Business Wire

Veracode Expands Industry-Leading Fix with AI-Powered SCA Remediation to Combat Software Supply Chain Risk

18.3.2026 13:00:00 CET | Business Wire | Press Release

Share

RSA Conference (booth #435)--Veracode, the global leader in application risk management, today announced Veracode Fix for Software Composition Analysis (SCA), an AI-powered solution to address software supply chain risk. The enhanced automated remediation engine—the next evolution of Veracode’s industry-leading Fix solution—enables organizations to detect and remediate open-source vulnerabilities easily, before code reaches production. Designed to integrate seamlessly into existing developer workflows, it delivers third-party updates and first-party code refactoring without breaking builds or disrupting development.

In 2025, software supply chain breaches accounted for 30 percent of external attacks. Meanwhile Veracode’s 2026 State of Software Security (SoSS) Report revealed 82 percent of organizations struggle with escalating security debt, largely due to open-source dependencies. Veracode Fix for SCA addresses both challenges directly. Leveraging deep, contextual analysis, the solution delivers pull requests that are safe to merge, enabling autonomous fixing. Unlike traditional SCA solutions that often overwhelm developers with alerts and hinder productivity, Veracode Fix combines logic-driven AI with proprietary vulnerability intelligence, ensuring ready-to-merge fixes while eliminating the risk of AI "hallucinations."

“AI is accelerating software development—but it's also enabling an unprecedented explosion of supply chain risks,” said Tim Jarrett, Vice President of Product Management. “Visibility into these risks is no longer enough. Organizations need intelligent, automated solutions that not only find vulnerabilities but fix them with precision, giving development teams the confidence to innovate securely.”

Veracode Fix for SCA transforms the remediation process through several core capabilities:

  • Contextual Analysis: Evaluates the interaction between third-party dependencies and first-party code, preventing breaking changes.
  • Multi-File, Cohesive Pull Requests: Bundles all configuration files and source code modifications into a focused, easily reviewable update.
  • Curated AI Engine: Grounds automated fixes in a proprietary, human-verified vulnerability database for accurate, trustworthy remediation.
  • Automated Workflows: Delivers ready-to-merge code directly into the developer's Git environment.

“By enabling development teams to upgrade to safe open-source libraries automatically while addressing breaking changes with a single, testable update, we move organizations from seeing risk to actively eliminating it, strengthening the security of their software supply chains,” Jarrett closed.

To learn more about Veracode Fix and Application Risk Management platform, visit the Veracode website. Attendees of the 2026 RSA Conference, March 23-26, can see a live demonstration of Veracode Fix for SCA and sign up for the Early Access program by visiting booth #435.

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, Package Firewall, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2026 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands, or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20260318932904/en/

Contacts

Press and Media Contacts
Katy Gwilliam
Head of Global Communications, Veracode
kgwilliam@veracode.com

(c) 2024 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Torq Becomes the Cursor of Security Operations With New Agentic Builder18.3.2026 15:47:00 CET | Press Release

Torq, the established agentic security operations leader, today unveiled Agentic Builder, a critical extension of the Torq AI SOC Platform that turns human intent into agentic outcomes. Agentic Builder enables SOCs to shift the cognitive load of engineering security automation from humans to machines. These Cursor-level capabilities eliminate all barriers to deliver production-grade agentic workflows and AI Agents that manage unlimited alerts 24x7, integrate with every level of the enterprise stack, streamline investigation, and respond at machine speed. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260318328878/en/ This news follows Torq’s recent announcement that it has secured a $140M Series D round at $1.2B valuation to lead the AI SOC and Agentic AI era. Torq AI Agents are now deeply embedded in the daily operations of Fortune 500 SOCs, managing millions of complex security tasks autonomously. Torq now protects hundred

Laserfiche Announces 2026 Run Smarter® Award Winners18.3.2026 15:17:00 CET | Press Release

Laserfiche — the leading SaaS provider of intelligent content management — today announced the winners of the 2026 Laserfiche Run Smarter® Awards. These awards celebrate the visionaries and trailblazers who are redefining the possible, using Laserfiche to break down operational silos and catalyze a new era of enterprise-wide productivity. From a large city reimagining criminal justice to a financial services firm’s innovative use of AI for smarter service delivery: The winners enhance productivity, reimagine processes and improve lives with Laserfiche technology. “The true power of Laserfiche has always been in how it unlocks value — whether that is through delivering actionable intelligence, cost savings, or reclaimed time to put toward innovation,” said Karl Chan, CEO of Laserfiche. “This year’s honorees are at the forefront of information management, with many of them leveraging cloud and AI technology to modernize processes and achieve business transformation.” Congratulations to t

I-Pulse Acquires CSI Technologies to Strengthen U.S. High-Energy Capacitor Manufacturing Capabilities18.3.2026 14:30:00 CET | Press Release

Co-Founder, Chairman, and CEO, Robert Friedland, and Co-Founder and Chief Technology Officer, Laurent Frescaline, of I-Pulse, the world leader in high pulsed power technologies, are pleased to announce the acquisition of CSI Technologies, Inc., the California-based manufacturer of high-energy, high-voltage capacitors serving industrial, medical, and defense applications. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260318099794/en/ The strategic acquisition enhances I-Pulse’s pulsed power development and U.S. manufacturing capabilities, particularly in mining, geothermal energy, mineral exploration, and water resource applications. By integrating CSI Technologies’ proven capacitor design and production expertise, I-Pulse strengthens its access to a reliable supply chain and expands its ability to rapidly design, prototype, and manufacture compact, high-energy-density capacitors. Co-Founder, Chairman, and CEO of I-Pulse Rob

Andersen Consulting Bolsters Cybersecurity Offering Through Collaboration with Trillium Information Security Systems18.3.2026 14:30:00 CET | Press Release

Andersen Consulting strengthens its technology and risk management capabilities through a Collaboration Agreement with Trillium Information Security Systems (TISS), a cybersecurity firm. With a presence in Canada and Pakistan, TISS delivers comprehensive cybersecurity solutions to organizations across the financial services, telecommunications, and public sectors. The firm’s team offers a broad suite of services, including security assessments, managed security operations, red team services, digital forensics & incident response, and GRC advisory. With nearly two decades of experience, TISS provides adaptive, intelligence-driven defenses that help clients anticipate and respond to evolving cyber threats. “At TISS, we work to create a safer digital environment by empowering organizations to operate securely and with confidence,” said Mahir Mohsin Sheikh, CEO of TISS. “Our collaboration with Andersen Consulting allows us to combine our deep technical expertise with a global consulting fr

Elliptic Integrates With Tempo, the Payments-First Blockchain18.3.2026 14:15:00 CET | Press Release

Elliptic, the leader in digital asset decisioning, today announced full blockchain coverage for Tempo, the payments-first Layer-1 blockchain incubated by Stripe and Paradigm. With this integration, compliance and investigation teams gain full visibility into one of the most significant expansions of real-world financial activity onto blockchain infrastructure. "We're excited to have Elliptic providing compliance infrastructure on Tempo from day one. As payments move onchain at scale, builders and their customers need real-time tools to meet regulatory requirements without slowing down." – Nischay Upadhyayula, GTM, Tempo Tempo is a Layer-1 blockchain designed for real-world payments at scale, with sub-second finality and high throughput. Incubated by Stripe and Paradigm, Tempo is built for the transaction volumes that global commerce demands. Elliptic’s blockchain analytics platform is purpose-built to analyse on-chain data at this scale. “Tempo’s payment-specific blockchain infrastruct

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye