Home / Companies / Snyk / Blog / January 2019

January 2019 Summaries

2 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
Bower, a popular web package manager, has been found to be vulnerable to archive extractions due to Zip Slip vulnerabilities in its decompress-zip dependency. Two security incidents have been associated with this issue, which were fixed in Bower 1.8.6 and 1.8.8. Despite the rise of other package managers like Webpack, yarn, and npm registry, Bower is still heavily relied upon with nearly two million downloads per month. A security researcher reported an arbitrary file write implemented through improper validation of symlinks resulting from the way Bower handles tar archive extraction. The issue was fixed in Bower 1.8.8 by ignoring any symlinks in packages to be installed.
Jan 31, 2019 995 words in the original blog post.
Snyk is an enterprise startup that aims to make open source software secure, empowering developers to own security. The company was included in Business Insider's annual list of top promising enterprise startups for 2019, highlighting its strong growth and commitment to security research. Snyk values diversity, inclusivity, and a positive work culture, where employees are encouraged to suggest new ideas and participate in the product roadmap. The company is committed to transparency and communication, recognizing individual contributions and embracing feedback. With over 200,000 developers using its platform, Snyk has experienced significant growth, tripling in size last year with 7x revenue growth and becoming a part of the Node.js Foundation.
Jan 04, 2019 870 words in the original blog post.