Wednesday, September 27, 2023
News
NEWS HOME
»
PRN INDIA
Mend.io Announces Integration of Crowdsourced Renovate Data to Reduce Open Source Attack Surface Risk Up to 80 Percent
  SocialTwist Tell-a-Friend  
   

Mend SCA now enables full automation of high-confidence open-source updates without 'breaking the build'

TEL AVIV, Israel and BOSTON, June 5, 2023 /PRNewswire/ -- Mend.io, a leader in application security, today announced the integration of crowdsourced data from Mend Renovate, its popular open source dependency update automation tool with more than one billion Docker pulls, with Mend SCA. The enhancement automates code dependency updates at unprecedented rates. This will help organizations to dramatically lower application security risk, keep software components up to date, and confidently merge updates to ensure fast, reliable, and sustainable application development and deployment. Recently positioned by Gartner as a Visionary in the 2023 Magic Quadrant for Application Security Testing*, Mend.io will showcase this new capability at the Gartner Security & Risk Management Summit 2023, June 5-7, at booth #1155.  

The trend toward more, smaller open-source software packages and more frequent updates has resulted in a backlog of vulnerabilities that security teams struggle to manage manually, even for minor and patch updates with high compatibility. From a security perspective, more than 85 percent of vulnerabilities already have a fix available before they are published in the National Vulnerability Database (NVD). Yet the majority of organizations struggle to update to newer, patched versions. As they linger, older vulnerabilities can become more dangerous and more easily exploited. In 2021, three out of every four attacks were launched through vulnerabilities that were at least four years old.

While it's easier than ever to scan applications and find out-of-date or vulnerable components, making the necessary updates is what matters. Now, Mend SCA has a way to automate remediation of high-confidence updates to reduce security debt without breaking the build.

"This is a North Star aligned achievement for Mend.io. We are proud to introduce capabilities to proactively update the code base to make it less vulnerable," said Rami Sass, CEO of Mend.io. "By leveraging Renovate data in this way, we enable levels of automation that are simply not possible to achieve with other tools in the market."

Mend SCA takes a unique, preventative approach to application security, automating dependency updates to reduce security debt without the need for manual effort.

Using data gathered from over 25 million dependency updates tracked by Renovate, Mend SCA can determine which updates are likely to break a build, enabling teams to confidently deploy changes without slowing the development pipeline.

Mend.io provides this automation via its proprietary confidence algorithms from crowdsourced Renovate data. Confidence is based on three factors:

  • Did the update pass tests without breaking builds?
  • How old is the update?
  • How widely adopted is it?

Join Mend.io at the Gartner Security & Risk Management Summit
Mend.io will discuss its preventative approach to application security leveraging Mend Renovate data at the Gartner Security & Risk Management Summit 2023, booth #1155, June 5-7. Additionally, Sam Quakenbush, senior director of field innovation and strategy at Mend.io, will speak on open source software security best practices.  

Title: Effective SBOMs and Beyond: How to Create a Best-In-Class Open Source Security Program

Abstract: Applications are now the number-one attack vector. Open source software now comprises more than 70 percent of most applications. Supply chain attacks increased 650 percent from 2020 to 2021. If you don't already have an effective open source security program, you need to get one. Learn best-in-class programs and processes to reduce your attack surface, detect malicious open source packages, and respond quickly and with ease to the next Log4j-style announcement.

When: Monday, June 5th, 1:55 - 2:15 p.m.
Where: Theater 4

About Mend.io
Mend.io, formerly known as WhiteSource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks. With a proven track record of successfully meeting complex and large-scale application security needs, Mend.io is the go-to technology for the world's most demanding development and security teams. The company has more than 1,000 customers, including 25 percent of the Fortune 100, and manages Renovate, the open source automated dependency update project. For more information, visit www.mend.io, the Mend.io blog, and Mend.io on LinkedIn and Twitter.

* Gartner, "Magic Quadrant for Application Security Testing," Authors Dale Gardner, Mark Horvath, Dionisio Zumerle, [17th  May 2023].

CONTACT: Crystal Monahan, mend@guyergroup.com

Cision View original content:https://www.prnewswire.co.uk/news-releases/mendio-announces-integration-of-crowdsourced-renovate-data-to-reduce-open-source-attack-surface-risk-up-to-80-percent-301841742.html

More News by PR Newswire India

Digital Prosperity Awards Garner Global Recognition with Hundreds of Submissions

ViewSonic Develops Comprehensive EDLA Lineup with New ViewBoard IFP52-2 Series

SAP Announces New Generative AI Assistant Joule

Shanghai Electric Showcases Multiple World-Class Scientific and Technological Innovations at the China International Industrial Fair 2023 in Shanghai

Pixalate's H1 2023 EMEA Mobile App Ad Supply Chain Report: 39% Mobile Open Programmatic Ad Revenue in Europe Attributed to Cyprus-based Developers

Pixalate Releases H1 2023 EMEA Connected TV (CTV) Ad Supply Chain Report: 58% YoY Decline in Open Programmatic CTV Ad Spend

InterGlobix wins Fast-Growing Company Award at the Second Annual Incredible Inc. 50 Awards

Are We Stuck in a 'Travel Bubble'? Travel Habits Exposed in Global Survey

Bison Development Unveils Glenhill - Ultra-Luxury, Contemporary Homes Coming Soon to Raleigh

CGTN: How does China act to build a global community of shared future?

RocketReach introduces AI-powered features and unprecedented data quality

First-of-its-Kind Net-Zero Carbon Life Sciences & Tech Facility Coming to Boulder, Colorado

New Version of Solace Event Portal Software Enables Unprecedented Visibility, Management and Control of Apache Kafka Deployments

The Power of Integration: Plesk and Sitejet Revolutionize Website Design and Management for Web Professionals, SMBs, and Agencies

BICES 2023: XCMG Machinery Takes Center Stage with Intelligent and Eco-Friendly Construction Machinery

Infosys collaborates with Microsoft to accelerate and democratize industry-wide adoption of generative AI

ACX's technology to power Indonesia Carbon Exchange

Bitget's Smart Portfolio Bot Enables Sophisticated Crypto Trading For Users

CMF by Nothing Unveils Debut Products

SAMCO launches its Trade API: Pioneering Algo Trading for Large-Volume Traders

Clarivate Establishes Academia & Government Innovation Incubator and Acquires Alethea, an AI Student Engagement Solution

Kavalan Secures 4th Consecutive ISC World Whisky Producer Title

iMocha, alongside other partners, wins the 'Best Catalyst - Culture and Talent' Award at TM Forum's Digital Transformation World (DTW) 2023

HIVENTURES INVESTS IN HUNGARIAN STARTUP THAT CREATES A FUTURE WITHOUT BARRIERS

Mango TV's Reality Show Call Me By Fire 3 Goes Viral, More International Artists Seeking to Perform in China

Clean-Tech Innovator, ReCircle, Raises Pre Series-A Round from Flipkart Ventures, 3i Partners & Acumen Fund Inc. to Fuel Innovation & Growth

11th White Page Leadership Conclave 2023, Dubai UAE featuring Global Inspirational Leaders, Asia's Women Power Leaders, Global Power Leaders 2023, and Power List (Brands) 2023

LyondellBasell Demonstrates Commitment to Sustainability with Launch of +LC (Low Carbon) Solutions

Brambles' 2023 Sustainability Review: Pathway to Regeneration

Luxury, Art, and Stardom in the spotlight at The Chanakya with an exclusive Art exhibit by Masha Art.

Stockify goes fully Digital, offers Mutual Funds and Dematerialization of shares

VIVOTEK Supports Taiwan-Owned Entity in Elevating Building Security & Surveillance Efficiency in the USA

SOAS and Asian International Arbitration Centre, Malaysia, sign Memorandum of Understanding and host London International Arbitration Colloquium

CGTN: 'Everyone's contributor': How China advances common prosperity through opening-up, rural revitalization

Global Times: China's strength, confidence and hospitality on full display at 19th Asian Games

Cignal TV taps Quickplay platform for Pilipinas Live global sports app

Fiera Capital Celebrates Its 20th Anniversary

THE GLEN GRANT DEVOTION 70-YEAR-OLD SELLS FOR £81,250 ($101,300 USD) AT AUCTION WITH PROCEEDS TO BENEFIT THE ROYAL SCOTTISH FORESTRY SOCIETY

Arçelik showcases climate action commitments at UN General Assembly with ambitious sustainable development goals

PRADA SPRING/SUMMER 2024 WOMENSWEAR SHOW

Boehringer Ingelheim India joins forces with Pet Practitioners Association of Mumbai (PPAM) and Brihanmumbai Municipal Corporation (BMC) to 'Stop Rabies' in Mumbai

Supermicro Introduces New All-in-One Open RAN System Optimized for Telco Edge Data Centers with Built-in Intel vRAN Boost

NBA DELIVERS MOST-WATCHED SEASON EVER IN INDIA WITH MORE THAN 100 MILLION UNIQUE VIEWERS ACROSS LINEAR AND DIGITAL PLATFORMS

71% of senior business technology decision makers are disappointed with B2B marketing content

Overloaded: 89% of Indian consumers think there are 'too many' subscription services to choose from now

EU group names Trina Solar Decarbonisation Leader

Huawei Accelerates the Commercial Market Advancement and Helps SMEs Go Digital and Intelligent

Senores Pharmaceuticals, Inc. announces the launch of Nicardipine Hydrochloride Capsules USP, 20 mg and 30 mg in the U.S. market

"From Ziquejie Terraces to the World" - An Invitation for Reaching the Ziquejie Consensus on Terrace Preservation and Development to the World

Huawei's Brand-New Digital and Intelligent Foundation Upgrades Aviation and Rail Industries

Cashfree Payments partners with Shopify to launch onsite payments for Indian merchants

EQT PRIVATE EQUITY TO SELL LIMACORPORATE TO ENOVIS: THE ITALIAN SITE IN SAN DANIELE DEL FRIULI WILL REMAIN THE FULCRUM OF PRODUCTION, BENEFITING FROM NEW INVESTMENTS

Celebrating the Grand Opening of Doo Group's New Hong Kong Office: A Promising Start to an Exciting Future

Huawei Launches the Global Intelligent Education Showcase to Accelerate Digitalization in Education

Xinhua Silk Road: China int'l service trade fair highlights new features of China's trade, open economy

Over 20,000 avail benefit at free mega health camp organised by Chandigarh Welfare Trust to celebrate 73rd birthday of PM Modi

Huawei Accelerates Intelligent Healthcare with the Innovative Digital Medical Technology Solution

Huawei High-Quality 10 Gbps CloudCampus Accelerates Intelligent Transformation Across Industries

Hexaware Appoints Anton Tomchenko as Chief Revenue & Solutions Officer for Digital & Software Services

Xinhua Silk Road: Dev't index witnesses progress of int'l shipping center construction in Shanghai

Pierre Fabre Laboratories and Vernalis announce a drug discovery collaboration in oncology

Religare Broking Takes A Global Leap to Serve NRIs: Hosted IGI Conference in Dubai

Artmarket.com: France obtains the maintenance of VAT at the reduced rate of 5.5% on the Art Market, a major victory with very considerable advantages according to Artprice.

Safer, Inclusive Schools Critical for Children's Learning: Coalition for Good Schools

LRQA verifies Bridgestone's plant in India as carbon neutral against international standard PAS 2060

A23 launches new brand campaign featuring Shah Rukh Khan; Unveils new A23 Poker app

VVDN Technologies and Axiado Collaborate on Open Compute Platform Compliant data center and Telco O-RAN servers

Huawei Upgrades the CloudWAN 3.0 Solution, Accelerating the Intelligent Era

Redefine Security with the All-New Huawei HiSec Intelligent Security Portfolio and the Powerful HiSec SASE Security Solution

Huawei Launches Three Product Portfolios for the Commercial Market to Build High-Quality Connections

GET THAT 'CAN'T WAIT TO WINTER' FEELING IN ABU DHABI

Come Discover Colorful Guiyang featuring "Thousand Parks, Thousand Paths"

Casio to Release League of Legends G-SHOCK Watches

Campus With A Conscience hosts a week-long UN festival

France Announces €40 Million in New Funding to Education Cannot Wait at Global Citizen Festival

CGTN: 'Heart to Heart': How can Hangzhou Asiad boost unity, friendship across Asia?

Education Icon Awards 2023 organized by Kiteskraft Productions LLP

Office of the Executive Committee of the WMC: Anhui Strengthens Scientific and Technological Innovation Capacity to Attract Multinational Enterprises

SAUDI ARABIA UNVEILS TOP TOURISM LEADERS AND GLOBAL MINISTERS IN SPEAKER LINEUP FOR WORLD TOURISM DAY 2023

TECNO Globally Launches PHANTOM V Flip 5G: Representing Flip in Style and Perfect in Pocket

 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
INDIA WORLD ASIA
BJP is a party of workers, whatever res...
MP: Police register FIRs against 25 name...
UP: CM Yogi instructs to appoint additio...
Uttarakhand: 107 Pakistani pilgrims arri...
'Indo-Pacific construct has come to occu...
PM Modi to distribute 51,000 appointment...
More...    
 
 Top Stories
'The Association' founding member, ... 
Delhi CM Kejriwal to announce Winte... 
Salman Khan to bring “Tiger ka mess... 
Political convenience must not dete... 
Northern Zonal Council meet: CM Kha... 
Bombay HC grants 28 days of furloug... 
Afghan women on brink of losing fin... 
Amit Shah holds meeting with Punjab...