3

Styra Repo Scan provides near-instant scanning of configuration files in GitHub

 1 year ago
source link: https://siliconangle.com/2023/01/18/styra-repo-scan-provides-near-instant-scanning-configuration-files-github/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Styra Repo Scan provides near-instant scanning of configuration files in GitHub

styra.jpeg
SECURITY

Cloud-native authorization startup Styra Inc., the founders of Open Policy Agent, an open-source engine for unifying policy enforcement across the software stack, today announced Repo Scan, a service that provides near-instant scanning of configuration files in GitHub.

Styra argues that software supply chain security — looking across each component of software to identify and address risk — must include detailed scanning of all the configuration files that govern how the application and cloud interact. With Repo Scan, Styra now provides what it says is a simple, efficient way for developers and platform teams to check their configuration files for human error, mismanagement or simple deployment gaps.

Repo Scan, offered as part of the Styra Declarative Authorization Service, gives platform teams a near-instant solution for scanning policy-as-code files in GitHub, then quickly finds and flags issues to minimize the possibility of risk to security, compliance or availability. The capability allows customers to promptly find errors within seconds and prove those errors have been fixed with dynamic compliance reporting.

Using Repo Scan, developers are empowered to enable tooling diversity using an OPA-based policy that is fully extensible across platforms and tooling. Another feature is enhanced productivity with automated policy enforcement that monitors and enforces policy guardrails from GitHub check-in to continuous integration and continuous deployment to production deployment.

The product ensures potential attackers cannot exploit configuration errors and “walk through the front door” of today’s software-defined infrastructure.

“No human can keep up with scanning thousands of lines of code, with infinite repetition, to ensure configuration changes and app updates don’t have unintended consequences,” Chris Hendrix, director of product management at Styra, said in a statement. “This new addition to Styra DAS lets our customers shift their security policy left, all the way to code check-in time, to catch errors even earlier, and remediate risk from the start.”

The company provides an authorization platform built on OPA to provide access control and security across cloud-native applications and systems. Originally focused on policy-as-code guardrails for Kubernetes, Styra has extended its policy-based authorization to microservices, gateways and cloud-native entitlements management.

Previous releases include Styra Run, a cloud service aimed at helping developers implement authorization features in their applications with less effort, in July. The company also added Terraform support in 2021.

Chief Executive Bill Mann spoke to theCUBE, SiliconANGLE Media’s video studio, in July 2020, explaining that enterprises and vendors are embracing Styra’s authorization solutions. OPA contributors include Google LLC, Microsoft, Cisco Systems Inc. and Goldman Sachs.

Image: Styra

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK