PROSTO24: NEOMSA APIM 4.6.0 Release Prioritizes Robust Security
The latest iteration of the NEOMSA APIM API management platform, version 4.6.0, has been released. This update places a strong emphasis on significantly bolstering the security posture of the platform’s delivery composition.
Comprehensive Vulnerability Remediation Process
Developers implemented stringent Secure Software Development Lifecycle (SSDLC) processes. As part of these procedures, a Software Bill of Materials (SBOM) was generated, and all components and their dependencies underwent a thorough Software Composition Analysis (SCA) to identify known vulnerabilities. The findings were then cross-referenced with the FSTEC of Russia’s vulnerability database.
Following the initial analysis and subsequent updates to problematic libraries, the number of identified vulnerabilities was substantially reduced. Initially, 57 potential threats were registered, but after a re-check, this figure dropped to 7. Crucially, the final build of NEOMSA APIM 4.6.0 contains no Critical or High-level vulnerabilities, underscoring the product’s elevated security standards.
Further details on the NEOMSA APIM pre-release verification process and the security criteria used to determine release readiness are available in the full report.
The focus on a robust SSDLC and SBOM generation, coupled with SCA against FSTEC of Russia’s vulnerability database, is a critical step for API management platforms. Reducing 57 initial threats to 7 without any Critical or High-level vulnerabilities in the final build of NEOMSA APIM 4.6.0 reflects a significant commitment to security hardening. This methodical approach to dependency management and vulnerability remediation sets a strong precedent in the enterprise API gateway segment, particularly given the increasing attack surface presented by distributed architectures.