Digital Media Net - Your Gateway To Digital media Creation. News and information on Digital Video, VR, Animation, Visual Effects, Mac Based media. Post Production, CAD, Sound and Music
Categories: MacNews

GrammaTech CodeSentry 4.0 Enables Developers to Identify Security Vulnerabilities Hidden in Third Party Code

Binary Software Composition Analysis Platform Closes Security Gap in Pre-Built Software without Access to Source Code

BETHESDA, Md.–(BUSINESS WIRE)–#AppSecGrammaTech, a leading provider of application security testing products and software research services, today announced a new version of its CodeSentry software supply chain security platform which enables organizations to detect security vulnerabilities contained in third party code. CodeSentry uses binary software composition analysis (BSCA) to identify known threats (CVEs) and common weakness enumeration (CWE) errors in externally developed software components without access to source code.

While the bulk of the industry’s attention has focused on vulnerabilities in open source software (OSS) with initiatives like OpenSSF, an equally important problem remains. According to VDC Research, nearly 60% of software products contain third-party code, most of which uses open source components under the hood. Since this pre-built code is delivered in binary format, organizations lack the ability to detect security risks it contains prior to using it to develop applications or embedding it in physical products such as automobiles, medical devices and more.

To detect vulnerabilities in third-party or pre-built code during the development process, CodeSentry 4.0 provides comprehensive support for desktop and mobile applications, firmware, containers, and embedded operating systems.

“Software development teams are increasingly being tasked with ensuring the integrity of their products by avoiding security and safety defects that can lead to costly product failures or recalls,” said Mike Dager, CEO of GrammaTech. “This security concern has even escalated the creation of regulatory requirements for the software supply chain from the FDA and the recent presidential Executive Order. CodeSentry 4.0 makes it possible for organizations to verify the contents, security and safety of third-party software components they use to build their products.”

Securing Third Party Code from the Inside Out

Since source code is rarely available for third party software, binary analysis is an emerging alternative for extracting a software bill of materials (SBOM) to identify components, dependencies and security vulnerabilities they may contain. Offered as a SaaS or on-premises solution, CodeSentry automates this process – providing a foundation for improving software supply chain security.

CodeSentry 4.0 provides the broadest coverage of any binary SCA platform that includes:

  • Desktop, Server and Mobile platforms: Windows, Linux, macOS, Java, Android and iOS
  • Language Support: Python, JavaScript and binaries originating from: C/C++, C#, Java and Go
  • Embedded OSes: VxWorks, QNX and Android
  • CPU Architectures: x86, ARM32/64, MIPS and AVR32
  • File Formats: Embedded and Firmware Filesystem Image Formats, Mobile File Formats, Docker containers, and Python and Javascript Packages
  • Supports multiple SBOM formats including SPDX and CycloneDX

Availability

GrammaTech CodeSentry 4.0 is available immediately from GrammaTech and its business partners worldwide.

About GrammaTech

GrammaTech is a leading global provider of application security testing (AST) solutions used by the world’s most security conscious organizations to detect, measure, analyze and resolve vulnerabilities for software they develop or use. The company is also a trusted cybersecurity and artificial intelligence research partner for the nation’s civil, defense, and intelligence agencies. GrammaTech has corporate headquarters in Bethesda MD, a Research and Development Center in Ithaca NY, and publishes Shift Left Academy, an educational resource for software developers. Visit us at https://www.grammatech.com/, and follow us on LinkedIn and Twitter.

CodeSonar® and CodeSentry® are registered trademarks of GrammaTech, Inc.

Contacts

Media Contact:

Marc Gendron

Marc Gendron PR for GrammaTech

617.877.7480

marc@mgpr.net

Staff

Recent Posts

Furiosa: A Mad Max Saga (Original Motion Picture Soundtrack) Music by Tom Holkenborg Available May 17th

First Single “Dementus Is Gaining” Available Now Album Art (For Media Use): DownloadLOS ANGELES--(BUSINESS WIRE)--WaterTower…

13 hours ago

Southwestern Energy Announces First Quarter 2024 Results

SPRING, Texas--(BUSINESS WIRE)--Southwestern Energy Company (NYSE: SWN) today announced financial and operating results for the…

1 day ago

HOMAGE Announces Ryan Reynolds’ Maximum Effort Investments as Lead Strategic Investor in Growth Capital Round

COLUMBUS, Ohio--(BUSINESS WIRE)--HOMAGE, Inc., a leading vintage-inspired sports and licensed apparel company, today announced a…

1 day ago

The Indy Autonomous Challenge Returns to the Indianapolis Motor Speedway on September 6, 2024

INDIANAPOLIS--(BUSINESS WIRE)--The Indy Autonomous Challenge (IAC) will make a grand return to the Indianapolis Motor…

2 days ago

Quad introduces new creative agency: Betty

Named after the late Betty Quadracci, co-founder of Quad, the new creative agency will offer…

2 days ago

RSAC 2024: Genians NAC-Driven ZTNA Leads Zero Trust Security Journeys

SAN JOSE, Calif.--(BUSINESS WIRE)--#Authentification--Genians, a pioneer in Zero Trust Network Access (ZTNA) powered by industry-leading…

2 days ago