Black Duck’s product release round-up: faster fixes, smarter security
好的,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要通读整篇文章,抓住主要内容和关键点。 文章主要讲的是Black Duck产品的新更新,包括更快的扫描、更智能的优先级和更紧密的集成。这些更新帮助安全跟上现代开发的步伐。接着,文章详细介绍了几个新功能:Black Duck Security GitHub应用、Polaris平台的改进、自动化在CI/CD中的扩展、AI驱动的功能如Black Duck Assist,以及对软件供应链的支持。 我需要把这些要点浓缩到100字以内。首先,提到产品更新带来的更快扫描和智能集成。然后,涵盖GitHub应用、自动化、AI功能和供应链安全。最后,总结这些更新如何提升开发效率和安全性。 确保语言简洁明了,不使用复杂的术语,同时覆盖所有关键点。检查字数是否在限制内,并调整句子结构以优化表达。 </think> Black Duck产品更新包括更快扫描、智能优先级和紧密集成,提升开发与安全同步效率。新GitHub应用实现自动化扫描与问题修复,Polaris优化风险评分与治理功能。扩展CI/CD自动化支持主流平台,AI驱动修复与开发体验提升。软件供应链安全增强 SPDX 3.0 支持与语言扩展。 2025-10-27 12:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Your teams move fast—and your security needs to keep up.

This quarter, updates to the Black Duck portfolio include faster scans, smarter prioritization, and tighter integrations that keep security in step with modern development.

Cruise Con 2025

Watch the full video below for a deeper dive into everything new.

Security where you work

Developers live in GitHub, so we brought security to them.

The new Black Duck® Security GitHub app lets teams automate Black Duck Polaris™ Platform, Black Duck® SCA, and Coverity® Static Analysis scans directly within their repositories.

You can run SAST and SCA scans automatically on every commit, block risky merges with policies, and view findings right in pull requests—so issues are caught and fixed early.

The result: developers stay focused, AppSec gets visibility, and everyone ships faster.

From alert fatigue to action in Polaris

Polaris now helps teams cut through noise with better prioritization and governance.

New risk-scoring and policy filters highlight what’s truly exploitable, while issue exclusions and smarter SBOM editing reduce false positives.

Instead of chasing alerts, your teams can focus on what matters most—and fix it fast.

AppSec automation that keeps up with DevOps

Security shouldn’t slow your pipelines.

With expanded automation across Jenkins, GitHub, GitLab, Azure DevOps, and Bitbucket, Polaris fAST Dynamic now triggers scans automatically and enforces policy-based pass/fail gates. And with Coverity Fail Pull Requests Support in GitHub, risky code can be blocked before it ever gets merged.

That’s guardrails at release speed.

AI-powered fixes and smarter developer experience

Meet Black Duck Assist™, the AI AppSec companion built into Polaris and the Code Sight™ IDE Plug-in. Developers can now ask natural-language questions, get instant explanations of SAST findings, and generate AI-powered code fixes—right in the IDE.

AI also powers new capabilities in Seeker® Interactive Analysis and Defensics® Fuzzing, detecting prompt-injection and data-leak risks in LLM transactions and fuzzing tests.

Proof and performance across the software supply chain

Security doesn’t stop at code.

Black Duck SCA and Black Duck® Binary Analysis now supports SPDX 3.0 for audit-ready SBOMs, with sharper CVSS 4.0 scoring and expanded language support, including Rust and OpenWRT.

Software Risk Manager™ adds bulk triage, custom dashboards, and new version-management roles—so you can scale securely without the stress.

What this means for you

This quarter’s updates deliver

  • Security embedded where developers already work
  • Smarter prioritization and faster fixes
  • CI/CD automation that scales with your pipelines
  • AI-driven insights that boost developer speed and accuracy
  • Audit-ready visibility across your software supply chain
     

Learn more and explore every feature. Join the conversation in our Customer Community

*** This is a Security Bloggers Network syndicated blog from Blog authored by Black Duck Editorial Staff. Read the original post at: https://www.blackduck.com/blog/black-duck-product-updates-faster-fixes-smarter-security.html


文章来源: https://securityboulevard.com/2025/10/black-ducks-product-release-round-up-faster-fixes-smarter-security/
如有侵权请联系:admin#unsafe.sh