Secure vulnerable images found in IaC templates with Bridgecrew Taylor Smith October 18, 2022October 17, 2022 Learn how to proactively identify and scan vulnerable images sourced in IaC and CI/CD files with Bridgecrew’s new Image Referencer capability. Product update
Full-stack code visibility with Bridgecrew’s Software Bill of Materials (SBOM) generation Taylor Smith October 5, 2022October 5, 2022 Learn how to get visibility into risk exposure and prevent supply chain attacks with Bridgecrew’s software bill of materials (SBOM) generation capabilities. Product update
The rise of software developers in cloud security Bridgecrew September 15, 2022September 15, 2022 Learn about the rise of developer-first cloud security that automates cloud-native security, simplifies permissions, and implements DevSecOps. DevSecOps
Using your pipelines to harden your pipelines: The importance of CI/CD security for your software supply chain Idan Tendler September 1, 2022 Learn how to shift your CI/CD security left to proactively harden your pipelines against software supply chain attacks. Cloud security DevSecOps
6 delivery pipeline security best practices for secure software supply chains Bridgecrew August 18, 2022August 18, 2022 Learn 6 VCS and CI/CD weaknesses that may leave your software supply chain vulnerable to attack and how to address them. Supply chain security
Checkov enables developer-first CI/CD security with new supply chain security policies Guy Eisenkot August 3, 2022September 20, 2022 Learn how you can embed CI/CD best practices into your existing DevOps workflows with Checkov’s new CI/CD security policies. Open source projects
How to prevent the 5 most common software supply chain weaknesses Bridgecrew July 28, 2022August 23, 2022 Learn the basics of software supply chain security and 7 best practices to protect yourself against common software supply chain weaknesses. DevSecOps
Checkov 2.1 roundup: Expanding into AppSec, supply chain security, and more Taylor Smith July 21, 2022August 22, 2022 Checkov 2.1 is packed with scanning support for new IaC frameworks, expanded supply chain and AppSec use cases, and more. Open source projects
Scaling in the cloud? IaC and DevSecOps are here to help Julia Benson July 14, 2022July 29, 2022 Learn how IaC and DevSecOps best practices can make working at scale in the cloud more agile, efficient, simple, and secure. DevSecOps Infrastructure as code
A primer on secure DevOps: Learn the benefits of these 3 DevSecOps use cases Julia Benson June 16, 2022August 23, 2022 Learn best practices and benefits of taking a DevSecOps approach to AppSec, IaC security, and software supply chain security. DevSecOps
5 ways K8s apps are vulnerable to supply chain attacks Payton O'Neal May 31, 2022July 29, 2022 Learn about 5 common security risks when working with Kubernetes apps. We’ll also walk through tips to help you secure your software supply chain. DevSecOps
Keep your software supply chain secure with these new VCS policies Barak Schoster April 4, 2022July 24, 2022 To help organizations enforce supply chain security best practices, Checkov and Bridgecrew now scan GitHub, GitLab, and Bitbucket configurations. Product update