Yan and Mr. Weidong Yin (collectively, the “Board”), will comprise the Board of the Company until the trial liste
Sinovac Receives Nasdaq Notification Regarding Late Filing of 2025 Half-Year Report4.1.2026 17:00:00 EET | Press release
Sinovac Biotech Ltd. (NASDAQ: SVA) (“SINOVAC” or the “Company”), a leading provider of biopharmaceutical products in China, today announced that it has received a notification letter dated January 2, 2026 (the “Notification Letter”) from Nasdaq Listing Qualifications (“Nasdaq”), stating that the Company was not in compliance with Nasdaq’s Listing Rule 5250(c)(2) since the Company did not timely file a Form 6-K containing an interim balance sheet and income statement as of the end of its second quarter of year 2025. As previously disclosed, the Company received a delisting determination letter (the “Staff Determination”) from Nasdaq in November 2025. The Company requested a hearing before the Nasdaq Hearings Panel to appeal the Staff Determination on November 19, 2025. Nasdaq has informed the Company that the Nasdaq Hearings Panel will also consider the matter addressed in the Notification Letter at a hearing scheduled for January 8, 2026 at which the Company has been invited to present
Consumer Tech Growth to Reset in 2026 as Demand Shifts to Europe and MEA4.1.2026 14:00:00 EET | Press release
NielsenIQ (NYSE:NIQ), a global leader in consumer intelligence, today released its 2026 Consumer Tech & Durable Goods (T&D) market outlook. In collaboration with the Consumer Technology Association (CTA), NIQ expects T&D global sales to level off in 2026 after a strong 2025. The sector is set to finish 2025 at roughly $1.3 trillion USD, up 3% from 2024, while 2026 overall sales value is projected to hold steady at an estimated -0.4% year over year (YoY). While the global picture looks flat, the real story lies in the differences in regional and sector performance. Consumers overall remain careful with their spending and are prioritizing value for money—with a focus on products that offer enhanced performance, convenience, energy-saving, and/or durability. Brands and retailers that align pricing, innovation, and experience to region- and category-specific demand will win share of wallet. “In 2025, global Consumer Tech & Durable goods purchases grew by a solid 3%. Growth is expected to s
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
