→ Back to Home
Containerization

Black Duck Polaris Enhances Container Security with Automated Remediation and Smarter Vulnerability Triage

Synopsys has rolled out a series of impactful updates to its Black Duck Polaris platform, specifically targeting the challenges of container security in today's rapid development environments. The enhancements are centered around two core areas: automating the remediation of identified vulnerabilities and providing smarter, more efficient vulnerability triage processes. This is particularly crucial for organizations leveraging containerization, as open-source components are ubiquitous and often introduce security risks. One of the standout new features is the introduction of automated fix pull requests. This capability allows Black Duck Polaris to automatically generate and submit pull requests for vulnerable open-source dependencies directly to source code management (SCM) systems such as GitHub, GitLab, Bitbucket, and Azure DevOps. This automation significantly reduces the manual effort and time traditionally required to investigate and patch security flaws, transforming security findings into actionable code changes with minimal developer intervention. The system ensures that human oversight remains in place for approval before any changes are merged, balancing automation with control. Beyond automated fixes, the platform also boasts smarter vulnerability triage. This is vital given the escalating rate at which new vulnerabilities are disclosed. The updated Polaris helps security and development teams keep pace by providing more intelligent ways to prioritize and manage these findings. This includes enhanced capabilities for Dynamic Application Security Testing (DAST), particularly for internal applications. The new DAST features allow for scanning applications on private networks or behind firewalls, which were previously difficult to assess comprehensively. A single Polaris secure tunnel can now serve multiple DAST scans simultaneously, eliminating per-project setup overhead and making enterprise-scale on-premise DAST practical. These improvements are integrated consistently across the Polaris platform, meaning that on-premises DAST results flow into the same issue model, dashboards, policies, and reports as cloud-based scans. This unified approach ensures a cohesive view of an organization's security posture. By automating remediation and refining triage, Synopsys aims to empower development and security teams to deliver thoroughly tested software, close security gaps proactively, and build a more resilient security program against increasingly sophisticated, AI-powered attacks.
#container security#vulnerability management#devsecops#automated remediation#open source security#dast
Read original source