INTRODUCTION: GOVERNANCE, PERFORMANCE, AND MODERNIZATION OpenText Application Security 25.2.0 (Fortify) focuses on strengthening cryptography, modernizing APIs and deployments, reducing operational noise, and nudging enterprises off fragile legacy integrations. For CIOs, CISOs, and SDLC leaders, this release is about improving risk posture, CI/CD efficiency, and long-term platform strategy.
STRONGER LICENSE & INFRASTRUCTURE SECURITY WITH SHA256
What it is LIM now supports SHA1 and SHA256 (offline activation needed). From 26.4.0, only SHA256 will be supported.
Enterprise impact
Reduces cryptographic risk and future-proofs license/infrastructure communications.
Supports staged upgrades of mixed Fortify environments without downtime.
Day-to-day team value
Platform owners can upgrade LIM once, preserving backward compatibility.
Offline customers have clear activation procedures without ad-hoc hacks.
KUBERNETES DEPLOYMENT MODERNIZATION FOR SSC
What it is Helm charts and values files removed from SSC ZIP; deployment now requires Tomcat 10.1 with clear documentation.
Plan/Execute Legacy Migrations: retire ALM, WIE, Bugzilla, CAS/Kerberos, Windows components.
Frequently Asked Questions
OpenText Application Security 25.2.0 expands enterprise AppSec capabilities through enhanced static application security testing, software composition analysis, API security visibility, and risk prioritization across modern CI/CD environments. Integrated with GitHub, GitLab, Azure DevOps, Jenkins, and containerized DevSecOps workflows, OpenText Fortify helps organizations identify vulnerabilities earlier in the SDLC while improving remediation efficiency and governance consistency. Enterprises also benefit from improved compliance reporting and centralized vulnerability management. Merito helps organizations buy, implement, optimize, and renew OpenText Application Security solutions while scaling enterprise AppSec and DevSecOps governance programs.
OpenText Fortify integrates into enterprise DevSecOps pipelines through connectors for GitHub Actions, GitLab CI, Azure DevOps, Jenkins, Bamboo, and cloud-native CI/CD environments. OpenText Application Security solutions automate static analysis, open-source dependency scanning, and policy enforcement across application portfolios to improve release quality and reduce security risk. Organizations use Fortify to strengthen compliance readiness and accelerate secure software delivery across regulated industries. Merito helps enterprises implement, optimize, and renew OpenText Fortify deployments while aligning AppSec governance with enterprise SDLC transformation objectives.
Enterprises use OpenText Application Security in compliance-driven environments because the platform supports centralized governance, audit-ready reporting, policy enforcement, and scalable vulnerability management across distributed development teams. OpenText Fortify capabilities help organizations strengthen PCI DSS, HIPAA, SOC 2, and internal governance requirements while integrating security scanning into CI/CD pipelines. Enterprises also benefit from improved visibility into software supply chain risk and remediation workflows. Merito helps organizations buy, implement, optimize, and renew OpenText Application Security environments aligned with enterprise compliance, DevSecOps, and risk management strategies.
OpenText Application Security improves developer remediation workflows by integrating vulnerability insights directly into GitHub, GitLab, Azure DevOps, and CI/CD development processes. OpenText Fortify provides contextual risk analysis, remediation guidance, and automated scanning capabilities that help developers resolve security issues earlier in the SDLC. Enterprises benefit from reduced manual review effort, improved release quality, and faster vulnerability remediation across distributed engineering teams. Merito helps organizations implement scalable AppSec workflows, optimize Fortify integrations, and align enterprise security operations with agile software delivery objectives.
Enterprises planning upgrades to OpenText Application Security 25.2.0 should evaluate CI/CD integration compatibility, policy governance requirements, reporting workflows, and existing application security processes across hybrid environments. Organizations often validate integrations with GitHub, GitLab, Azure DevOps, Jenkins, and cloud-native development pipelines before deployment. Enterprises should also review vulnerability management workflows, compliance reporting needs, and operational scalability for distributed teams. Merito helps organizations assess upgrade readiness, implement optimized AppSec architectures, and renew OpenText security environments for long-term governance and software delivery success.
OpenText Application Security strengthens software supply chain visibility through software composition analysis, dependency scanning, and policy-driven risk management across enterprise development pipelines. Integrated with GitHub, GitLab, Azure DevOps, and containerized DevSecOps environments, OpenText Fortify helps organizations identify vulnerable open-source components, prioritize remediation, and maintain centralized governance. Enterprises use these capabilities to improve compliance readiness and reduce operational security exposure across modern application portfolios. Merito helps organizations procure, implement, optimize, and renew OpenText Application Security solutions while scaling enterprise AppSec and supply chain governance initiatives.
Keep Reading
Related Product Release Updates
Explore a few more Merito release updates that align with the themes in this article.