Black Duck Extends Scope and Reach of Code Scanning Tool

Black Duck has updated its Coverity static analysis code scanning tool to provide deeper integrations with artificial intelligence (AI) tools along with updates to its user interface that make it simpler to prioritize issues in a way that makes it easier to adhere to multiple compliance mandates.

A Model Context Protocol (MCP) server added to Coverity enables AI coding agents to run local scans to surface security and quality issues in context. That capability can be run using any large language model (LLM) a DevSecOps team may prefer.

At the same time, Black Duck has added a security impact lens and code checker capability through which DevSecOps teams can sort and filter issues by security priority to make it simpler to comply with, for example, the Cyber Resilience Act (CRA) enacted by the European Union (EU).

Black Duck has also added a checker that identifies Insecure Direct Object Reference (IDOR) vulnerabilities in JavaScript and TypeScript code.

Finally, there is now an AI-assisted issue triage capability that has been optimized for scans of C and C++ code that tend to generate higher levels of false positives. Black Duck has also added support for version 1.92 of the Rust programming language.

Corey Hamilton, principal product marketing manager for Black Duck, said that as DevSecOps workflows evolve rapidly in the AI era, there is a clear need to be able to triage issues faster. As malicious actors gain access to more advanced AI models, the overall pace at which vulnerabilities in code need to be discovered and remediated has rapidly accelerated, he added.

The latest updates to Coverity are designed to enable DevSecOps teams to identify and prioritize technical debt issues in their codebases in a way that enables them to comply with more stringent requirements, such as 24-hour vulnerability reporting requirements, defined in the CRA by regulators in Brussels.

In general, AI is changing the application security game as it becomes harder to prioritize vulnerabilities. Historically, DevSecOps teams have responded to issues based on the severity of the risk ascribed to a vulnerability by researchers. However, it’s now much simpler for adversaries to launch attacks using AI tools to chain together a series of exploits aimed at low-level vulnerabilities.

Unfortunately, the amount of code being generated by developers using AI tools is overwhelming the ability of DevSecOps teams to keep pace. As a result, more vulnerabilities than ever may be finding their way into production environments.

Each DevSecOps team will need to determine how rapidly they will need to reengineer their existing workflows for the AI era, but time is running short. While access to more advanced AI models from Anthropic and OpenAI remain restricted, providers of rival AI models are catching up. In many cases, cybercriminals are already taking advantage of the latest AI models to not only discover vulnerabilities but also create exploits in a matter of hours. The challenge, as always, is making the best use of the all-too-limited resources that DevSecOps teams have to stem what is becoming a massive wave of newly discovered vulnerabilities that one way or another will need to be remediated as soon as possible.

Read More

Scroll to Top