Veracode Q4 2026 Product Updates

What's New in Application Security

Veracode is excited to share the latest innovations across the Veracode Application Risk Management Platform. This quarter brings significant advancements in automated remediation, developer experience, and security operations — all designed to help your teams build secure software faster.

 

Read our full page of updates here (requires Customer login): https://community.veracode.com/s/product-updates

 

Here's a teaser:

 

Key Launches

🔧 Veracode Fix for SCA (Software Composition Analysis)

Status: [Early Access Now Available]

Veracode Fix for SCA introduces automated remediation for supply chain vulnerabilities, helping your teams manage dependencies more efficiently. This intelligence engine analyzes your code context to suggest secure third-party library updates and first-party code refactoring — all without breaking your build.

 

Key Capabilities:

  • Automated Dependency Management: Receive ready-to-merge pull requests with all necessary changes for seamless library upgrades
  • Deep Contextual Analysis: Fix suggestions account for your specific application context to ensure compatibility
  • Pre-Commit Protection: Address vulnerabilities before they enter your codebase
  • Unified Fix Experience: Single SKU covering both SAST (Static Analysis) and SCA remediation

What it Means: Accelerate remediation workflows while reducing the manual effort required to maintain secure dependencies across your software supply chain.

Want to sign up for Early Access? Reach out to your account manager or CSM.

 

Learn More: Veracode Fix Updates

 

 

💻 Developer Experience Enhancements

 

Java Source Code Scanning

Status: [Now Available]

Scan Java applications directly from source code — no binary compilation required. This enhancement provides developers with additional flexibility in their security workflows.

What's New:

  • Native Java source code scanning across Static Analysis, CLI, and Autopackager
  • Choice of scanning approaches: source code, binary, or hybrid
  • Faster feedback cycles by eliminating build requirements

Supported Workflows: Static Analysis, CLI scans, and Autopackager (IDE and Repository integrations coming soon)

Learn More: Static Analysis Updates | CLI Updates

 


Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.