Home / Companies / Snyk / Blog / September 2017

September 2017 Summaries

4 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
The General Data Protection Regulation (GDPR) has significant implications for organizations operating globally, particularly those collecting data from European citizens, with severe fines of up to 4% of global revenues or €20 million for non-compliance. The regulation emphasizes the need for continuous security adjustments and the use of technical measures such as automated security tools to track known vulnerabilities across tech stacks, help developers find and fix existing vulnerabilities, and integrate security into developer workflows. The rapid evolution of open source components poses a risk to organizations, with many attacks exploiting unpatched vulnerabilities in open source software, highlighting the importance of keeping dependencies up-to-date and secure. Snyk's tools aim to automate fixing vulnerabilities, protecting the full app lifecycle from early prevention on commit hooks to monitoring for vulnerabilities in deployed apps.
Sep 26, 2017 665 words in the original blog post.
Our goal is to help understand where we stand when it comes to building and consuming open source in a way that keeps us and the data we hold safe. Open source has changed the way companies build software, and keeping it secure has never been more important. We've started working on a State of Open Source Security report, digging into data to get an understanding of security techniques being used, vulnerability mitigation, and how closely open source users monitor their security. The survey is targeted at both open source maintainers and developers who use open source libraries in their day-to-day work, providing valuable insights into the human aspects around security.
Sep 21, 2017 366 words in the original blog post.
Snyk Enterprise` is a comprehensive platform designed to support large-scale software development teams in securing their applications and adhering to licensing requirements, while also providing a centralized dashboard for monitoring and reporting on security and compliance issues. The platform offers features such as license compliance management, source code management integration, enterprise integrations with various tools and systems, and dedicated support services. Snyk Enterprise aims to empower developers to fix vulnerabilities rather than just finding them, making it an attractive solution for enterprises that prioritize early security inclusion throughout the developer lifecycle.
Sep 19, 2017 380 words in the original blog post.
Open source vulnerabilities can lead to significant breaches, such as the Equifax incident, which exposed personal data of 143 million people due to a vulnerability in Apache Struts, a popular Java library. The risk from these vulnerabilities is real and immediate, with attackers taking advantage of known security holes. While Apache Struts has a history of disclosed vulnerabilities, its team has been responsible in addressing found issues. However, developers who use open source libraries without checking for vulnerabilities or monitoring them over time can be held accountable for their role in the breach. The final owner of the fiasco is often the executive team, which must understand and manage the risks associated with using modern development practices such as open source libraries. To protect yourself from similar breaches, it's essential to get tested, fix problems found, monitor vulnerabilities, find security tools developers can use, and build vulnerability management into your development process.
Sep 11, 2017 1,233 words in the original blog post.