See for yourself – run a scan on your code right now

ShiftLeft, Inc., the leader in application security (AppSec) for developers, today announced that its NextGen Static Analysis (NG SAST) product is now available on GitHub Marketplace. Modern static application security testing (SAST) products need to be purpose-built for developers. NG SAST is designed to bridge the gap between AppSec and development teams. Now available as a free GitHub App, NG SAST enables extremely fast and highly accurate code analysis to be easily integrated into developer workflows in just a few clicks.

In the modern software development lifecycle (SDLC) developers perform the majority of the application security work, not traditional AppSec teams. ShiftLeft research found that developer productivity suffers greatly when using tools and processes not designed with software engineers in mind. ShiftLeft discovered that 96% of developers believe the disconnect between engineering and security workflows inhibits them. In order for AppSec to match the speed of the modern SDLC, security products must be built with developer engagement and productivity as the driving principles.

NG SAST is the most developer-friendly code analysis solution available today. Now that NG SAST is available through GitHub Marketplace, developers can make their own choices about which tools they adopt. Unlike other SAST products that require manual installation and setup, and at times even expensive professional services to integrate into an organization’s workflow, NG SAST’s GitHub App automates each step, making SAST self-serve for the first time in the industry.

NG SAST is the fastest scanning tool on the market, boasting speeds of up to 40X faster than competing products, and is able to scan 250,000 lines of code in under 30 seconds. NG SAST scans every pull/merge request, so individual developers get near-instantaneous security feedback about their code. With ShiftLeft’s NG SAST, developers never have to wait for security results, with most being returned in five minutes or less. This reduced wait time vastly minimizes the amount of context switching required by developers and increases remediation efficiency.

“At ShiftLeft, our priority is to help developers easily insert security into today’s modern software development lifecycle through holistic workflow experiences where security-related issues are highlighted in the same manner as quality of code, without impacting time-to-market,” said Manish Gupta, CEO, ShiftLeft. “Today, we are excited to welcome the GitHub developer community to leverage our developer-friendly NG SAST product for maximum efficiency and security. Our goal is to enhance developer productivity and security across every SDLC.”

GitHub Marketplace is a way to discover and purchase software tools that extend the developer workflow. The Marketplace offers tools that can find apps across the development process, from continuous integration to project management and code review.

For more information on ShiftLeft NG SAST, visit the ShiftLeft website. To access ShiftLeft NG SAST on the GitHub Marketplace, visit its listing page.

About ShiftLeft

ShiftLeft is the leading application security software provider for developers. Through industry-leading speed and accuracy, ShiftLeft maximizes developer productivity and efficiency by providing near-instantaneous security feedback on software code during every pull request. Its flagship NG SAST product is purpose-built to insert security directly into the modern software development lifecycle; as a result, developers receive the right vulnerability information at the right time. Backed by Bain Capital Ventures, Mayfield, Thomvest Ventures and SineWave Ventures, ShiftLeft is based in Santa Clara, CA.

To learn how ShiftLeft keeps AppSec in sync with the rapid pace of DevOps, see https://www.shiftleft.io/.

About ShiftLeft

ShiftLeft empowers developers and AppSec teams to dramatically reduce risk by quickly finding and fixing the vulnerabilities most likely to reach their applications and ignoring reported vulnerabilities that pose little risk. Industry-leading accuracy allows developers to focus on security fixes that matter and improve code velocity while enabling AppSec engineers to shift security left.

A unified code security platform, ShiftLeft CORE scans for attack context across custom code, APIs, OSS, containers, internal microservices, and first-party business logic by combining results of the company’s and Intelligent Software Composition Analysis (SCA). Using its unique graph database that combines code attributes and analyzes actual attack paths based on real application architecture, ShiftLeft then provides detailed guidance on risk remediation within existing development workflows and tooling. Teams that use ShiftLeft ship more secure code, faster. Backed by SYN Ventures, Bain Capital Ventures, Blackstone, Mayfield, Thomvest Ventures, and SineWave Ventures, ShiftLeft is based in Santa Clara, California. For information, visit: www.shiftleft.io.

Share

See for yourself – run a scan on your code right now