
Product Announcements — SamHouston (Veracode) asked a question.
What's New in Application Security
Veracode is excited to share the latest innovations across the Veracode Application Risk Management Platform. This quarter brings significant advancements in automated remediation, developer experience, and security operations — all designed to help your teams build secure software faster.
Read our full page of updates here (requires Customer login): https://community.veracode.com/s/product-updates
Here's a teaser:
Key Launches
🔧 Veracode Fix for SCA (Software Composition Analysis)
Status: [Early Access Now Available]
Veracode Fix for SCA introduces automated remediation for supply chain vulnerabilities, helping your teams manage dependencies more efficiently. This intelligence engine analyzes your code context to suggest secure third-party library updates and first-party code refactoring — all without breaking your build.
Key Capabilities:
- Automated Dependency Management: Receive ready-to-merge pull requests with all necessary changes for seamless library upgrades
- Deep Contextual Analysis: Fix suggestions account for your specific application context to ensure compatibility
- Pre-Commit Protection: Address vulnerabilities before they enter your codebase
- Unified Fix Experience: Single SKU covering both SAST (Static Analysis) and SCA remediation
What it Means: Accelerate remediation workflows while reducing the manual effort required to maintain secure dependencies across your software supply chain.
Want to sign up for Early Access? Reach out to your account manager or CSM.
Learn More: Veracode Fix Updates
💻 Developer Experience Enhancements
Java Source Code Scanning
Status: [Now Available]
Scan Java applications directly from source code — no binary compilation required. This enhancement provides developers with additional flexibility in their security workflows.
What's New:
- Native Java source code scanning across Static Analysis, CLI, and Autopackager
- Choice of scanning approaches: source code, binary, or hybrid
- Faster feedback cycles by eliminating build requirements
Supported Workflows: Static Analysis, CLI scans, and Autopackager (IDE and Repository integrations coming soon)
Learn More: Static Analysis Updates | CLI Updates
.png)