Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Development

    Synopsys Launches Polaris Software Integrity Platform

    Written by

    Sean Michael Kerner
    Published February 25, 2019
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Synopsys is bringing together its software integrity assets in a new offering aimed at helping organizations improve code quality, security and assurance.

      The Polaris Software Integrity Platform is being formally announced by Synopsys on Feb. 25, with the company planning on showcasing the new technology at the RSA Conference in San Francisco, which runs from March 4-8.  With Polaris, Synopsys is bringing together multiple technologies and product lines it already has into an integrated offering to help organizations with the entire developer and operations workflow, identifying code defects and security issues as well as providing risk reporting capabilities.

      “Polaris is really more than the sum of its parts, though under the hood it has the Coverity, Black Duck and Seeker engines,” Andreas Kuehlmann, general manager of the Synopsys Software Integrity Group, told eWEEK. “What we are working on now is synergy between the different technologies.”

      Synopsys has been growing its Software Integrity Group portfolio over the last five years with multiple acquisitions. Back in March 2014, Synopsys acquired static code analysis vendor Coverity and has steadily improved the technology in the years since then. In May 2015, Synopsys acquired the Seeker interactive application security testing (IAST) technology from Quotium. In November 2016, Synopsys acquired privately held security companies Cigital and Codiscope.  In November 2017, Synopsys acquired Black Duck Software for $565 million, providing software composition analysis capabilities that are used to help organizations understand and secure applications.

      Kuehlmann said that in Polaris the different software integrity technologies are brought together with a uniform reporting and user experience. He explained that the integration will, for example, enable Coverity static analysis technology to inform the Black Duck engine if there is a vulnerability in a piece of code and if that vulnerability can be exploited.

      “Part of the strategy is really that the different technologies help each other,” Kuehlmann said.

      Overall, Kuehlmann said Polaris is all about helping organizations improve the entire software development lifecycle. That begins at the IDE (Integrated Development Environment) level where developers are coding, and includes the CI/CD (continuous integration/ continuous deployment) DevOps workflow as well as staging and product environments.

      How Polaris Works

      Polaris consists of several components, with a central server at the core. Kuehlmann explained that the Polaris central server plugs into a CI/CD workflow such that it is an integrated part of the process every time a developer triggers a build or pushes something from a staging environment into production.

      Another core element of Polaris is the Code Sight IDE plugin that integrates with a developer’s coding workflow in an interactive and integrated approach. 

      “The moment you save the file in the IDE, Coverity kicks off in the background and populates your screen with anything it finds,” he said. “The outcome is that a developer can actually fix the majority of the defects earlier in the process when they are coding.”

      Consolidated Risk Reporting

      With the integrated backend technologies for different types of software analysis, Polaris also enables consolidated risk reporting.

      “What a risk-based approach really means is you need to find a way to holistically look at your application portfolio and be able to prioritize the different findings and among the different applications,” Kuehlmann said.

      Kuehlmann explained that Polaris provides an integrated view for risk from its own technologies, and is also set to be open to other integrations to provide a broader viewpoint. He said that the plan is to enable Polaris to be an open platform that will be able to integrate with multiple components.

      “We see Polaris as an open platform that not only uses our technology and can integrate with other technologies, but also as a platform where we look at security as well as quality, service and compliance,” he said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×