phpBB Heb

Main Menu

  • Home
  • Internet Forum
  • PHP Scripting Language
  • Open Source Software
  • Online Communities
  • Commerce

phpBB Heb

Header Banner

phpBB Heb

  • Home
  • Internet Forum
  • PHP Scripting Language
  • Open Source Software
  • Online Communities
  • Commerce
Open Source Software
Home›Open Source Software›WhiteSource for Azure Repos scans open source code for security vulnerabilities

WhiteSource for Azure Repos scans open source code for security vulnerabilities

By George T. Sprague
January 28, 2022
0
0

WhiteSource has released an Azure DevOps repository integration, allowing Azure DevOps users to detect all open source components and automatically apply security policies directly from their repository.

Users can now receive vulnerability alerts along with detailed remediation information, including suggested fixes and prioritization tips, all from the comfort of their native environment, without having to learn a new user interface (UI) .

As the time to market for applications gets shorter every year, software development teams are challenged to speed up their processes without compromising security. Many software composition analysis (SCA) vendors scan the repository for vulnerabilities, but only provide results in their own user interface, which slows down the development process.

WhiteSource’s integration for Azure Repos automatically scans open source code for security vulnerabilities or license violations with every merge request, before the code is merged. If a merge request introduces a new error, the developer receives immediate feedback to resolve any newly introduced vulnerabilities. Positive feedback is given when a pull request resolves vulnerabilities.

This differential view between feature branches and master branches avoids interruptions in workflows. In addition to WhiteSource’s existing integrations with all major code repositories, including GitHub, GitHub Packages, JFrog, Bitbucket, and GitLab, the new WhiteSource integration for Azure Repos allows users to generate inventory, security, and compliance.

With WhiteSource’s cloud-based integration for Azure Repos, users can:

  • Show automated correction suggestions — WhiteSource Enterprise automatically generates pull requests in the repository to update vulnerable open source components to the lowest non-vulnerable version.
  • Apply policies – policies are automatically applied in the repository for each merge request. The status and results of each scan are displayed on the Commits page.
  • Merge with confidence – WhiteSource’s “Merge Confidence” feature uses crowdsourced data to show the likelihood that an open source component can be updated without breaking the build. Merge Confidence includes age, adoption, and upgrade compatibility data to create a confidence score.
  • Check for IaC configuration errors – Protect production environments and secure cloud, containers, and Kubernetes directly from Azure Repos.

“Scanning for vulnerabilities within the repository is the ‘leftmost’ of organizations that can shift their security efforts while enforcing policies and requiring all developers to scan their code,” said Ori Bach, Executive Vice President of Products at WhiteSource. “The cost of patching vulnerabilities is higher as you progress through your software development lifecycle. With the WhiteSource for Azure Repos integration, developers can receive feedback on their code when it’s fresh in their minds, making it easier to fix vulnerabilities while helping organizations save time and money .

Related posts:

  1. Eclipse Sparkplug working group continues to drive adoption of IIot specifications – ADTmag
  2. Armory uses K3 to simplify CD Spinnaker installations
  3. IBM moves to ‘container native’ with software-defined storage platform for OpenShift, Cloud Native
  4. Opto 22 joins the Eclipse Foundation and the Sparkplug working group
Tagssoftware developmentvice president

Recent Posts

  • A high country paradise for sockeye salmon | Alaska Science Forum
  • How to Choose the Best Tech Stack for Your Startup in 2022
  • Open Source to commercial software, the process from project to product
  • 5G services expected to be rolled out within a month, says MoS Telecom
  • 3 ways every business can get started with an open source software strategy

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020

Categories

  • Commerce
  • Internet Forum
  • Online Communities
  • Open Source Software
  • PHP Scripting Language
  • Terms and Conditions
  • Privacy Policy