You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: "Ingest your own custom attestations and leverage Harness’s querying and policy engine to enforce governance and compliance across all pipelines and artifacts.",
// description: "Visibility into End of Life components using SBOMs.",
30
-
// },
31
-
{
32
-
tag: [{value: "Artifact Security"}],
33
-
title: "Keyless attestation/signing support",
34
-
description: "Support SBOM and SLSA attestations, as well as artifact signing, using keyless workflows.",
23
+
title: "Evidence Vault - Phase 1",
24
+
description: "Native CI integration to automatically capture Source and Build attestations, link artifacts to source code, support custom attestations, and enable attestation downloads.",
35
25
},
36
-
{
26
+
{
37
27
tag: [{value: "Dependency Management"}],
38
28
title: "Automate OSS Dependency Updates with Harness AI",
39
29
description: "Leverage Harness AI to automatically generate PRs for updating outdated dependencies.",
description: "Complete support for Bitbucket, allowing users to onboard repositories and perform SBOM generation, SAST, SCA and secret scans.",
35
+
},
36
+
41
37
{
42
-
tag: [{value: "SBOM"}],
43
-
title: "SBOM Direct and Indirect Dependencies",
44
-
description: "Gain full visibility into OSS usage in your code repos by analyzing both direct and transitive dependencies for comprehensive risk insights.",
38
+
tag: [{value: "Artifact Security"}],
39
+
title: "Keyless signing support using OIDC",
40
+
description: "Support SBOM and SLSA attestations, as well as artifact signing, using keyless workflows powered by Harness OIDC.",
45
41
},
42
+
46
43
{
47
44
tag: [{value: "AI"}],
48
-
title: "Agentic AI Workflows",
45
+
title: "AppSec Agentic Workflows",
49
46
description: "Deliver intelligent insights and automate key SCS actions to proactively secure your software supply chain with AI-driven agents.",
description: " Detect malicious open source packages, typosquatted dependencies, and other suspicious components across your repositories and artifacts.",
52
+
},
53
+
54
+
{
55
+
tag: [{value: "SLSA"}],
56
+
title: "SLSA for non-containers",
57
+
description: "Enable SLSA provenance generation and verification for non-container artifacts.",
58
+
},
51
59
52
60
53
61
],
54
62
},
55
63
"Next": {
56
-
description: "Q1 2026, February 2026 - April 2026",
description: "Complete support for GitLab and Bitbucket, allowing users to onboard repositories and perform configuration checks, SBOM generation, and security scans.",
description: " Identify and flag dependency names that closely resemble popular packages to prevent accidental inclusion of typosquatted or impersonated components.",
description: "Extend to CD events with deployment attestations and environment snapshots, plus attestation search and policy enforcement to streamline audit readiness and compliance reporting.",
// description: "Enhanced audit trail that seamlessly integrates all pipeline events at an account level, spanning from source code to deployment.",
86
+
// },
87
+
// {
79
88
// tag: [{value: "Visibility"}],
80
89
// title: "Global Level View",
81
90
// description: "Gain complete visibility into all artifact and code repositories across projects, along with their associated findings, in a unified account-level view.",
// description: "Improving search, filtering across product pages and overall user experience",
87
96
// },
88
97
89
-
{
90
-
tag: [{value : "Repo Security"}],
91
-
title: "Repo Security Posture Management for Harness Code",
92
-
description: "Identify misconfigurations in source code repositories based on industry standards such as CIS v1.0 and OWASP Top 10 CI/CD Risk. Also, includes support for SBOM generation and security tests such as SAST, SCA, and secrets scanning.",
93
-
},
94
98
{
95
99
tag: [{value : "Risk & Compliance"}],
96
100
title: "Global Artifact & Repository visibility",
97
101
description: "Account-wide views of repositories and artifacts, enabling unified visibility and oversight across all resources.",
98
102
},
99
-
{
100
-
tag: [{value: "Run time Security"}],
101
-
title: "Run Time Security for CI/CD Pipelines",
102
-
description: "Protect your Harness CI/CD pipelines from supply chain attacks by detecting anomalies and unauthorized activity through real-time system and network event monitoring.",
103
+
{
104
+
tag: [{value: "Risk & Compliance"}],
105
+
title: "OSS Risk Scoring",
106
+
description: "Introduce contextual risk scoring for open source dependencies based on risks such as EOL, malicious packages, and known vulnerabilities.",
description: "Out of the box policies to identify risks in open source dependencies based on the OSS Top 10 risks, with the ability to block builds and deployments when critical vulnerabilities or license violations are detected.",
109
+
tag: [{value : "AIBOM"}],
110
+
title: "AIBOM",
111
+
description: "Gain visibility into all AI models, datasets and prompts used across your systems, enabling governance, risk assessment, and secure AI adoption.",
108
112
},
109
113
110
114
],
111
115
},
112
116
"Later": {
113
-
description: "Q2 2026+, May 2026 & beyond",
117
+
description: "Q3 2026+, August 2026 & beyond",
114
118
feature: [
119
+
// {
120
+
// tag: [{value : "CI/CD Security"}],
121
+
// title: "CI/CD Security for Jenkins",
122
+
// description: "Perform static analysis to detect risks and misconfigurations in Jenkins pipelines.",
123
+
// },
124
+
// {
125
+
// tag: [{value: "Repo Security"}],
126
+
// title: "Malicious Package Detection",
127
+
// description: " Detect malicious open-source packages using behavioral analysis and malware scanning to identify backdoors, droppers, and other harmful payloads before deployment.",
// description: "Generate SBOMs and achieve SLSA compliance using Jenkins pipelines.",
133
+
// },
115
134
{
116
-
tag: [{value : "CI/CD Security"}],
117
-
title: "CI/CD Security for Jenkins",
118
-
description: "Perform static analysis to detect risks and misconfigurations in Jenkins pipelines.",
119
-
},
120
-
{
121
-
tag: [{value : "AIBOM"}],
122
-
title: "AIBOM",
123
-
description: "Gain visibility into all AI models and datasets used across your systems, enabling governance, risk assessment, and secure AI adoption.",
135
+
tag: [{value: "Run time Security"}],
136
+
title: "Run Time Security for CI/CD Pipelines",
137
+
description: "Protect your Harness CI/CD pipelines from supply chain attacks by detecting anomalies and unauthorized activity through real-time system and network event monitoring.",
124
138
},
125
-
{
126
-
tag: [{value: "Repo Security"}],
127
-
title: "Malicious Package Detection",
128
-
description: " Detect malicious open-source packages using behavioral analysis and malware scanning to identify backdoors, droppers, and other harmful payloads before deployment.",
139
+
{
140
+
tag: [{value: "Repo Security"}],
141
+
title: "Repo Security Posture Management for Harness Code",
142
+
description: "Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Risks, with built-in SBOM generation, SAST, SCA, and secrets scanning.",
description: "Out of the box policies to identify risks in open source dependencies based on the OSS Top 10 risks, with the ability to block builds and deployments when critical vulnerabilities or license violations are detected.",
134
148
},
135
149
{
136
150
tag: [{value : "Risk & Compliance"}],
137
151
title: "NIST SP800-204D Support",
138
152
description: "Out of the box rules for supporting NIST SP800-204D compliance standards.",
description: "View risk scores on dependencies that get added or removed between artifact drifts which contain vulnerabilities, have invalid licenses, or are unmaintained.",
// description: "View risk scores on dependencies that get added or removed between artifact drifts which contain vulnerabilities, have invalid licenses, or are unmaintained.",
// description: "Assign vulnerabilities & compliance issues to developers using remediation tracker to track across different types of targets (Artifacts, CI/CD, Repos).",
description: "AI-powered chatbot capabilities to assist users within the SCS module",
226
236
},
237
+
{
238
+
tag: [{value: "SBOM"}],
239
+
title: "SBOM Direct and Indirect Dependencies",
240
+
description: "Gain full visibility into OSS usage in your code repos by analyzing both direct and transitive dependencies for comprehensive risk insights.",
0 commit comments