Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

‘It’s how we use this for learning.’ Lenox and Lee schools partner with MIT to prepare students for the AI revolution | Central Berkshires

This AI Learns Faster Than Anything We’ve Seen!

ByteDance’s Doubao: China’s answer to GPT-4o is 50x cheaper and ready for action: Details – Technology News

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Industry AI
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Crunchbase AI

What Is DevSecOps And Why Does It Matter In The Age Of AI?

By Advanced AI EditorApril 3, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


By Sanket Saurav

Interest in DevSecOps has surged in recent years — but many people probably don’t know what it is, or why it has become especially important for tech companies in the age of AI.

When building software, someone has to make sure it doesn’t contain bugs that can later be exploited by bad actors. Today’s AI code generation tools can produce vast amounts of code quickly, but often with many hidden vulnerabilities. Adopting DevSecOps helps tech companies mitigate these risks, but it’s a relatively new approach.

Twenty years ago, most companies deployed their code using three teams: development (writing code), operations (deployment) and security, which usually reviewed the code for vulnerabilities just before shipping. Security was often a reactive step occurring late in the process.

Development and operations eventually merged into DevOps, and in recent years, it became clear that security should be as close to the development process as possible, not an afterthought. DevSecOps was born. A number of changes have made it especially important for tech teams to adopt a robust DevSecOps strategy.

AI-generated code has intensified security needs

Sanket Saurav/DeepSource
Sanket Saurav of DeepSource

With today’s generative AI tools, five developers can generate the work of 20 people. However, automation for code security has not kept pace, creating huge gaps in security compliance. Human reviewers simply can’t deal with the surge in volume.

Studies on AI-generated code found that almost half the code had bugs that could lead to harmful exploitation. Every company today needs to be using automated code security tools — namely static application security testing, or SAST, software — so the code they’re rapidly shipping out doesn’t shoot them in the foot tomorrow.

Developers are relying more on open source

Software developers have been integrating much more open-source code into their projects in recent years, meaning they depend on code that’s been developed externally and repeatedly modified by individual contributors. Each open-source “package” uses an entire chain of third-party code: The average open-source JavaScript package relies on 377 third-party packages, and up to 90% of applications’ code is estimated to be open-sourced.

Developers have far less control over the quality and security of these “dependencies.” Real-life examples of this happening include Log4j, a widely used open-source program that had a serious security flaw allowing hackers to take control of devices that used it.

DevSecOps tools such as Software Composition Analysis, or SCA, analyze those open-source components of a codebase for any security vulnerabilities. Because they can do so rapidly and at scale, they can better insulate security-conscious teams.

Software releases have become more frequent

While a few years ago, traditional development cycles allowed time for manual security reviews  (releases happened every few weeks), software releases now get deployed every few hours. Faster deployments risk creating a “security debt” that compounds with each release.

It’s particularly important for automated tools to step in to secure that continuous deployment, or the security debt could lead to vulnerability proliferation, as each undetected flaw becomes the foundation for dozens of dependent features.

Even smaller startups are being asked to meet security standards

While larger companies typically have DevSecOps capabilities, smaller startups have often focused on product development over security. But nowadays, enterprises purchasing B2B SaaS are compelling those providers to obtain SOC2 Type 2 compliance, which demands a holistic security program.

That can’t be done without a robust code security strategy and tooling in place.

Code security has always been an important part of software development, but recent trends have shifted security closer to the active software development process, and therefore increased the need for fast and efficient security tools.

Sanket Saurav is the co-founder and CEO of DeepSource, a company with a mission to help developers write secure code with static analysis and AI.

Illustration: Dom Guzman


Stay up to date with recent funding rounds, acquisitions, and more with the
Crunchbase Daily.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHow Amex uses AI to increase efficiency: 40% fewer IT escalations, 85% travel assistance boost
Next Article OpenAI and Anthropic are fighting over college students with free AI
Advanced AI Editor
  • Website

Related Posts

Risk Management, AI Lead In Attracting Capital

July 25, 2025

Universal Flu Vaccine Candidate, AI Legal Matchmaker And Seeing Underground

July 25, 2025

Rocksalt Raises $3.5M Seed To Help Execs Become Influencers Via AI Marketing

July 24, 2025
Leave A Reply

Latest Posts

David Geffen Sued By Estranged Husband for Breach of Contract

Auction House Will Sell Egyptian Artifact Despite Concern From Experts

Anish Kapoor Lists New York Apartment for $17.75 M.

Street Fighter 6 Community Rocked by AI Art Controversy

Latest Posts

‘It’s how we use this for learning.’ Lenox and Lee schools partner with MIT to prepare students for the AI revolution | Central Berkshires

July 27, 2025

This AI Learns Faster Than Anything We’ve Seen!

July 27, 2025

ByteDance’s Doubao: China’s answer to GPT-4o is 50x cheaper and ready for action: Details – Technology News

July 27, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • ‘It’s how we use this for learning.’ Lenox and Lee schools partner with MIT to prepare students for the AI revolution | Central Berkshires
  • This AI Learns Faster Than Anything We’ve Seen!
  • ByteDance’s Doubao: China’s answer to GPT-4o is 50x cheaper and ready for action: Details – Technology News
  • Google launches Gemma to help developers build AI apps responsibly
  • Alibaba’s New Qwen3 Reasoning Model Tops OpenAI and Google Benchmarks in Major Open-Source Release

Recent Comments

  1. binance sign up on Inclusion Strategies in Workplace | Recruiting News Network
  2. Rejestracja on Online Education – How I Make My Videos
  3. Anonymous on AI, CEOs, and the Wild West of Streaming
  4. MichaelWinty on Local gov’t reps say they look forward to working with Thomas
  5. 4rabet mirror on Former Tesla AI czar Andrej Karpathy coins ‘vibe coding’: Here’s what it means

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.