TechNewsReel
Live

Veracode Debuts Curated Marketplace to Scale AI-Driven AppSec Integrations

The new ecosystem launches with DryRun Security to help enterprises verify AI-generated code and reduce security noise.

TechNewsReel Newsroom · August 7, 2026

Veracode launched the Veracode Marketplace on July 30, 2026, creating a curated ecosystem of vetted third-party security integrations. The move aims to help enterprises manage the risks of AI-generated code and improve how security teams prioritize vulnerabilities.

DryRun Security joined the marketplace as the inaugural partner, bringing an AI-native contextual security analysis engine to the platform. According to company data, DryRun currently powers more than 500,000 code reviews per month and maintains integrations with several major development tools, including GitHub, GitLab, Cursor, Codex, and Claude Code.

The Shift Toward AI-Native Security

Traditional static analysis tools often struggle to keep pace with the rise of agentic development environments and AI-generated code. While these legacy scanners are effective at finding known patterns, they frequently produce high noise levels and struggle to identify complex logic vulnerabilities. As a result, security teams are increasingly seeking specialized, AI-driven capabilities that can be integrated directly into existing application security (AppSec) workflows without adding significant operational friction.

Reducing the Burden on Security Teams

For CISOs and CIOs, the primary challenge is no longer a lack of data, but a lack of clarity. Veracode noted that application security teams are not asking for more findings, but rather for better verification of which risks actually matter. By combining Veracode's deterministic scanning with AI-reasoning tools like DryRun, organizations can shift from simple detection to the validated remediation of intent-based vulnerabilities that traditional tools typically miss.

This consolidation is designed to reduce the operational burden of managing a fragmented security stack. Veracode stated that application security has entered a new era where no single vendor can solve every challenge alone, necessitating a platform approach to security integration.

Future Outlook

As the marketplace expands beyond its first partner, the industry will be watching how other third-party security vendors integrate their tools into the Veracode ecosystem. The success of the initiative will likely depend on the ability of these vetted integrations to provide a unified audit trail and reduce the manual effort required to verify AI-generated code. While the initial focus is on contextual analysis, the marketplace provides a blueprint for how AppSec platforms may evolve into broader hubs for specialized security intelligence.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.