Modern software is a bit like manufacturing: gluing open source components together using proprietary code and tracking everything with a bill of materials.
Continue Reading...
Posted in Open Source Security, Software Composition Analysis (SCA)
With advanced policy management and best-in-class vulnerability reports, developers can fix the most critical vulnerabilities quickly and effectively.
Continue Reading...
Posted in Open Source Security, Software Composition Analysis (SCA), Webinars
You know that static analysis can find code quality defects in your proprietary code. But what are you doing to manage your open source code quality risk?
Continue Reading...
Posted in Open Source Security, Software Composition Analysis (SCA)
With new SCA capabilities, the Code Sight IDE plugin detects vulnerabilities (CVEs) in the open source you use, alongside weaknesses in proprietary code.
Continue Reading...
Posted in News & Announcements, Open Source Security, Software Composition Analysis (SCA)
Learn about the addition of Black Duck to VMware Cloud Marketplace and the benefits and limitations of different types of open source scans.
Continue Reading...
Posted in Open Source Security, Software Composition Analysis (SCA), Webinars
There’s no single silver bullet for application security. Instead, you need a combination of application security tools and services. Here’s an overview.
Continue Reading...
Posted in Application Security, Interactive Application Security Testing (IAST), Software Composition Analysis (SCA), Static Analysis (SAST)
Already using static code analysis? Try boosting your application security program with software composition analysis to automate open source management.
Continue Reading...
Posted in Application Security, Open Source Security, Software Composition Analysis (SCA)
Using static code analysis (SAST) and software composition analysis (SCA) together makes your software development process better, faster, and stronger.
Continue Reading...
Posted in Application Security, Open Source Security, Software Composition Analysis (SCA), Static Analysis (SAST)
GitHub Actions brings the platform into the CI/CD market, making it simple to integrate SAST and SCA into workflows with the Synopsys Detect GitHub Action.
Continue Reading...
Posted in Agile, CI/CD & DevOps, Software Composition Analysis (SCA), Static Analysis (SAST)
Our Defensics R&D team put a couple of Synopsys tools to the test in the 5G Cyber Security Hackathon in Oulu, Finland, and placed in both of their competitions.
Continue Reading...
Posted in Fuzz Testing, Software Composition Analysis (SCA), Software Security Research