VOOZH about

URL: https://thenewstack.io/veracodes-sbom-api-simplifies-software-security-for-devs/

⇱ Veracode’s SBOM API Simplifies Software Security for Devs - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-08-17 09:02:27
Veracode’s SBOM API Simplifies Software Security for Devs
Security / Software Development

Veracode’s SBOM API Simplifies Software Security for Devs

Veracode has tweaked its app dev security platform to offer a Software Bill of Materials (SBOM) API that makes it easier to provide visibility for developers when using third party components.
Aug 17th, 2022 9:02am by Darryl K. Taft
👁 Featued image for: Veracode’s SBOM API Simplifies Software Security for Devs
Featured image by Denny Müller on Unsplash.

Veracode has enhanced its cloud native application security testing platform with new integrations, support for Software Bill of Materials (SBOM) and other key improvements.

New features in Veracode’s Continuous Software Security Platform include extended integrations to support software composition analysis (SCA), an SBOM Application Programming Interface (API), and additional language and framework support for static analysis. Frequent scanning of code using tools like Veracode’s mitigates the risk from both proprietary and open source vulnerabilities, such as Log4j.

Dropping SBOMs

“The federal government’s May 2021 executive order highlighted the importance of securing the software supply chain and the role of a Software Bill of Materials in that process,” said Janet Worthington, an analyst at Forrester Research. “Since then, we have seen an increase in government agencies and private sector companies asking us how to request an SBOM. Software providers aren’t far behind, and many of them now proactively generate SBOMs. Integrating SBOM generation tools into the development CI/CD process gives software providers the flexibility to generate and update the SBOM throughout the product lifecycle.”

Veracode’s SBOM API enables developers to easily generate an SBOM in CycloneDX JSON format — one of the approved formats for compliance with the U.S. Executive Order. This will help confirm that the code being used or built is clear of vulnerabilities.

“With the volume of open source code that developers are building upon today, manual processes can slow developers and security teams down,” Chris Wysopal, CTO and co-founder at Veracode, told The New Stack. “The Veracode SBOM API was introduced to make it easier to provide visibility when using third-party components. By taking manual inventory steps out of software composition analysis, resources and time can be dedicated to quicker update and vulnerability response instead.”

Moreover, modern applications are assembled, not written from scratch, according to Brian Roche, Chief Product Officer at Veracode. And open source code makes up a significant proportion of audited code bases, increasing security risk and the need to identify supply chain risk. For example, 97% of the typical Java application is made up of open source libraries, he said.

“Our SBOM API, is designed to make it easier for developers to inventory their code base, including third-party components, allowing them to act quickly if new vulnerabilities emerge,” Roche said in a statement. “Since the launch of our Continuous Software Security Platform in May, we have introduced additional capabilities that meet developers right where they work: in the integrated developer environment (IDE), code repository, and command line interface. These innovations are designed to drive adoption by making the platform even more developer friendly.”

By incorporating SBOM generation into the software development lifecycle, software vendors gain visibility into the components and libraries they assemble and package with their products, Worthington said.

“These practices give them an edge over the competition when customers request an SBOM during the sales and procurement process,” she noted.

New Integrations

Meanwhile, Veracode has introduced integrations that enable developers to work in their familiar environments or to meet developers where they work. For instance, the Veracode Azure DevOps Extension has a new SCA Flaw Importer to automatically import flaws into the IDE, which makes it easy to find and fix any static or SCA security flaws.

The company is also about to release a Veracode for Visual Studio Code extension, which will provide detailed information on vulnerabilities, license risks, and recommended versions of open source libraries and transitive dependencies, Roche said.

Veracode’s platform supports more than 100 languages and frameworks, including those for cloud native application development and older languages used with legacy assets, like COBOL. The new version of the platform provides adding support for Rails 7.0, Ruby 3.x, and PHP Symfony.

“Veracode brought a complete platform for us to build security tools into our development pipelines, as well as helped us grow our knowledge to keep getting better at security,” said Peter Evans, engineering director at QAD Precision GTTE, in a statement. “Veracode was also a good fit because the platform can scan Java code in the Spring framework where we develop our software. We’ve gone from reviewing code to integrating continuous scans into our daily pipelines. Security threats don’t stand still and Veracode provides us the tools to keep up with the latest vulnerabilities and rules.”

TRENDING STORIES
Darryl K. Taft covers DevOps, software development tools and developer-related issues from his office in the Baltimore area. He has more than 25 years of experience in the business and is always looking for the next scoop. He has worked...
Read more from Darryl K. Taft
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.