OpsMx
Ask or search…
K
Links
Comment on page

OpsMx Secure Software Delivery (SSD) - Release Notes

Version 2023.8.0

Introduction

Software supply chain attacks are on the rise and have become a critical concern for all organizations. The modern software delivery pipelines have become increasingly complex, and the threat landscape is continuously evolving. Therefore, a unified and proactive approach to security, risk management, and governance across the software delivery lifecycle is essential.
OpsMx Secure Software Delivery (SSD) is a solution that focuses on monitoring, alerting, preventing, and resolving security threats and vulnerabilities across the software delivery lifecycle. It seamlessly integrates with your DevOps ecosystem to gather and evaluate information against a set of secure software delivery practices and frameworks. This ensures that insecure application versions do not get released. The solution also keeps track of all actions, people, and process metadata related to software development, thereby enabling enterprises to meet their compliance requirements with ease.

Features

  • Ability to collect software delivery data from Git, Jenkins, Spinnaker, Kubernetes, and Aqua Trivy.
  • Supply chain dashboard - Helps you to view the organization-level security posture, applications and their risk status and security alerts.
  • Application status page - Displays the security status, active vulnerabilities, and alerts of the running services.
  • Alerts Management - Ability to track and resolve security alerts across environments with SSD suggestions.
  • SBOM - Generate software bill of materials for the deployed images.
  • DBOM - The Delivery Bill of Actions and Materials is a comprehensive report that offers complete visibility of the software development process, from coding to deployment. It keeps track of crucial information such as tools used, actions taken, artifacts produced, and security checks performed during the software delivery process. This report serves as a valuable tool to monitor and optimize software development.
  • Smart Diff - Helps you to dry run code promotion from one environment to another. By doing so, you can compare the services that run in different environments in terms of their security status, active alerts, vulnerabilities, and dependencies. This helps you understand the impact that a new version of a service may have when deployed to production.
  • Slack Integration - Ability to share alerts to Slack channels.

Version 2023.9.0

Features

  • Deployment Firewall - The Kubernetes cluster can now automatically block insecure application versions from being deployed by running an admission control mechanism. This decision-making is powered by SSD's security analysis and data collection throughout the software delivery lifecycle.
  • New SAST Integrations - SSD can now mandate SAST scans during software development, analyze reports to provide suggestions, and update the application's risk status by connecting to SonarQube and Semgrep.
  • Smart Search - The ability to discover vulnerabilities, images, and other components across all applications allows for easier identification of newly found vulnerabilities within existing applications.
  • OpenSSF Scorecard Integration - Connected git repositories will receive an OpenSSF scorecard with security posture alerts and suggestions accessible on the Manage Alerts Page.
  • NIST and FedRAMP Compliance Automation - SSD now includes prebuilt policies for NIST 800-53 and FedRAMP compliance, with suggestions for fixing issues and achieving 100% compliance.
  • Rules Genie - A new AI assistant that creates custom deployment firewall rules based on business requirements.
  • Alerts Genie - A new AI assistant that helps understand security alerts and recommends solutions.

Enhancements

  • Application level Smart Diff and Application DBOM - Users can now perform Smart Diff at the application level and view the Delivery bill of materials for the entire application version.
  • Search and filtering options - In the Alerts Management and Rules Configuration pages, you can access additional search and filtering options.

Version 2023.10.0

Features

  • Kubernetes Hardening Analysis
    • CIS Benchmark analysis for Kubernetes clusters - SSD automatically evaluates connected clusters for CIS Benchmark compliance using 200+ predefined deployment firewall rules. Kubernetes posture-related alerts and suggestions are available on the Manage Alerts Page.
    • "Additionally, it allows for the assessment of your clusters according to the guidelines provided by NSA-CISA and MITRE ATT&CK."
  • Jenkins Integration - SSD now supports Jenkins as a build and deployment tool, gathering information to improve security posture through alerts and recommendations.
  • Deployment History Timeline - The application status page now displays cluster deployments as a timeline graph, providing an audit trail and historical view of changes to cluster security posture.
  • Vulnerability Report - The application status page now displays vulnerability reports for both the application and service.

Enhancements

  • Added support for user-defined tags for deployment firewall rules, allowing users to group rules based on the custom logic.
  • Expanded the functionality of the smart search feature to include the alerts and vulnerabilities report page.
  • Added the ability to distinguish between alerts on the current and the old versions of running applications.
Last modified 28d ago