

Orca Safety has introduced a brand new integration that may allow it to scan Bitbucket repositories for misconfigurations, uncovered secrets and techniques, and vulnerabilities.
In line with Orca Safety, code scanning is a vital ingredient of any safety program, and when builders make the most of public code repositories, they sometimes should manually embed CLI safety instruments into every repository and CI/CD pipeline. This could add growth overhead, create friction between safety and growth groups, and it might be troublesome to constantly cowl all repositories.
With the Orca Bitbucket App, safety scans are mechanically performed at any time when a department is merged. These scans will present contextual alerts and insights on easy methods to remediate safety points.
It additionally scans each pull request to detect newly launched points and forestall questionable code from being merged into the bigger codebase till points are resolved.
“By eliminating guide safety configuration and embedding safety immediately into growth workflows, the Orca Bitbucket App delivers smarter, quicker, and more practical software safety,” the corporate wrote in a weblog put up.
Orca Bitbucket App can even periodically scan inactive repositories to make sure that newly found vulnerabilities aren’t going unnoticed.
The app includes a Code Safety dashboard that gives visibility into all Bitbucket repositories and their safety findings.
The mixing with Bitbucket follows related integrations Orca Safety already has with GitHub, GitLab, and Azure DevOps.