industry news
Subscribe Now

Synopsys Advances Application Security Testing for Developers with Rapid Scan

New Rapid Scan Capabilities in Coverity SAST and Black Duck SCA Help Development Teams Secure Cloud-native Applications as Fast as They Write Them

MOUNTAIN VIEW, Calif., July 27, 2021 /PRNewswire/ — Synopsys, Inc. (Nasdaq: SNPS) today announced the availability of new Rapid Scan capabilities within the company’s Coverity static application security testing (SAST) and Black Duck software composition analysis (SCA) solutions. The Rapid Scan features provide fast, lightweight vulnerability detection for both proprietary and open source code. Rapid Scan is optimized for the early stages of development, particularly for cloud-native applications and infrastructure-as-code (IaC).

While comprehensive and thorough security testing is critical to managing risk in the later stages of the software development lifecycle (SDLC), it is often too time- and resource-intensive to perform full scans at every incremental step in the early stages of the SDLC. Rapid Scan complements conventional application security testing activities by enabling development teams to perform fast SAST and SCA scans at every code check-in or early-stage build without slowing them down. It allows developers to shift left efficiently and prevents security issues from propagating into the later stages of the SDLC.

“One of the hallmarks of modern software development is breaking down large processes into smaller, more manageable tasks that can performed rapidly and concurrently in a distributed fashion,” said Jason Schmitt, general manager of the Synopsys Software Integrity Group. “For organizations embracing DevSecOps, application security testing needs to follow suit. With Rapid Scan, Coverity and Black Duck users can run quick preventative scans to detect and eliminate surface-level vulnerabilities as their developers write and commit code, and they can use the same solutions to run deep scans later in the SDLC prior to deploying their applications.”

The new capabilities include:

Coverity Rapid Scan. The new Rapid Scan capabilities of Coverity SAST provide fast security analysis of proprietary code at the developer’s desktop and in continuous integration (CI) pipelines such as GitLab and GitHub Actions. Coverity Rapid Scan is optimized for cloud-native applications built on infrastructure-as-code frameworks such as Kubernetes, Terraform, and CloudFormation, and microservices such as GraphQL, Kafka, and Postman. Rapid Scan can quickly detect many of the most common security weaknesses, as well as problematic misconfiguration flaws and API misuses.

Black Duck Rapid Scan. The Rapid Scan capabilities of Black Duck SCA allows developers and release managers to perform fast dependency analysis to determine if any of the open source components in their application violate their organization’s security and license policies prior to merging code into release branches. Black Duck Rapid Scan is optimized for speed and efficiency by providing developers with early insight into dependency risk and by deferring resource-intensive SCA activities such as multi-factor open source detection and generating a complete software bill of materials to later stages of the SDLC.

Intelligent Orchestration and Rapid Scan. The Coverity and Black Duck Rapid Scan capabilities can be used in conjunction with Synopsys’ Intelligent Orchestration solution to automatically trigger fast SAST and SCA scans based on events in the continuous integration (CI) pipeline. Intelligent Orchestration, which enables DevOps teams to run the right security tests at the right time, can leverage Rapid Scan at early stages in the pipeline when speed and efficiency are critical, and it can run full Coverity and Black Duck scans at later stages in the pipeline when validating the quality and security of applications prior to deployment.

To learn more about Rapid Scan for Coverity and Black Duck, read the blog post.

About the Synopsys Software Integrity Group

Synopsys Software Integrity Group helps development teams build secure, high-quality software, minimizing risks while maximizing speed and productivity. Synopsys, a recognized leader in application security, provides static analysis, software composition analysis, and dynamic analysis solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Synopsys helps organizations optimize security and quality in DevSecOps and throughout the software development life cycle. Learn more at www.synopsys.com/software.

About Synopsys

Synopsys, Inc. (Nasdaq: SNPS) is the Silicon to Software™ partner for innovative companies developing the electronic products and software applications we rely on every day. As an S&P 500 company, Synopsys has a long history of being a global leader in electronic design automation (EDA) and semiconductor IP and offers the industry’s broadest portfolio of application security testing tools and services. Whether you’re a system-on-chip (SoC) designer creating advanced semiconductors, or a software developer writing more secure, high-quality code, Synopsys has the solutions needed to deliver innovative products. Learn more at www.synopsys.com.

Leave a Reply

featured blogs
Apr 24, 2024
Diversity, equity, and inclusion (DEI) are not just words but values that are exemplified through our culture at Cadence. In the DEI@Cadence blog series, you'll find a community where employees share their perspectives and experiences. By providing a glimpse of their personal...
Apr 23, 2024
We explore Aerospace and Government (A&G) chip design and explain how Silicon Lifecycle Management (SLM) ensures semiconductor reliability for A&G applications.The post SLM Solutions for Mission-Critical Aerospace and Government Chip Designs appeared first on Chip ...
Apr 18, 2024
Are you ready for a revolution in robotic technology (as opposed to a robotic revolution, of course)?...

featured video

MaxLinear Integrates Analog & Digital Design in One Chip with Cadence 3D Solvers

Sponsored by Cadence Design Systems

MaxLinear has the unique capability of integrating analog and digital design on the same chip. Because of this, the team developed some interesting technology in the communication space. In the optical infrastructure domain, they created the first fully integrated 5nm CMOS PAM4 DSP. All their products solve critical communication and high-frequency analysis challenges.

Learn more about how MaxLinear is using Cadence’s Clarity 3D Solver and EMX Planar 3D Solver in their design process.

featured paper

Designing Robust 5G Power Amplifiers for the Real World

Sponsored by Keysight

Simulating 5G power amplifier (PA) designs at the component and system levels with authentic modulation and high-fidelity behavioral models increases predictability, lowers risk, and shrinks schedules. Simulation software enables multi-technology layout and multi-domain analysis, evaluating the impacts of 5G PA design choices while delivering accurate results in a single virtual workspace. This application note delves into how authentic modulation enhances predictability and performance in 5G millimeter-wave systems.

Download now to revolutionize your design process.

featured chalk talk

Electromagnetic Compatibility (EMC) Gasket Design Considerations
Electromagnetic interference can cause a variety of costly issues and can be avoided with a robust EMI shielding solution. In this episode of Chalk Talk, Amelia Dalton chats with Sam Robinson from TE Connectivity about the role that EMC gaskets play in EMI shielding, how compression can affect EMI shielding, and how TE Connectivity can help you solve your EMI shielding needs in your next design.
Aug 30, 2023
28,662 views