Company
Date Published
Author
Jaweed Metz
Word count
1409
Language
English
Hacker News points
None

Summary

Harness's Security Testing Orchestration (STO) is now generally available, offering automated security scans, intelligent vulnerability management, and customizable governance policies, all seamlessly integrated into CI/CD pipelines. This enables collaboration between developers and security teams to enhance secure software delivery without compromising current processes. Feedback from end users has led to new features that increase security throughout the software delivery process while maintaining high innovation velocity. Key capabilities include orchestrating multiple security scanners, managing security exemptions, providing comprehensive dashboards and reports, and establishing governance policies based on the Open Policy Agent (OPA). STO also offers enterprise-grade audit trails and role-based access control, allowing for detailed examination of security activities and efficient permissions management. By integrating with popular application security scanners and normalizing their outputs, STO helps prioritize vulnerabilities, thereby reducing rework and enhancing productivity and compliance. The solution is available as a standalone module or integrated with Harness CI/CD, offering flexibility for various deployment models.