Veracode Expands Industry-Leading Fix with AI-Powered SCA Remediation to Combat Software Supply Chain Risk
18.3.2026 13:00:00 CET | Business Wire | Press release
New Capability Automates Open-Source Vulnerability Remediation as Software Supply Chain Attacks Surge
RSA Conference (booth #435)--Veracode, the global leader in application risk management, today announced Veracode Fix for Software Composition Analysis (SCA), an AI-powered solution to address software supply chain risk. The enhanced automated remediation engine—the next evolution of Veracode’s industry-leading Fix solution—enables organizations to detect and remediate open-source vulnerabilities easily, before code reaches production. Designed to integrate seamlessly into existing developer workflows, it delivers third-party updates and first-party code refactoring without breaking builds or disrupting development.
In 2025, software supply chain breaches accounted for 30 percent of external attacks. Meanwhile Veracode’s 2026 State of Software Security (SoSS) Report revealed 82 percent of organizations struggle with escalating security debt, largely due to open-source dependencies. Veracode Fix for SCA addresses both challenges directly. Leveraging deep, contextual analysis, the solution delivers pull requests that are safe to merge, enabling autonomous fixing. Unlike traditional SCA solutions that often overwhelm developers with alerts and hinder productivity, Veracode Fix combines logic-driven AI with proprietary vulnerability intelligence, ensuring ready-to-merge fixes while eliminating the risk of AI "hallucinations."
“AI is accelerating software development—but it's also enabling an unprecedented explosion of supply chain risks,” said Tim Jarrett, Vice President of Product Management. “Visibility into these risks is no longer enough. Organizations need intelligent, automated solutions that not only find vulnerabilities but fix them with precision, giving development teams the confidence to innovate securely.”
Veracode Fix for SCA transforms the remediation process through several core capabilities:
- Contextual Analysis: Evaluates the interaction between third-party dependencies and first-party code, preventing breaking changes.
- Multi-File, Cohesive Pull Requests: Bundles all configuration files and source code modifications into a focused, easily reviewable update.
- Curated AI Engine: Grounds automated fixes in a proprietary, human-verified vulnerability database for accurate, trustworthy remediation.
- Automated Workflows: Delivers ready-to-merge code directly into the developer's Git environment.
“By enabling development teams to upgrade to safe open-source libraries automatically while addressing breaking changes with a single, testable update, we move organizations from seeing risk to actively eliminating it, strengthening the security of their software supply chains,” Jarrett closed.
To learn more about Veracode Fix and Application Risk Management platform, visit the Veracode website. Attendees of the 2026 RSA Conference, March 23-26, can see a live demonstration of Veracode Fix for SCA and sign up for the Early Access program by visiting booth #435.
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, Package Firewall, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2026 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260318932904/en/
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Only 7% of Companies Achieve Full Compliance as Global Expansion Increases Legal Complexity11.5.2026 15:00:00 CEST | Press release
47% of general counsels say beneficial ownership rules pose the biggest risks to legal operations44% lack confidence in meeting cross-border data security requirements As businesses accelerate their global expansion in 2026, compliance fails to keep pace. In fact, only 7% of organizations report full compliance across their global entities, according to a new study by CSC, the leading provider of global business administration and compliance solutions. CSC surveyed 350 general counsel (GCs) and senior legal professionals across Europe, North America, and Asia Pacific to examine how their teams navigate international expansion, regulatory pressure, and the increasing adoption of artificial intelligence (AI).¹ The findings appear in CSC’s latest report, General Counsel Barometer 2026: From Complexity to Control. Most organizations report partial compliance, with over half (53%) estimating they are 50–75% compliant, and a further 35% placing themselves between 76%–99%. This leaves just 7%
IFF Opens Vanilla Innovation Center in Madagascar11.5.2026 14:15:00 CEST | Press release
Advancing science‑led flavor innovation where vanilla is grown IFF (NYSE: IFF)—a global leader in flavors, fragrances, food ingredients, health & bioscience—today announced the opening of its Vanilla Innovation Center in Madagascar, reinforcing vanilla as a strategic and priority tonality for IFF and strengthening its ability to innovate at origin. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260508110162/en/ IFF's Vanilla Innovation Center in Madagascar “The opening of the center marks an important step in how we approach vanilla innovation,” said Adam Jańczuk, Ph.D., senior vice president, research, creation and design, Taste, IFF. “By strengthening our presence at origin, we connect science, creativity and sustainability more closely, responding to climate changes, safeguarding quality and creating value across the supply chain.” Located in Toamasina, Madagascar’s principal seaport, near vanilla growing areas and post‑h
ARIS Recognised as a Leader in Gartner® Magic Quadrant™ for Process Intelligence Platforms, Believes This Reinforces Its Role in Enabling Enterprise AI at Scale11.5.2026 14:00:00 CEST | Press release
ARIS, the process context foundation platform for enterprise AI deployment, today announced its recognition as a Leader in the Gartner® Magic Quadrant™ for Process Intelligence Platforms. This is the fourth consecutive year that ARIS has been recognized as a Leader in the report and the company believes it underscores a continued commitment to innovation and growth as enterprises focus on turning AI ambition into measurable business outcomes. While technology has advanced rapidly, companies are struggling to operationalise AI across complex operating models. ARIS sees this recognition by Gartner as a reflection of its strength in delivering a single unified platform for process intelligence, providing the context layer on which G2000 organisations can successfully deploy and scale agentic AI. “AI is moving from experimentation to execution – but many enterprises are finding it difficult to scale,” said Guillaume Bacuvier, CEO of ARIS. “The reason is simple: AI lacks the context it need
HistoSonics Moves to Advance Additional Histotripsy Applications Announcing FDA Submission for Kidney Tumors11.5.2026 14:00:00 CEST | Press release
HistoSonics, the developer of the Edison® Histotripsy System and novel histotripsy therapy platform, today announced it has submitted a De Novo request to the U.S. Food and Drug Administration seeking authorization to expand the use of its Edison® Histotripsy System to include the destruction of kidney (renal) tumors. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260511268688/en/ HistoSonics Edison® Histotripsy System This milestone marks a significant step forward in the company’s mission to transform the treatment of solid tumors with a completely non-invasive technology that harnesses focused ultrasound to mechanically liquefy and destroy targeted tissue, reducing the risk of many complications and side effects associated with surgery, radiation, and other common therapies. “This submission is an important milestone in expanding histotripsy beyond the liver and into the kidney, an area where patients and physicians are s
Logistics Reply Named a Visionary in 2026 Gartner® Magic Quadrant™ for Warehouse Management Systems and Ranks #2 for Level 2 and #3 for Level 3 Operations Use Cases in Gartner® Critical Capabilities Report11.5.2026 14:00:00 CEST | Press release
Logistics Reply, the Reply Group company specializing in innovative solutions for supply chain execution, is proud to announce its recognition as a Visionary in the Gartner® Magic Quadrant™ for Warehouse Management Systems for the seventh consecutive year, as its global team of warehouse technology professionals continues to drive innovation that puts customers first. Additionally, Logistics Reply for its LEA Reply™ WMS is recognized in the 2026 Gartner® Critical Capabilities for Warehouse Management Systems report where it ranked #2 for Level 2 Warehouse Operations and #3 for Level 3 Warehouse Operations. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260511344452/en/ We believe these important recognitions underscore Logistics Reply's commitment to delivering intelligent, flexible and scalable warehouse execution solutions for enterprise customers around the world. For us, our placement in the Visionaries Quadrant reflects
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom