Veracode Enhances Platform to Combat Software Supply Chain Attacks
- Securityish
- Tools & Best Practices
Quick Summary
The Securityish Brief
Veracode introduced key platform innovations in the second half of 2025, notably the Package Firewall, which serves as a preventive control against software supply chain attacks. This enhancement is crucial as supply chain-related breaches have doubled, now accounting for 30 percent of incidents, according to the Verizon 2025 Data Breach Investigations Report.
The Package Firewall, launched in June 2025, prevents malicious and risky packages from entering development environments, a significant advancement over traditional Software Composition Analysis (SCA) tools that only identify vulnerabilities in already used packages. This solution integrates seamlessly with Azure Artifacts and supports various package managers like NPM, PyPI, Maven, Nexus, and Artifactory.
Veracode has also expanded its platform capabilities, enhancing the developer experience with updates to Dynamic Application Security Testing (DAST) Essentials, which now includes manual application linking for better policy evaluation. The Software Composition Analysis (SCA) tool has been upgraded to implement intelligent policies that reduce developer friction by only failing builds when fixes are available for vulnerable components.
Recent updates also introduced enterprise-grade security features, including deeper role-based access control and OAuth-based single sign-on (SSO) authentication across its Integrated Development Environment (IDE) plugins, such as Visual Studio Code and JetBrains. These enhancements aim to streamline security processes while maintaining developer productivity.
Tim Jarrett, VP of Product at Veracode, emphasized the importance of these enhancements in empowering organizations to enhance their security posture and accelerate remediation efforts. By continuously evolving their platform, Veracode aims to meet the growing needs of their customers in a complex security landscape.
Why This Matters for Your Security
The rise in supply chain attacks highlights the urgent need for organizations to adopt preventive measures like Veracode’s Package Firewall. As third-party breaches become more common, companies must ensure that their software supply chains are secure from the outset.
Organizations should consider integrating tools that provide preventive controls rather than reactive measures, as this can significantly reduce the risk of vulnerabilities being exploited. Additionally, implementing role-based access controls and SSO can enhance security without compromising developer efficiency.
By staying informed about the latest security solutions and best practices, organizations can better protect themselves against the evolving threat landscape.
Key Takeaways
- Evaluate your current software supply chain security measures and consider implementing preventive controls like Veracode’s Package Firewall.
- Integrate role-based access controls and OAuth-based SSO to enhance security across your development environments.
- Stay updated on the latest vulnerabilities and ensure your development teams are trained on secure coding practices.
- Regularly review and update your security policies based on the risk profiles of third-party packages.
- Monitor your software supply chain for any signs of malicious activity and respond promptly to any threats.
Key Terms & Concepts
- Package Firewall: In this article, Package Firewall refers to Veracode’s tool that blocks malicious packages from entering the software development environment.
- Software Composition Analysis (SCA): In this article, SCA refers to tools that identify vulnerabilities in software packages that are already in use.
- Dynamic Application Security Testing (DAST): In this article, DAST refers to a testing methodology that evaluates the security of applications while they are running.
- OAuth-based single sign-on (SSO): In this article, OAuth-based SSO refers to a secure authentication method that allows users to access multiple applications with one set of credentials.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.