Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,149,958 members, 7,806,774 topics. Date: Tuesday, 23 April 2024 at 11:29 PM

Github Acquires Semmle To Help Developers Spot Security Vulnerabilities - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Github Acquires Semmle To Help Developers Spot Security Vulnerabilities (632 Views)

How Can I Check My Website For Vulnerabilities / Github Launches Security Lab To Spot Vulnerabilities In Open-source Code / Dominic Barcity Acquires Two Cars, To Open Multi Million Naira Newspaper Firm (2) (3) (4)

(1) (Reply)

Github Acquires Semmle To Help Developers Spot Security Vulnerabilities by gavinhallton: 7:37am On Nov 14, 2019
Popular software hosting service GitHub has acquired Semmle, a code analysis platform that helps product developers and security researchers discover potential zero-days and critical vulnerabilities in large codebases.

The financial terms of the deal were not disclosed by the two companies. But GitHub intends to make Semmle’s automated code review products available via GitHub Actions.

The San Francisco-based firm — founded in 2006 — counts Uber, NASA, Microsoft, Google, and Nasdaq as some of its clients.

Semmle offers tools like QL that codifies logical programming errors as queries to spot mistakes, find variants of the same bug elsewhere in the code, and prevent them from occurring in the future.

QL also powers Semmle’s second product, LGTM (short for “Looks Good to Me”), a software engineering analytics platform that combines deep semantic code search with data science insights to let teams get feedback, recommendations, and uncover vulnerable versions of third-party library dependencies.

GitHub is positioning Semmle’s offerings as a means to “investigate, address, and propagate security issues” in open-source projects, as it seeks to incentivize developers in securing software.

In addition, GitHub revealed it’s now a Common Vulnerabilities and Exposures (CVE) Numbering Authority, thereby allowing the company to assign identifiers to new security flaws as and when they are discovered on the platform.

With Semmle integration, every CVE-ID can be associated with a Semmle QL query, which can then be shared and tracked by the broader developer community.

To date, hundreds of CVEs in open-source projects have been uncovered using Semmle, spanning across Google Chromium, Linux, Ubuntu, and Microsoft’s Edge browser.

The Microsoft subsidiary’s acquisition comes months after it purchased Pull Panda to beef up its portfolio of code review tools and provide developers an infrastructure to create secure software that follows the best software practices.

In the year since the tech giant acquired GitHub, the latter has grown into a full-fledged version control system, in addition to becoming one of the largest repositories for hosting open-source software.

Viewed in that light, Semmle is a cog in the grand GitHub wheel that fits right into its software development workflow.

https://www.gamespot.com/startopia/forums/township-unlimited-coins-and-cash-hack-download-io-33473371/

https://www.gamespot.com/kohan-immortal-sovereigns/forums/homescapes-unlimited-coins-and-stars-hack-2020-ios-33473481/

https://www.gamespot.com/moon-project/forums/yokai-tamer-unlimited-jade-and-coins-hack-download-33472711/

(1) (Reply)

How To Make A Game With Html And Javascript / Limited Paypal Account Over 180days / My Facebook Account Was Hacked

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 30
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.