February 2020 Summaries
12 posts from Snyk
Filter
Month:
Year:
Post Summaries
Back to Blog
The Java Virtual Machine (JVM) ecosystem has undergone significant changes in February, with 36% of developers switching from Oracle JDK to alternative OpenJDK distributions in the past year. The latest JVM Ecosystem report provides insights into developer behavior and trends. Additionally, security news highlights a Ghostcat high-severity vulnerability found in Tomcat versions, emphasizing the importance of patching solutions. Snyk has released several product updates, including automated fix pull requests for Python dependencies, improved reports experience, and Artifactory container registry support. The company also offers simplified EKS + ECR detection and scanning. Various community events and webinars are scheduled, including a live MyDevSecOps webinar and the KubeCon EU conference. DevSecCon 24 is also announced as a free virtual conference on June 15th-16th.
Feb 28, 2020
558 words in the original blog post.
Apache Tomcat, a widely used Java HTTP web server environment, has been affected by a high-severity vulnerability known as Ghostcat. The vulnerability was discovered in the Apache JServ Protocol (AJP) and allows an attacker to read or include any file into Tomcat webapp directories. All versions of Tomcat that do not contain the patch are vulnerable, including those using the AJP Connector on port 8009. To mitigate this issue, users can disable the AJP Connector by commenting out or deleting its declaration in the server.xml file, or add a requiredSecret field with a safe secret to the Connector configuration. Spring Boot users should also be aware that they may be vulnerable if they use an embedded Tomcat package without proper configuration.
Feb 26, 2020
491 words in the original blog post.
The Snyk team has announced a new strategic partnership with Rapid7, a leader in security analytics and automation, at RSA 2020. This partnership aims to deliver end-to-end application security to organizations developing cloud native applications. The integration of Snyk's vulnerability intelligence into Rapid7's Insight Cloud products will enable customers to create a workflow that brings developers closer to security and enables IT teams to fix vulnerabilities fast and early, at scale. By combining their capabilities, the partnership provides security teams with end-to-end modern application security capabilities.
Feb 24, 2020
387 words in the original blog post.
At Snyk, the company aims to make the digital world a safer place by ensuring that customers trust their ability to protect and secure their data and privacy. Digital Trust is a constant challenge in today's time of heightened user awareness around privacy and security. To demonstrate Digital Trust, companies must think beyond compliance exercises and focus on leadership and accountability, as well as changing behavior through training, celebration, and champions. Snyk has implemented various measures such as talking about it, celebrating employees who raise security or privacy issues, leading from the top, using donuts to foster good security habits, and empowering privacy champions to spread awareness in their teams. By making people care deeply about Digital Trust, companies can build a culture of continuous compliance and innovation responsibly and safely.
Feb 18, 2020
999 words in the original blog post.
A severe security breach has exposed the personal data of 6.5 million Israeli voters, including full names, ID numbers, gender, addresses, and voting information. The breach was uncovered by an anonymous tip, which led the writer to discover a vulnerability in the election management system used by the Likud party. Despite claims from the company that their security standards were rigorous, the writer was able to gain unauthorized access to the system within minutes, revealing plaintext passwords and complete access to voter data. The incident has sparked concerns over privacy and has prompted calls for the elections to be canceled due to security concerns.
Feb 12, 2020
595 words in the original blog post.
A Content Security Policy (CSP) can prevent XSS and other vulnerabilities by specifying allowed resources and their origins, defining directives to control specific elements of the policy, and gaining the ability to report policy violations to the server. A CSP makes it difficult for hackers to inject malicious code into a website's legitimate users, protecting against common web hacking tactics such as injection attacks and cookie theft. By implementing a CSP, developers can support other security best practices like template systems, vulnerability scanning, and manual security reviews, and improve their secure coding skills. Additionally, using a CSP is relatively easy and essential for websites involving complex web applications, login functionalities, and user cookies to stay secure against XSS vulnerabilities.
Feb 09, 2020
900 words in the original blog post.
Snyk Container has been integrated with JFrog Artifactory, enabling users to scan their container images for vulnerabilities and fix them with recommended upgrades and prioritized vulnerability details. Snyk Container provides features such as base image upgrade recommendations, layer identification, and Dockerfile statement analysis to help developers optimize their containers and reduce vulnerabilities. The integration is available for Snyk Pro and Enterprise plans, and users can get started by setting up the integration in the Snyk application console. This enables developers to focus on fixing container vulnerabilities and stay secure with a developer-first approach.
Feb 08, 2020
674 words in the original blog post.
The JVM ecosystem is thriving, with a diverse global community of developers participating in the latest survey. The majority of respondents are from technical backgrounds, and there's a significant presence of C-level employees. The survey reveals that 36% of developers have switched to alternative OpenJDK distributions, while 64% still use Java 8 as their primary release. Kotlin has become the second most popular language on the JVM, overtaking Scala and Clojure. Spring dominates the Java ecosystem with 60% usage for main applications, and IntelliJ IDEA is the preferred IDE among JVM developers, adopted by 62%. The survey highlights the versatility of the JVM ecosystem in both enterprises and startups.
Feb 05, 2020
460 words in the original blog post.
The annual JVM ecosystem report highlights key trends and insights from a survey of over 2000 developers. The majority of respondents, 64%, use Java 8 as their most often used release, despite the introduction of new releases like Java 11. Many developers are reluctant to adopt changes due to concerns about migration costs and the need for significant updates every six months. However, the report also shows that most developers (61%) take security seriously by applying security updates within a month of release, while some (15%) apply them immediately after release. The report provides insights into language usage, IDE adoption, and JDK release models, with Kotlin emerging as the second most popular language on the JVM, overtaking Scala and Clojure.
Feb 05, 2020
926 words in the original blog post.
The JVM ecosystem survey report reveals that Kotlin has overtaken Scala and Clojure to become the second most popular language on the JVM, surpassing them in popularity. The majority of developers still use Java as their main language, with 64% reporting that Java 8 remains the most often used release. Spring dominates the Java ecosystem with 60% using it for their main applications, while IntelliJ IDEA dominates the IDE market with 62% adoption among JVM developers. The survey also shows that 36% of developers switched from Oracle JDK to an alternate OpenJDK distribution over the last year, highlighting a growing trend towards open-source alternatives. Additionally, the report highlights the importance of Java modules in the JVM ecosystem, with only 7% of respondents already using them and 29% planning to use them in the future. Overall, the survey provides valuable insights into the trends and preferences of developers working on the JVM ecosystem.
Feb 05, 2020
970 words in the original blog post.
The Java Virtual Machine (JVM) ecosystem has undergone significant changes in the past year, with a notable shift towards OpenJDK distributions. 36% of developers have switched from Oracle JDK to an alternate OpenJDK distribution over the last year. This trend is largely driven by the fact that 86% of respondents do not wish to pay for JDK support, and instead opt for free or open-source alternatives. The new release cadence of Java, with versions released every March and September, has also played a role in this shift. Additionally, Kotlin has become the second most popular language on the JVM, overtaking Scala and Clojure. Spring remains dominant in the Java ecosystem, with 60% of developers using it for their main applications. IntelliJ IDEA dominates the IDE market, with 62% adoption among JVM developers.
Feb 05, 2020
736 words in the original blog post.
Snyk, a rapidly growing software company, is navigating the challenges of scaling its culture and maintaining cohesiveness as it continues to expand. The company's unique culture, characterized by trust and collaboration, has been instrumental in its success. As Snyk scales, the leadership team is focusing on protecting these core attributes through intentional investments in building trust and refining collaboration processes. This includes investing in tools, establishing processes, and fostering a culture of transparency and autonomy while reducing "noise" in communication channels. By acknowledging that their culture will naturally evolve, Snyk aims to preserve its essential values and maintain the high level of trust and intimacy that has driven its growth.
Feb 04, 2020
823 words in the original blog post.