+44 (0)1249 700551 info@eoheurope.com

EOH work with Micro Focus Fortify and Sonatype to Deliver 360 Degree View of Application Security

In today’s world, we know that most security breaches occur because of application vulnerabilities. We also know that most typical software applications are, on average, comprised of 85% open source software. These facts are changing the way enterprises are thinking about security overall, and makes open source libraries a critical dimension of any serious application security initiative.

The need to understand both custom and open source code, in a holistic way, is exactly why Micro Focus and Sonatype are coming together in partnership and powering a best-in-class, fully integrated application security platform for all Fortify customers. 

This new partnership, which promotes Sonatype as Fortify’s preferred Software Composition Analysis (SCA) partner, delivers Micro Focus’s Fortify on Demand or On Premise (Fortify SSC) customers the advantages of a single, fully integrated application security platform, without compromising depth and capability in managing open source risk and vulnerabilities.

Application Security as a Service

Fortify software composition analysis, now powered by Sonatype, provides Micro Focus customers with greatly expanded SCA coverage. Sonatype uses artificial intelligence, machine learning, and human curation to identify open source software security vulnerabilities. This significantly expands component intelligence in depth and breadth beyond name matching files listed in the NVD (National Vulnerability Database). Sonatype’s SCA platform is continuously updated as open source projects, GitHub commits, advisory websites, and other vulnerability sources are examined. Security monitoring is ongoing and automatic.

Benefits for Dev and Sec

Fortify simplifies the onboarding and scanning process by combining static and composition analysis into a single integration point, whether that’s in the IDE or CI/CD pipeline. The comprehensive software bill-of-materials, including security vulnerabilities and license details, is delivered as a fully integrated experience for security professionals and developers alike.

Key features and updates include:

Simultaneously run SAST and SCA analysis
Supports Java, .NET, JavaScript and Python
Integrated results deliver one platform for remediation, reporting and analytics
Examines fingerprints of over 65 million components – not file names and package manifests
Detects 70% more vulnerabilities than the NVD database alone

Get an inside look at how to use Sonatype’s open source security capability with Micro Focus Fortify:

Other News

ALM Octane with UFT and Git Integration Integrating UFT with Source Control and ALM Octane

In this blog we have a couple of videos that were captured from a series of Webinars we delivered. These look at how we can use UFT with source control (Git & GitHub) as well as integrating UFT into Microficus’ new ALM Octane. The first video concentrates on using...

Test Automation with ALM Octane, Jenkins, GitHub & Selenium

DevOps & Continuous Integration with ALM Octane. This webinar demonstrates using Microfocus' ALM Octane, Jenkins, GitHub and Selenium WebDriver Java with Cucumber to provide a full end-to-end C.I. approach to automated testing.EOH Europe is a specialist in...

How can we help?

 
Contact Us