May 2022 Summaries
17 posts from Snyk
Filter
Month:
Year:
Post Summaries
Back to Blog
Tim Leroy, a Senior Solutions Engineer at Snyk in London, shares his personal story of coping with the loss of his father due to cancer. The experience led him to re-evaluate his relationships and career priorities, but ultimately taught him valuable lessons about self-awareness, resilience, and the importance of support systems. As he navigates Mental Health Awareness Month, Tim emphasizes the need for open conversations, empathy, and understanding in addressing mental health issues. He encourages others to talk openly about their struggles, seek support from loved ones or professional resources, and prioritize their well-being.
May 31, 2022
957 words in the original blog post.
Celebrating Asian American and Pacific Islander Heritage Month is important as it provides an opportunity for individuals like Sarah Gibb and Dipti Salopek to share their personal experiences and cultural backgrounds, promoting awareness and understanding of the diverse Asian American and Pacific Islander community. Both women have mixed backgrounds with elements of Taiwanese and Indian heritage respectively, which they feel has impacted them on both a professional and personal level. They discuss how their heritage has influenced their identities, and how they've sought out opportunities to learn more about themselves and other cultures through groups like Asian@Snyk at Snyk. The women also share advice for reconnecting with one's AAPI heritage, such as consuming media that features Asian representation. Overall, their stories highlight the importance of celebrating diversity and promoting inclusivity in the workplace.
May 27, 2022
1,141 words in the original blog post.
Snyk recently discovered over 200 malicious npm packages, including those that perform data exfiltration, spawn reverse shells, and use trojans. These malicious packages were found using a custom approach to detect install-time scripts and analyze package metadata. The detection system uses static analysis and applies rules to identify suspicious behavior, such as sending personal identifying information over HTTP or DNS requests. Manual security analysis is still required to confirm the findings. Snyk's approach aims to improve the detection of malicious packages in the npm registry, which has become a target for supply chain attacks. The company recommends using tools like Snyk to protect open-source software ecosystems and cautions against publishing packages that may exfiltrate PII or engage in other malicious activities.
May 24, 2022
2,807 words in the original blog post.
Snyk hosted its first in-person event, SnykWeek: Boston, at the Boston Park Plaza hotel, which brought together developers of all skill levels and backgrounds to learn about developer security. The event featured various sessions, including a talk by Micah Silverman on Developer Security Essentials, a developer challenge called "Hack with Patch," and a roundtable discussion on cultivating developer security. The event also included interactive activities such as Snyk's presence in billboards, signage, free coffee, and a taco truck around the city. The "Hack with Patch" challenge saw 19 participants import at least one new project into Snyk, 10 fix at least one security issue, and 618 total security fixes were made during the event. The winners of the SnykWeek Boston Best Hacker award were Shuchita Mishra and Parth Shukla, who found and fixed a total of 73 vulnerabilities using Snyk's platform. The event aimed to introduce developers to Snyk's powerful platform while sharing knowledge and having fun, and it was well-received by attendees.
May 19, 2022
663 words in the original blog post.
LiveRamp, a data connectivity company, was concerned about being infected with Log4Shell, a popular open source logging library vulnerability. They used Snyk to secure their CI/CD pipeline and remediated the issue, discovering that 23% of their Java projects contained the vulnerability. Snyk helped them scan containers in GCR for Log4j, which was labor-intensive but valuable for understanding container images and prioritizing remediation efforts. The company set up a pecking order for remediation, fixing customer-facing apps first, followed by internal apps. They learned the importance of having a software bill of materials (SBOM) to better understand their infrastructure dependencies. With Snyk's help, LiveRamp was able to remediate all instances of Log4Shell before the end of the year, improving their security posture and visibility into open source dependencies.
May 19, 2022
685 words in the original blog post.
Cloud security challenges are numerous and complex, requiring a deeper understanding of the unique threats and risks associated with cloud architecture. Organizations must be aware of legacy systems, container workload security, data breaches, misconfigurations and change control, cloud security architecture, open source risks, identity, credential and access management, regulatory compliance, unsecured APIs, insider threats, and lack of internal expertise to protect their sensitive data and prevent security incidents. To overcome these challenges, it's essential for organizations to adopt a cloud security architecture, implement security measures such as encryption, two-factor authentication, and policy as code, conduct regular security audits and testing, and develop a culture of security awareness within the organization.
May 19, 2022
2,423 words in the original blog post.
Saar Kuriel, a Senior Software Engineer at Snyk, has made the transition from an Engineering Manager role to an Individual Contributor, where he works on the revolutionary developer-centric SAST tool, Snyk Code. He aims to be technically proficient in his group's systems, promote engineering needs, improve and grow the product, and mentor other team members. Saar is currently working on refactoring a core component of Snyk Code, which handles communication with source code management tools and processes repositories for analysis. The challenge lies in balancing innovation, agility, and quality to produce scalable and reliable software. With full support from his managers, he has the freedom to experiment and learn new skills, including programming languages like Go. Saar describes the engineering culture at Snyk as transparent, allowing team members to contribute to different projects and make a difference, while leaving their stamp on the company's efforts.
May 18, 2022
1,355 words in the original blog post.
Congratulations to Courtney Broadwell, Cyndi Doyle, Anna Hester, Kristina Onyon and Jill Wilkins for being recognized by CRN as 2022 Women of the Channel, a distinction that honors compassionate leadership, innovative thinking and practical planning in the technology industry. The five women, all part of Snyk's team, have made significant contributions to their respective fields, including creating scalable programs, innovative partnerships, and empowering developers to build securely. Their work has been instrumental in helping Snyk navigate market shifts and achieve its mission to accelerate secure development for every developer worldwide.
May 09, 2022
740 words in the original blog post.
The Snyk Infrastructure as Code (IaC) tool now detects all types of infrastructure drift, including changes or deletions of managed and unmanaged resources, and reports them as Terraform resources. This provides developers with complete visibility and the ability to remediate early. The tool supports all major cloud providers and requires minimal access rights, making it a secure way to manage infrastructure drift. Snyk IaC can help increase IaC coverage, inform infrastructure drift within specific features or applications, detect drift within specific cloud services, and provide benefits such as improved code coverage, increased security, and compliance. The tool is available on all Snyk plans, including the Free plan, and can be used locally on developers' laptops, in CI/CD pipelines, or as scheduled cron jobs to get focused reports.
May 09, 2022
1,485 words in the original blog post.
Noa Korem, a Senior Director of EMEA Marketing at Snyk, recently returned from her third maternity leave, which was easier than her previous ones due to her experience and planning. She had to balance her work and personal life, including caring for her new baby, while also managing her team's expectations. Noa found it challenging to separate herself from work, but ultimately enjoyed returning to a role she loved. She emphasized the importance of being present with her kids, focusing on work when working, and planning ahead to make her transition smoother.
Amanda Parks, a Senior Director of Enterprise Sales at Snyk, returned to work after a six-month maternity leave, which was facilitated by a well-planned return-to-work strategy that included hiring someone to backfill her role while she was out. Amanda juggled being a mom and continuing to excel in her role by working remotely, planning ahead, and trusting others to help with childcare responsibilities. She found it difficult to let go of control and trust someone else to care for her baby, but ultimately appreciated the support of her coworkers and the company's supportive culture. Both Noa and Amanda emphasized the importance of being proactive, using their support systems, and taking care of themselves during their transition back to work.
May 06, 2022
2,557 words in the original blog post.
Snyk Code, a product of DeepCode, has completed its first year and is now part of the Snyk platform, offering static application security testing (SAST) capabilities to developers. The tool was created by combining machine learning with static code analysis, powered by research-driven processes, and has already reported over 2.5 million issues in more than a quarter of a million projects. With its unique engine and industry-leading speeds, Snyk Code supports multiple programming languages and IDEs, including Visual Studio Code, IntelliJ, WebStorm, PyCharm, GoLand, and Visual Studio. The team behind Snyk Code has grown significantly, with several engineering groups working on the rule set, engine, web, and IDE integrations. Looking ahead, Snyk Code plans to expand its capabilities, including reporting, languages, engine features, IDE integrations, community growth, and product capabilities, in line with Snyk's vision for the future of code security.
May 06, 2022
1,368 words in the original blog post.
In a recent discussion between Simon Maple, Field CTO at Snyk, and Craik Pyke, Senior Director of Security, Cloud, and DataStores Engineering at SurveyMonkey (now part of Momentive), the two professionals discussed strategies for integrating security throughout software development processes. They emphasized the importance of creating consistency and visibility in a microservices architecture, providing better tools and data to developers, building a paved road approach, leveraging security champions as a grassroots initiative, sharing responsibilities and goals between developers and security teams, and supporting developers through collaboration and coaching. By adopting these strategies, organizations can accelerate secure development while maintaining agility and efficiency in their software engineering processes.
May 05, 2022
1,381 words in the original blog post.
The npm ecosystem has seen a rise in malicious packages being released, which can lead to dependency injection and security vulnerabilities. To protect applications from these threats, developers should perform due diligence by understanding the functionality of their chosen open source packages and using tools like Snyk Advisor to gauge support and identify potential vulnerabilities. Building dependency trees can also help spot packages added through a library or dependency, making it easier to generate a software bill of materials. Additionally, regular scanning with a software composition analysis tool like Snyk Open Source can provide ongoing alerts for new vulnerabilities and suggest remediations, helping developers maintain application security.
May 04, 2022
1,141 words in the original blog post.
Snyk has integrated its Infrastructure as Code (IaC) security capabilities with HashiCorp Terraform Cloud, providing a streamlined and secure way to provision and manage public cloud infrastructure. This integration allows developers to easily identify and fix IaC misconfigurations and noncompliant security issues while coding, reducing the risk of insecure infrastructure before it's deployed. The Snyk Terraform run task provides immediate feedback on security and compliance, using static analysis to compare IaC files against predefined security rules and custom policies. This integration enables developers to automate IaC security and compliance in workflows, detecting drifted and missing resources, and providing structured security context and fix guidance for each issue. The Snyk Terraform Cloud integration aims to make Terraform Cloud workflows one of the safest ways to provision and manage cloud infrastructure, shifting IaC security left to become an integral part of the development process.
May 04, 2022
762 words in the original blog post.
Building Docker images in a Kubernetes cluster is becoming increasingly common among engineers, as it offers several benefits such as automation, consistency, and monitoring of microservices. However, this approach also presents technical hurdles that require workarounds. Several tools are available to build Docker images in a Kubernetes cluster, including Buildah, img, kaniko, Docker in Docker, Sysbox Enterprise Edition, BuildKit CLI, Jib for Java containers, KO for Go applications, and others. These tools offer varying levels of security, convenience, and compatibility with different environments. The Docker in Docker method is commonly used in CI/CD pipelines but has security concerns and limitations, whereas kaniko provides a secure way to build Docker images without relying on a Docker daemon. Kaniko works by running the Dockerfile commands individually, taking snapshots of the userspace after each command, and appending them to the base layer. Creating a Kubernetes Secret for kaniko is necessary for authentication with Docker Hub, and the tool integrates seamlessly with other tools such as GitHub, Jenkins, and Snyk for container security. By using kaniko, developers can build and deploy Docker images from their Kubernetes cluster securely and efficiently.
May 03, 2022
1,557 words in the original blog post.
Snyk provides various ways to ignore security issues, including using the Snyk CLI, API, UI, or .snyk policy file. The method used depends on the specific use case and organization's policies. Ignoring vulnerabilities is necessary for development teams to prioritize their work effectively, but it should not be a default practice. Not all vulnerabilities are equal, and some can be ignored due to lack of fix availability, irrelevance, or other characteristics. Security solutions must enable developers to suppress vulnerabilities while providing security teams with control over who ignores what. The Snyk platform provides tools such as automated pull requests, security policies, and the .snyk policy file to help manage ignores in a measured way. It is essential to review ignores on a regular basis and set the right balance between developer productivity and security measures.
May 03, 2022
1,845 words in the original blog post.
Snyk and StackHawk have formed a strategic alliance to provide modern, developer-first security testing solutions for application teams, equipping them with tools that help catch vulnerabilities early in the development lifecycle, utilizing automated testing to find and fix issues before release. The partnership aims to bring a holistic, scalable approach to securing the software development lifecycle (SDLC) through a best-in-class application security solution. With Snyk and StackHawk's solutions, DevOps teams can automate open source vulnerability management across the SDLC, leveraging both static and dynamic testing in CI/CD pipelines, providing alerts for identified security issues early in the SDLC. The alliance offers developer-friendly application security testing tools that cover modern applications' needs, including microservices, APIs, languages, and open source dependencies. Automated AppSec testing is also integrated into CI/CD pipelines, enabling comprehensive, correlated scan results within StackHawk by way of a new Snyk Code tab on the Finding Details page of every connected project.
May 02, 2022
716 words in the original blog post.