Home / Companies / Snyk / Blog / September 2020

September 2020 Summaries

15 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
Snyk has released Project Attributes and Tags, which enable organizations to organize their projects effectively while providing granular governance and prioritization. These features allow developers to assign values to project attributes such as environment, criticality, and lifecycle stage, facilitating filtering of projects in the project listing page. Additionally, tags can be created and assigned to projects to group them based on custom criteria, enabling teams to prioritize work more effectively. By applying policies to projects based on their attributes and tags, organizations can ensure that high-risk projects receive tailored security and license controls. These features are available across various Snyk plans, including the Free plan, with further capabilities in development for Pro and Enterprise plans.
Sep 30, 2020 1,160 words in the original blog post.
Snyk and Trek10 have partnered to provide a CI/CD solution for serverless applications on AWS, following best practices for isolating resources and providing an enterprise-ready deployment pipeline. The solution integrates with Snyk's Developer-First Security platform to find and fix vulnerabilities in open source dependencies, using cross-account access to development and production subaccounts as well as to Snyk's API. It deploys resources across three subaccounts consisting of AWS services such as CodeCommit, CodePipeline, CodeBuild, and a sample serverless application leveraging Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. The solution also includes integration with Snyk's AWS Lambda integration to monitor the serverless application and notify users via email or Slack if vulnerabilities are found. Additionally, it allows for automated provisioning and deployment of services, simplified billing through Snyk's AWS Marketplace listing, and advanced implementation support from Trek10.
Sep 29, 2020 480 words in the original blog post.
Prioritizing container and web application vulnerabilities is crucial for organizations to focus their security efforts on the most critical issues, given the limited time and resources available. To achieve this, various prioritization methods can be employed, including the use of Common Weakness Enumeration (CWE), Common Vulnerability Scoring System (CVSS), exploitability, reachability, age, fixability, and automation. These tools provide different types of context that help organizations make informed decisions about which vulnerabilities to prioritize first, ultimately strengthening their overall security posture. By leveraging these tools and solutions, such as Snyk, organizations can maximize the value of their time and effort, while minimizing the risk posed by vulnerable applications.
Sep 22, 2020 1,195 words in the original blog post.
Snyk has released an AWS Quick Start for its latest integration with Amazon Elastic Container Registry (ECR) and AWS Lambda. This new feature simplifies the process of integrating Snyk with ECR and Lambda by automating the setup of roles that work for both services, saving users from having to manually configure settings across multiple interfaces. The Quick Start offers three options: Snyk Container and AWS ECR integration, which enables Snyk Container to access container images stored in ECR to scan for vulnerabilities; and Snyk Container and AWS Lambda integration, which allows users to scan and monitor their Lambda code for vulnerable dependencies. Feedback on the Quick Start can be submitted via GitHub.
Sep 22, 2020 424 words in the original blog post.
The BSD License, also known as the Berkeley Source Distribution license, is a low-restriction FOSS (Free and Open Source Software) family of licenses that allows for the distribution of open source, freeware, and shareware projects without any restrictions on redistribution. It originated from the University of California, Berkeley's operating system based on UNIX, which was widely adopted by workstation vendors in the 1980s. The license has undergone changes over time, with a new version replacing the original 4-Clause BSD License due to controversy surrounding its advertising clause. The current New BSD License (or 3-Clause BSD License) requires users to retain copyright notices and disclaimers on all redistributions, reproduce them on documentation, and not use the organization's name to endorse products without permission. The license is classified as a permissive license, which places minimal restrictions on how users can modify, use, or redistribute the source code, making it popular among teams with specific goals in mind. It can be used commercially, and its benefits include allowing for flexible development environments and no additional licensing fees required. Various software projects, including FreeBSD, DragonFly BSD, Google's Bionic, and Darwin, are released under a BSD license, which is the sixth most popular license on Github.
Sep 22, 2020 969 words in the original blog post.
The Grunt JavaScript package was found to have an arbitrary code execution vulnerability, specifically due to the use of a vulnerable `load()` function from the `js-yaml` package. The Snyk research team discovered this vulnerability through their efforts to identify patterns of insecure coding practices and developed a linter rule to detect it. The vulnerability was confirmed to be exploitable by George Gkitsas, who built a proof of concept, and the Grunt package maintainer responded quickly to address the issue, releasing a fix within under a week. This discovery highlights Snyk's efforts to empower developers to stay secure while leveraging open source in their development.
Sep 21, 2020 872 words in the original blog post.
Snyk and Rapid7 have partnered to expand their capabilities in enhancing security for cloud native applications by integrating the Snyk Intel Vulnerability database into tCell by Rapid7, a next-generation cloud Web Application Firewall (WAF) and Real-time Application Security Protection (RASP) technology. This integration enables users to identify open source and container vulnerabilities before runtime, paving the way for automation, remediation, and ongoing monitoring. The Snyk Intel Vulnerability Database is the most advanced and accurate open source vulnerability database in the industry, continuously curated by the Snyk Security Research Team and enriched with machine learning. This partnership expands on existing collaborations between Snyk and other major companies such as Red Hat, Docker, Google Chrome Lighthouse, the Linux Foundation, Tenable, and Trend Micro. The companies will co-host a webinar to highlight the importance of shifting left and right for robust application security and are sponsoring SnykCon, a free event designed to help development, security, and operations teams accelerate secure software development.
Sep 17, 2020 341 words in the original blog post.
The Forbes Cloud 100 company Snyk has been recognized for its modern approach to software development, delivery, and security in the cloud-based environment. The company's mission to deliver developer-first security is setting a new standard of leadership in the public cloud computing market. A modern approach to cloud-native application security goes hand-in-hand with a modern DevOps-oriented organization that prioritizes speed, automation, and collaboration. This approach enables self-sufficient teams and accelerates business instead of slowing it down, by embedding security early into the development pipeline through tools and processes that empower developers to be more self-sufficient and secure in their applications.
Sep 16, 2020 730 words in the original blog post.
Maven, as the most widely used build system in the Java ecosystem, requires attention to its vulnerabilities, especially those found in third-party libraries. Snyk can scan Maven projects for vulnerabilities and provide fixes by updating top-level dependencies or underlying dependencies. The process involves identifying the version specification location, such as a parent pom, properties, or direct declaration in the maven pom file, and then updating it accordingly. In some cases, using a Bill of Materials (BOM) to manage underlying dependencies can also be beneficial. Additionally, using the dependency management section in the maven pom file allows project authors to specify versions for transitive dependencies. By following these steps, developers can mitigate security issues in their Maven-based projects and ensure the integrity of their code.
Sep 14, 2020 948 words in the original blog post.
Snyk Closes $200M to Modernize Security Industry` Snyk, a company focused on modernizing the security industry by empowering developers to integrate security into their software development lifecycle, has closed a $200 million funding round led by Addition. The investment brings Snyk's total funding to $450 million and its current valuation to over $2.6 billion. Despite the challenges of the pandemic year, Snyk has continued to drive its mission forward, growing revenue by 275% and forging significant partnerships with industry leaders. The latest investment will help meet the unique challenges of this time, providing security intelligence, automated workflows, and visibility to busy development teams. Snyk is proud of its hard-won milestones, including a community of over 1.5 million developers embracing the DevSecOps movement. With this funding, Snyk plans to continue supporting its customers and team members as they find new ways to accelerate secure software development globally.
Sep 09, 2020 371 words in the original blog post.
Snyk has introduced a new feature to prioritize container vulnerabilities based on exploit maturity for Linux vulnerabilities, which helps developers quickly decide which vulnerabilities to focus their efforts on. This data is now available in Snyk Container vulnerability scanning and is a built-in factor in the Priority Score calculations. The concept of exploit maturity measures how practical a vulnerability is in the real world, considering factors such as whether an exploit has been published and its ease of use by attackers. By using this feature, developers can filter container security vulnerabilities based on Exploit Maturity, making it easier to prioritize their efforts and stay secure. Snyk's new feature is part of all plans, including free trials, and provides a developer-first approach to container security.
Sep 09, 2020 800 words in the original blog post.
There is no single approach to securing an Amazon S3 bucket that will work for all organizations. A secure S3 bucket requires multiple layers of security, including Identity and Access Management (IAM) policies, Bucket Policies, encryption, and Block Public Access. IAM policies are crucial in defining access control points between Principals, Actions, and Resources, while Bucket Policies can further scope down access to specific resources. Encryption is also essential in protecting data at rest, but it should be used in conjunction with other security measures. Block Public Access can provide an additional layer of protection, but it's not a one-size-fits-all solution and should be carefully evaluated on a case-by-case basis. A mental model of policy and how it relates to actions and resources is critical in designing secure S3 buckets, and using AWS Managed Policies can help streamline the process. Access logging, object-level logging, and versioning are also essential for monitoring and managing S3 bucket activity.
Sep 08, 2020 1,746 words in the original blog post.
The Snyk team has released a new PyCharm plugin that helps Python developers find and fix security and license issues in their open source dependencies, as early as their first lines of code. This plugin complements Snyk's existing integrations with other IDEs and provides wide coverage across various ecosystems, enabling developers to shift security left and take responsibility for it within their workflows. The plugin identifies vulnerabilities and licenses compliance issues, runs automatically, and highlights the issues within the IDE for quick fixing. It is easy to use, comprehensive, and accurate, using Snyk's CLI and correlating findings with the Snyk Intel vulnerability database. The plugin is free but requires a Snyk user account and authentication before use.
Sep 08, 2020 750 words in the original blog post.
The new release of CodeReady Dependency Analytics, integrated with Snyk, enhances vulnerability detection and analysis capabilities for developers, providing real-time security advisories and guidance on choosing appropriate dependencies. This integration is available as an IDE plugin for popular development environments such as Visual Studio Code, Eclipse Che, and IntelliJ-based IDEs. Powered by the advanced Snyk Intel vulnerability database, users can view vulnerabilities as they code, including premium vulnerabilities and detailed security advisories. The partnership between Red Hat and Snyk aims to empower developers to secure their OpenShift applications with ease.
Sep 03, 2020 374 words in the original blog post.
The Gartner Market Guide for Software Composition Analysis (SCA) highlights the growing importance of open source software security and the need for effective risk management and mitigation. The guide recommends that organizations add SCA tools to their application security testing toolkit, secure their software supply chain, establish policies for automated enforcement, and position SCA more prominently in development workflows. SCA tools are essential for identifying and mitigating security vulnerabilities and license issues introduced via open source dependencies, and they must provide functions such as identification of open source components, license compliance management, security vulnerability correlation with vulnerability databases, governance and control, reporting and analysis, and prioritization. To evaluate SCA tools, organizations should consider criteria such as ecosystem and language support, deep and broad security data, prioritiization, developer-friendliness, remediation, integrations, policies, and reporting/BoM.
Sep 01, 2020 1,434 words in the original blog post.