Harness Automates DevSecOps Workflows with AI Agents and Virtual Patching

·

DevSecOps teams are facing an increasingly daunting task: keeping up with the exponential growth of vulnerabilities in code. To address this challenge, Harness has introduced a suite of artificial intelligence (AI) agents that automate vulnerability triage, remediation, and pull request creation across DevSecOps workflows at machine speed.

Harness’s new AI agents include one integrated into its static application security testing (SAST) tool, which automatically prioritizes scanner findings based on exploitability. This integration enables teams to combine the probabilistic capabilities of an AI agent with a deterministic platform that validates whether a vulnerability is actually exploitable.

The SAST tool now also includes AI-powered features for creating and validating fixes, as well as opening pull requests for developers to review and approve. DevSecOps teams can opt to add their own AI scanners within their pipelines, further streamlining the process.

In addition to these enhancements, Harness has introduced a Zero-Day Agent that continuously monitors threat intelligence feeds around the clock. Once a zero-day vulnerability is discovered, this agent instantly identifies every affected pipeline and artifact and generates a validated fix ready for review within minutes.

Harness’s virtual patching capability allows DevSecOps teams to apply patches without immediately changing application code. This feature enables teams to mitigate vulnerabilities in real-time, reducing the risk of exploitation by cybercriminals who can create exploits in just hours.

Rahul Sood, general manager of application security at Harness, emphasizes that these additions make it possible for DevSecOps teams to respond to issues at machine speed – a crucial capability given the rapid pace of AI-driven vulnerability discovery and exploitation. He notes that many DevSecOps teams are underestimating the degree to which their applications may become collateral damage in cyberattacks enabled by AI.

Sood highlights the challenge posed by AI tools for businesses: while they can discover thousands of vulnerabilities, they also generate a high number of false positives. By incorporating AI agents into SAST tools, it becomes possible to combine probabilistic capabilities with deterministic validation, reducing the risk of unnecessary code changes and minimizing tokens consumed during scanning.

According to Mitch Ashley, vice president and practice lead for software lifecycle engineering at the Futurum Group, DevSecOps teams are now drowning in vulnerability findings they can’t act on fast enough. Harness’s introduction of AI-powered triage and remediation into the pipeline is a significant step towards addressing this issue, as it enables fixes to travel with releases rather than being delayed until the next scan window.

Periodic scanning was designed for code written at human speed, but machine-speed generation breaks that model. As Ashley notes, DevSecOps teams need control over code creation in real-time, not just during periodic scans. This shift is crucial given the rapid pace of AI-driven vulnerability discovery and exploitation.

It’s unclear to what degree DevSecOps teams are revisiting existing workflows, tools, and platforms to address this growing crisis. However, it’s now a question of when and to what extent they will need to prioritize which applications to fix first – assuming that not all issues can be remediated before AI-enabled cyberattacks are launched.

While the short-term outlook may seem daunting, there is also an opportunity for DevSecOps teams to finally address technical debt issues that have been kicked down the road. In the longer term, this could lead to improved overall application security.