2022-04-11T09:16:00Z

PeerSpot Users' DevOps and DevSecOps predictions 2022

NC
  • 29
Published:
Search for a product comparison in Software Composition Analysis (SCA)
PeerSpot user
0
PeerSpot user
Find out what your peers are saying about Synopsys, Snyk, Veracode and others in Software Composition Analysis (SCA). Updated: April 2024.
768,578 professionals have used our research since 2012.
Related Questions
Ariel Lindenfeld - PeerSpot reviewer
Dec 14, 2023
Dec 14, 2023
The complexity of the "software supply chain" has exploded and continues to grow. Think of the software product you buy as a car that has just rolled off the assembly line. While the car as you know it is branded by the automaker, many of the components within (i.e. brakes, batteries, tires, even software too) come from other providers. Likewise, software is a mix of proprietary source code cr...
See 1 answer
AB
Dec 14, 2023
The complexity of the "software supply chain" has exploded and continues to grow. Think of the software product you buy as a car that has just rolled off the assembly line.  While the car as you know it is branded by the automaker, many of the components within (i.e. brakes, batteries, tires, even software too) come from other providers. Likewise, software is a mix of proprietary source code created by the vendor, commercially licensed code, and open source code. Open source components have a wide-range of licensing styles with unique permissions and restrictions. This makes it difficult to generate a complete and accurate inventory of what is used in the software - a software bill of materials (SBOM).Just as it is very economic and productive for an automaker to use OEM suppliers, likewise, it is very smart for software developers to leverage open source software (OSS). Faster development, greater reliability, better user experiences, and more time to innovate are a few top benefits.But to take advantage of OSS projects, software developers need to manage both the legal and security risks inherent to integrating third-party components. Software Composition Analysis (SCA) brings order to the chaos by giving software developers confidence that they know what's in their code, that they are adhering to the OSS licenses, and that they can identify and remediate any security vulnerabilities. With the invention of AI-generated code, SCA has never been more critical to software vendors. SCA tools must be advanced enough to not only detect OSS components, but even identify code snippets belonging to OSS components that may have been copied-pasted from AI code generators like ChatGPT, GitHub CoPilot, or Google's AlphaCode 2 to name a few.SCA also requires expertise.  Skilled and knowledgeable open source auditors are necessary to fully leverage the tools, make accurate identifications and classifications, and assess risk levels.
Avigayil Henderson - PeerSpot reviewer
Feb 24, 2023
Feb 24, 2023
When you say centralized view, do you mean different testing categories which should be looked at for matured software development? If yes, sharing my views on important ones. 1. Functional Testing (either using open source frameworks like playwright, cypress, and selenium or using a platform approach like Katalon, Tricentis, SmartBear). 2) Performance and Load Testing 3) Chaos Engineering ...
See 1 answer
VG
Feb 24, 2023
When you say centralized view, do you mean different testing categories which should be looked at for matured software development? If yes, sharing my views on important ones.  1. Functional Testing (either using open source frameworks like playwright, cypress, and selenium or using a platform approach like Katalon, Tricentis, SmartBear).  2) Performance and Load Testing  3) Chaos Engineering  4) Security Testing which includes SCA, SAST, DAST, checking IaaC scripts, checking K8 clusters, docker images  5) Accessibility Testing to comply with WCAG guidelines  6) API testing
Download Free Report
Download our free Software Composition Analysis (SCA) Report and find out what your peers are saying about Synopsys, Snyk, Veracode, and more! Updated: April 2024.
DOWNLOAD NOW
768,578 professionals have used our research since 2012.