Harness provides a secure way for engineering & DevOps teams to release applications in a simple, safe, and secure way.
The Checkmarx and Harness integrations supports software engineering excellence and improves the developer experience.
Harness Security Testing Orchestration (STO) integrates application security tests throughout developer pipelines, in a way that connects developers with security engineers and provides intuitive workflows. The net result – besides identifying vulnerabilities earlier in the lifecycle – is that the developer has little toil and burden in remediating vulnerabilities.
Harness seamlessly integrates our application security testing tools and can orchestrate tests across the pipeline. If a Harness customer wants to run Checkmarx Source Code Analysis Solution and Static Application Security Testing this can be delivered running Harness Security Testing Orchestration (STO).
What integrations does the partnership support?
Harness Security Testing Orchestration (STO)
STO enables DevOps and security teams to shift security testing across the SDLC as a key outcome of their DevSecOps initiative. STO orchestrates scanning, intelligently deduplicating scanner output, prioritizing remediations, and enforcing governance into pipelines this ensures that vulnerabilities are caught and fixed before products are released.
With Harness STO and Checkmarx, customers can do the following:
- Run local SAST scans using the CxConsole CLI (orchestration mode).
- Extract results from a Checkmarx SAST server (extraction mode).
- Ingest results from any Checkmarx scanner that can be published to SARIF
Harness Software Engineering Insights (SEI)
SEI enables engineering leaders to make data-driven decisions that improve engineering productivity, efficiency, alignment, planning, and execution. It provides actionable insights into software delivery and workflows across teams, processes, and systems to improve software quality, enhance developer experience, and accelerate time to value.
- Customers can integrate SEI with Checkmarx One, CxSAST and CxSCA.