Company
Date Published
Author
Pritesh Chandaliya
Word count
274
Language
English
Hacker News points
None

Summary

Harness has partnered with Wiz, a leading cloud security provider, to integrate Wiz's scanning capabilities into the Harness Security Testing Orchestration (STO) module, making it the first CI/CD platform vendor to do so. This integration allows developers to incorporate Wiz's Infrastructure as Code (IaC), Static Application Security Testing (SAST), Secret Detection, Container, and Software Composition Analysis (SCA) scans directly into their pipelines. The partnership aims to enhance security by enabling developers to detect secrets, identify misconfigurations, and address vulnerabilities within pull requests, while also reducing alert fatigue through deduplication and prioritization. Harness users can block pipelines based on vulnerability severity and automatically remediate issues using the Harness AI Developer Assistant (AIDA). This collaboration emphasizes a developer-friendly approach to security by shifting left, ensuring vulnerabilities are managed proactively within the development workflow.