통합 개요

The Wiz plugin for Spotify Backstage brings Wiz Issues and Vulnerabilities directly into the Spotify Backstage developer portal. By mapping Wiz Projects to Backstage components, the integration surfaces critical cloud security risk and context next to the software services developers interact with daily.

Integration Benefits

  • In-Context Visibility: Developers can view the total count, severity, remediation status, and detection timelines of vulnerabilities per component directly within Backstage.

  • Granular Search & Filtering: Allows development teams to search through findings by specific rule, resource, or CVE to quickly focus on what is relevant to their current tasks.

  • Frictionless Remediation: Provides one-click navigation from the Backstage portal into the Wiz platform, passing full context, remediation guidance, and code-to-cloud pipeline analysis to accelerate fixes.

Better Together

Wiz and Spotify Backstage bridge the gap between security and engineering teams by aligning security findings with established ownership boundaries. While Wiz provides horizontal and vertical views of risk across cloud environments (via Projects and Services), Backstage serves as the daily operational hub for developers. Together, they democratize security, eliminating the need for developers to sift through unfamiliar dashboards or wait for manual tickets, thereby maintaining engineering momentum while ensuring a strong security posture.

사용 사례 개요

Challenge

Security risks are traditionally disconnected from the everyday tools and ownership models used by developers. Cloud risks are often written in a "different language," making it difficult for an engineer to determine if a vulnerability even belongs to their team or service. This lack of clear ownership slows down response times, creates friction between security and engineering, and leaves organizations exposed to unresolved threats.

Solution

When a developer opens a specific component in Spotify Backstage (such as a public-facing website), the Wiz plugin automatically pulls and displays the associated security findings for that project. For example, if a component shows multiple vulnerable resources, the developer can instantly see that these resources run on an internet-exposed load balancer via the Wiz Security Graph. The developer can immediately assess the impact and seamlessly transition into Wiz for exact remediation guidance—all without disrupting their standard development workflow.

클라우드 보안 제공업체이신가요?

Wiz 기술 파트너 되기

우리와 함께 승리하십시오 이미 파트너이신가요? 로그인

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자