Business Wire

CA-VERACODE

1.5.2024 14:51:32 CEST | Business Wire | Press release

Share
Veracode Elevates Developer-Powered Application Risk Management with Latest Innovations: Enhanced Repo Risk Visibility & Analysis and Veracode Fix in the IDE

Veracode, a global leader in application risk management, today announced platform innovations that set a new standard for developer-powered application security. New repo risk visibility and analysis from Longbow Security, powered by Veracode, speeds up remediation of application risk from code repositories to runtime images. The solution launches alongside Veracode Fix in the Integrated Development Environment (IDE) and Batch Fix to bridge the gap between development and security teams. These latest innovations help developers focus on the most critical tasks that drive value and differentiation.

“Developers today face significant competing pressures to innovate faster and perform more security checks on their code than ever before,” said Tim Jarrett, Group Head of Product Management at Veracode. “We are committed to a frictionless experience for developers and security operators and our latest product enhancements make the job of securing code simple and seamless.”

Bringing Developer & Security Teams Together: Repo Risk Visibility & Analysis

In April, Veracode acquired Longbow Security to help organizations effectively manage and reduce application risk across the growing attack surface. The integration of Longbow’s newest capability, repo risk visibility and analysis, bridges the gap between development and security teams with enhanced visibility from code repositories to cloud assets and runtime images. It also illuminates infrastructure-as-code and misconfiguration risk for cloud assets originating from repositories.

“Customers challenged us to apply our unique cloud risk and prioritization expertise from Longbow to problems they face managing upstream risk in their code repositories,” said Derek Maki, Vice President of Product Management at Veracode. “We responded with a solution that gives visibility into the relationship between source code weaknesses and runtime security posture. Simultaneously, development teams get a consolidated view of risk and huge time savings when it comes to prioritizing remediation, reducing code changes, and fixing issues fast.”

This new feature complements Veracode’s latest innovation for GitHub repo scanning, which enables developers to streamline activities like staging servers and environments so they don’t need to scan every time. This makes it easier for development and security teams to collaborate on secure coding and scanning as Veracode results are delivered to GitHub where developers can act immediately.

Security Debt Reduction: Veracode Fix in the IDE & Batch Fix

Research shows 92 percent of U.S.-based developers are already using artificial intelligence (AI) coding tools both in and outside of work, with generative AI helping software engineers write code 35-45 percent faster. At the same time, other research suggests code developed by AI contains the same percentage of security flaws as that generated by humans.

Veracode was the first company to deliver a solution that provides developers with AI-generated secure code fixes. Since launching Veracode Fix at RSA Conference last year, hundreds of customers have used the solution to reduce their backlog of security debt and risk. Ninety-two percent of CWEs (Common Weakness Enumeration) with a severity rating from medium to very high can be addressed through AI-generated code edits from Veracode Fix.

With the introduction of Veracode Fix in the IDE, developers can now fix flaws faster with AI-suggested remediation right in the IDE, without switching applications or researching alternative code options. Fixes can be made before code is pushed through the software development lifecycle, dramatically cutting the time and cost spent fixing flaws compared to retroactive remediation.

Batch Fix enables bulk AI-assisted remediation of flaws in source code across multiple flaws and files in one operation. This makes remediation of flaws an order of magnitude faster, aiding the reduction of security debt at scale. For example, developers can use it to fix a CWE that requires an easy-to-test resolution and run it across multiple source files at once.

Jarrett closed, “With these latest innovations, Veracode meets developers where they are—in the tools they use daily—to help them secure the code they create today, without compromising productivity. This vastly improves efficiency and velocity, fostering a culture of collaboration and trust between development and security teams.”

Repo Risk Visibility & Analysis, Veracode Fix in the IDE, and Batch Fix are available immediately. For more information, please visit the Veracode blog.

Visitors to RSA Conference can learn more about Veracode’s platform and these new features by visiting Veracode’s booth #2045 in the main hall.

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and Twitter.

Copyright © 2024 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240501107223/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Clearlake Capital Closes on $14.8 Billion to Capitalize on AI-Driven Transformation and Continue Sector-Focused Investment Strategy16.6.2026 15:00:00 CEST | Press release

Fund VIII Reflects Strong Global Investor Support for Clearlake’s Integrated Platform, Operational Value-Creation Model, and AI-Enabled Investment Approach Clearlake Capital Group, L.P. (“Clearlake” or the “Firm”), a global investment firm managing integrated platforms spanning private equity, liquid and private credit, and other related strategies, today announced the successful close of its eighth flagship fund, Clearlake Capital Partners VIII (“Fund VIII”), alongside related co-investment vehicles and separately managed accounts. Together, these vehicles represent $14.8 billion of capital commitments and position Clearlake to continue investing behind the secular trends reshaping industries, including artificial intelligence, software modernization, digital transformation, and operational efficiency. The successful fundraise comes amid a highly competitive and selective fundraising environment for private markets and underscores continued investor confidence in Clearlake's different

Gurobi's Research Leadership Recognized Across Leading Scientific Organizations16.6.2026 15:00:00 CEST | Press release

Awards recognize foundational research that helped shape the fields of mixed-integer and nonlinear optimization—and reflect the company’s deep scientific roots. Gurobi Optimization, LLC, the leader in decision intelligence technology, today announced recognitions received by Dr. Edward Rothberg and Dr. Andreas Wächter from leading academic and industry organizations for research that has had lasting impact on the field of optimization. “Gurobi was founded on a commitment to rigorous, applied optimization research,” said Dr. Oliver Bastert, CTO, Gurobi. “And these recognitions are a reflection of that legacy. The foundational work that Ed and Andreas produced continues to shape the field, and that same spirit of scientific innovation drives everything we do today.” Dr. Edward Rothberg, co-founder and Chairman of the Board at Gurobi, was recently honored with the INFORMS Test of Time Paper Award for his paper, “An Evolutionary Algorithm for Polishing Mixed Integer Programming Solutions.”

Airship Helps DIE ZEIT Turn Silent Advocates into 4.9-Star Rating16.6.2026 15:00:00 CEST | Press release

Leveraging Airship’s Customer Experience Platform, Germany’s leading digital news publisher transforms reader engagement and captures 822 active responses in a single day. Airship, the mobile-first customer experience company, today announced that DIE ZEIT, one of Germany’s largest and most prestigious publishers, has successfully transformed its mobile app presence, lifting the Google Play app store rating from 2.7 stars in early 2026 to a near-perfect 4.9 stars. At a time when many traditional publishers are seeing readership numbers plummet, DIE ZEIT is growing — reaching an all-time high circulation in 2025 and building a digital ecosystem around the brand. The majority of the publication’s readers are now digital, but the publication’s app store rating for DIE ZEIT didn’t match this momentum. DIE ZEIT was up against a universal challenge faced by digital product teams and customer experience executives globally: the "silent advocate" problem. While highly satisfied customers rarel

New CSC Report Illustrates How AI Is Affecting Enterprise Security Leaders16.6.2026 15:00:00 CEST | Press release

CISO Outlook 2026 report indicates 73% of security leaders view AI as an opportunity rather than a risk, however traditional and AI-driven cyber threats persist CSC, an enterprise-class domain registrar and world leader in mitigating brand, fraud, domain, and domain name system (DNS) threats, today released new research on how chief information security officers (CISOs) are adapting to an evolving artificial intelligence (AI) ecosystem while managing traditional cyber threats, such as DNS outages. According to CSC’s CISO Outlook 2026 report, 73% of respondents say AI presents more of an opportunity than a risk for cybersecurity. However, these security leaders continue to face challenges in addressing attacks, including AI-powered domain generation algorithms (DGAs), which 86% of respondents cite as a threat. To thoroughly understand the CISO perspective on today’s cybersecurity landscape, CSC surveyed 300 senior executives—including CISOs, chief technology officers (CTOs), chief infor

TestMu AI Introduces DevTools Assertions in Kane CLI, Enabling Browser-Level Validation Through Natural Language16.6.2026 14:30:00 CEST | Press release

New capability allows developers and AI agents to validate network activity, console logs, browser storage, and performance metrics without writing custom scripts TestMu AI (formerly LambdaTest), the world's first Agentic AI-powered Quality Engineering platform, today announced DevTools Assertions for Kane CLI, enabling developers and AI agents to validate browser internals using natural language. Traditional browser automation focuses on what users can see: buttons, forms, text, and visual states. However, modern web applications depend heavily on browser activity that remains invisible to users, including network requests, API responses, console logs, cookies, local storage, and performance metrics. With DevTools Assertions, Kane CLI extends browser validation beyond the UI, allowing teams to verify these underlying signals using plain-English objectives. Developers can now write objectives such as: "Click Add to Cart and assert the request to /api/cart returned status 200." "Run the

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye