Home / Companies / Snyk / Blog / May 2022

May 2022 Summaries

24 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
Tim Leroy, a Senior Solutions Engineer at Snyk in London, shares his personal story of coping with the loss of his father due to cancer. The experience led him to re-evaluate his relationships and career priorities, but ultimately taught him valuable lessons about self-awareness, resilience, and the importance of support systems. As he navigates Mental Health Awareness Month, Tim emphasizes the need for open conversations, empathy, and understanding in addressing mental health issues. He encourages others to talk openly about their struggles, seek support from loved ones or professional resources, and prioritize their well-being.
May 31, 2022 957 words in the original blog post.
Celebrating Asian American and Pacific Islander Heritage Month is important as it provides an opportunity for individuals like Sarah Gibb and Dipti Salopek to share their personal experiences and cultural backgrounds, promoting awareness and understanding of the diverse Asian American and Pacific Islander community. Both women have mixed backgrounds with elements of Taiwanese and Indian heritage respectively, which they feel has impacted them on both a professional and personal level. They discuss how their heritage has influenced their identities, and how they've sought out opportunities to learn more about themselves and other cultures through groups like Asian@Snyk at Snyk. The women also share advice for reconnecting with one's AAPI heritage, such as consuming media that features Asian representation. Overall, their stories highlight the importance of celebrating diversity and promoting inclusivity in the workplace.
May 27, 2022 1,141 words in the original blog post.
At SnykWeek Boston, Simon Maple moderated a panel with security leaders from Datto, Manulife, and Ready Education on improving developer adoption of application security. Panelists emphasized that organizations can retain decentralized, regionally tailored security teams while centralizing monitoring to gain enterprise-wide visibility and make data-driven decisions. They advocated setting transparent, progressively tougher security KPIs, aligning leadership objectives with development-team goals, and framing security and compliance as cross-functional business priorities that build customer trust. Automation was presented as a key way to scale compliance across teams and regions while making secure practices easier for developers to follow. The discussion also highlighted that developer empowerment depends on trust, open communication about both security successes and failures, and early engagement with development teams when introducing standards, tools, or frameworks.
May 26, 2022 962 words in the original blog post.
Snyk recently discovered over 200 malicious npm packages, including those that perform data exfiltration, spawn reverse shells, and use trojans. These malicious packages were found using a custom approach to detect install-time scripts and analyze package metadata. The detection system uses static analysis and applies rules to identify suspicious behavior, such as sending personal identifying information over HTTP or DNS requests. Manual security analysis is still required to confirm the findings. Snyk's approach aims to improve the detection of malicious packages in the npm registry, which has become a target for supply chain attacks. The company recommends using tools like Snyk to protect open-source software ecosystems and cautions against publishing packages that may exfiltrate PII or engage in other malicious activities.
May 24, 2022 2,807 words in the original blog post.
Snyk hosted its first in-person event, SnykWeek: Boston, at the Boston Park Plaza hotel, which brought together developers of all skill levels and backgrounds to learn about developer security. The event featured various sessions, including a talk by Micah Silverman on Developer Security Essentials, a developer challenge called "Hack with Patch," and a roundtable discussion on cultivating developer security. The event also included interactive activities such as Snyk's presence in billboards, signage, free coffee, and a taco truck around the city. The "Hack with Patch" challenge saw 19 participants import at least one new project into Snyk, 10 fix at least one security issue, and 618 total security fixes were made during the event. The winners of the SnykWeek Boston Best Hacker award were Shuchita Mishra and Parth Shukla, who found and fixed a total of 73 vulnerabilities using Snyk's platform. The event aimed to introduce developers to Snyk's powerful platform while sharing knowledge and having fun, and it was well-received by attendees.
May 19, 2022 663 words in the original blog post.
LiveRamp, a data connectivity company, was concerned about being infected with Log4Shell, a popular open source logging library vulnerability. They used Snyk to secure their CI/CD pipeline and remediated the issue, discovering that 23% of their Java projects contained the vulnerability. Snyk helped them scan containers in GCR for Log4j, which was labor-intensive but valuable for understanding container images and prioritizing remediation efforts. The company set up a pecking order for remediation, fixing customer-facing apps first, followed by internal apps. They learned the importance of having a software bill of materials (SBOM) to better understand their infrastructure dependencies. With Snyk's help, LiveRamp was able to remediate all instances of Log4Shell before the end of the year, improving their security posture and visibility into open source dependencies.
May 19, 2022 685 words in the original blog post.
Cloud security challenges are numerous and complex, requiring a deeper understanding of the unique threats and risks associated with cloud architecture. Organizations must be aware of legacy systems, container workload security, data breaches, misconfigurations and change control, cloud security architecture, open source risks, identity, credential and access management, regulatory compliance, unsecured APIs, insider threats, and lack of internal expertise to protect their sensitive data and prevent security incidents. To overcome these challenges, it's essential for organizations to adopt a cloud security architecture, implement security measures such as encryption, two-factor authentication, and policy as code, conduct regular security audits and testing, and develop a culture of security awareness within the organization.
May 19, 2022 2,423 words in the original blog post.
Saar Kuriel, a Senior Software Engineer at Snyk, has made the transition from an Engineering Manager role to an Individual Contributor, where he works on the revolutionary developer-centric SAST tool, Snyk Code. He aims to be technically proficient in his group's systems, promote engineering needs, improve and grow the product, and mentor other team members. Saar is currently working on refactoring a core component of Snyk Code, which handles communication with source code management tools and processes repositories for analysis. The challenge lies in balancing innovation, agility, and quality to produce scalable and reliable software. With full support from his managers, he has the freedom to experiment and learn new skills, including programming languages like Go. Saar describes the engineering culture at Snyk as transparent, allowing team members to contribute to different projects and make a difference, while leaving their stamp on the company's efforts.
May 18, 2022 1,355 words in the original blog post.
Security automation is presented as essential for organizations seeking to maintain strong security practices amid growing products, teams, and rapid development cycles. Security leaders from New Relic, Auth0, and One Medical emphasize embedding lightweight, largely transparent automated controls into developers’ workflows so teams can focus on higher-value detection, analysis, and engineering work rather than repetitive tasks. Automation is also described as necessary for scaling security programs, with organizations needing engineers skilled in both security and DevOps to keep pace with continuous delivery and evolving threats, while reserving manual work for testing that cannot be automated. Contributors from NCC Group and Intuit further highlight automation’s role in providing continuous visibility into system risk, integrating security checks throughout CI/CD pipelines, measuring resilience, and potentially creating more self-resilient systems over time.
May 16, 2022 772 words in the original blog post.
Snyk’s EMEA SDR organization, with teams in London and Tel Aviv, is presented through the experiences of Tel Aviv SDR Jonathan Chetrit and London Sales Development Manager Paula Kanikuru. Chetrit describes SDRs as the first customer-facing contact in the sales process, responsible for qualifying inbound interest, conducting outbound outreach, understanding prospects’ needs, and generating meetings and pipeline for account executives while collaborating with marketing, sales, and technical teams. He highlights the challenges of handling rejection and meeting targets, as well as the company’s emphasis on diversity, teamwork, training, and career growth for people with or without prior technical sales experience. Kanikuru characterizes the role as a foundation for broader careers in sales, engineering, customer success, and other functions, noting that SDRs at Snyk participate beyond initial prospecting by supporting account expansion and customer relationships. She emphasizes individualized development plans, mentoring, regional and cultural alignment, peer-led onboarding, and training in products, leadership, sales tools, and customer interactions, while noting that the team recruits people from varied academic and professional backgrounds.
May 11, 2022 1,479 words in the original blog post.
Snyk has appointed Adi Sharabani as Chief Technology Officer, tasking him with shaping the short- and long-term vision for its developer security platform, overseeing Snyk Labs, and working closely with customers and product deployments to anticipate emerging needs. Sharabani has known Snyk’s founders since their time at Watchfire and IBM, became an early investor and advisor after recognizing the need to empower developers to build security into innovation, and has advocated for developer security and DevSecOps since Snyk’s 2015 founding. His prior experience includes co-founding and leading mobile threat defense company Skycure until its acquisition by Symantec in 2017, after which he led Symantec’s $650 million Endpoint Solutions business unit. Sharabani brings technical, strategic, and operational experience to the role, along with more than 25 application security patents and involvement in developing Israel’s high-school cyber defense curriculum.
May 11, 2022 618 words in the original blog post.
Congratulations to Courtney Broadwell, Cyndi Doyle, Anna Hester, Kristina Onyon and Jill Wilkins for being recognized by CRN as 2022 Women of the Channel, a distinction that honors compassionate leadership, innovative thinking and practical planning in the technology industry. The five women, all part of Snyk's team, have made significant contributions to their respective fields, including creating scalable programs, innovative partnerships, and empowering developers to build securely. Their work has been instrumental in helping Snyk navigate market shifts and achieve its mission to accelerate secure development for every developer worldwide.
May 09, 2022 740 words in the original blog post.
The Snyk Infrastructure as Code (IaC) tool now detects all types of infrastructure drift, including changes or deletions of managed and unmanaged resources, and reports them as Terraform resources. This provides developers with complete visibility and the ability to remediate early. The tool supports all major cloud providers and requires minimal access rights, making it a secure way to manage infrastructure drift. Snyk IaC can help increase IaC coverage, inform infrastructure drift within specific features or applications, detect drift within specific cloud services, and provide benefits such as improved code coverage, increased security, and compliance. The tool is available on all Snyk plans, including the Free plan, and can be used locally on developers' laptops, in CI/CD pipelines, or as scheduled cron jobs to get focused reports.
May 09, 2022 1,485 words in the original blog post.
Noa Korem, a Senior Director of EMEA Marketing at Snyk, recently returned from her third maternity leave, which was easier than her previous ones due to her experience and planning. She had to balance her work and personal life, including caring for her new baby, while also managing her team's expectations. Noa found it challenging to separate herself from work, but ultimately enjoyed returning to a role she loved. She emphasized the importance of being present with her kids, focusing on work when working, and planning ahead to make her transition smoother. Amanda Parks, a Senior Director of Enterprise Sales at Snyk, returned to work after a six-month maternity leave, which was facilitated by a well-planned return-to-work strategy that included hiring someone to backfill her role while she was out. Amanda juggled being a mom and continuing to excel in her role by working remotely, planning ahead, and trusting others to help with childcare responsibilities. She found it difficult to let go of control and trust someone else to care for her baby, but ultimately appreciated the support of her coworkers and the company's supportive culture. Both Noa and Amanda emphasized the importance of being proactive, using their support systems, and taking care of themselves during their transition back to work.
May 06, 2022 2,557 words in the original blog post.
Snyk Code, a product of DeepCode, has completed its first year and is now part of the Snyk platform, offering static application security testing (SAST) capabilities to developers. The tool was created by combining machine learning with static code analysis, powered by research-driven processes, and has already reported over 2.5 million issues in more than a quarter of a million projects. With its unique engine and industry-leading speeds, Snyk Code supports multiple programming languages and IDEs, including Visual Studio Code, IntelliJ, WebStorm, PyCharm, GoLand, and Visual Studio. The team behind Snyk Code has grown significantly, with several engineering groups working on the rule set, engine, web, and IDE integrations. Looking ahead, Snyk Code plans to expand its capabilities, including reporting, languages, engine features, IDE integrations, community growth, and product capabilities, in line with Snyk's vision for the future of code security.
May 06, 2022 1,368 words in the original blog post.
Snyk’s North American SDR organization, with teams in Boston and Denver, is presented through the experiences of Boston-based Senior SDR Ally Sirois and Sales Development Manager Joe MacInnis. Sirois describes moving from marketing into sales after gaining experience with lead generation, Salesforce campaigns, and events, and says Snyk hired her based on ambition, learning potential, and alignment with its “One Team” value despite her lack of direct sales experience. She characterizes the SDR role as a strategic, research-driven prospecting position that serves as an early point of contact for customers, supported by collaboration, recognition, coaching, and visibility into career paths across sales, customer success, marketing, and other functions. MacInnis, who began in door-to-door sales and entered software in 2019, explains that his management role focuses on helping SDRs, including those without prior sales experience, ramp quickly through individual coaching, team collaboration, and coordination with marketing and sales leadership. He emphasizes the team’s contribution to pipeline generation, its role in allowing account executives to concentrate on closing deals, and a culture centered on shared goals, adaptable coaching, professional development, and opportunities for advancement into leadership or other commercial roles.
May 05, 2022 1,743 words in the original blog post.
In a recent discussion between Simon Maple, Field CTO at Snyk, and Craik Pyke, Senior Director of Security, Cloud, and DataStores Engineering at SurveyMonkey (now part of Momentive), the two professionals discussed strategies for integrating security throughout software development processes. They emphasized the importance of creating consistency and visibility in a microservices architecture, providing better tools and data to developers, building a paved road approach, leveraging security champions as a grassroots initiative, sharing responsibilities and goals between developers and security teams, and supporting developers through collaboration and coaching. By adopting these strategies, organizations can accelerate secure development while maintaining agility and efficiency in their software engineering processes.
May 05, 2022 1,381 words in the original blog post.
Using Star Wars quotations as a framework, the piece encourages developers to treat JavaScript security as an ongoing, layered practice rather than a one-time task. It recommends adopting accessible tools such as eslint-anti-trojan-source to detect Trojan Source attacks, lockfile-lint to validate dependency lockfiles, snync to help prevent dependency-confusion attacks, and Snyk for dependency, code, infrastructure, container, and IDE security scanning. It also emphasizes the importance of secure code reviews, awareness of injection risks and typosquatting, and evaluating package health beyond download counts, citing the deprecated but widely downloaded request package as an example. Security risks can remain unnoticed for years, as illustrated by the sudo privilege-escalation vulnerability, while emerging issues such as prototype pollution show that threats evolve with software ecosystems. Connecting repositories to monitoring services can help teams receive alerts and automated remediation pull requests for newly disclosed vulnerabilities, and educational resources can help developers continually build application-security knowledge.
May 04, 2022 1,091 words in the original blog post.
To celebrate May the 4th, Snyk provides downloadable assets and instructions for creating a Star Wars-inspired virtual video scene in the open-source OBS application. Users install OBS on Linux, macOS, or Windows, configure it to use its virtual camera feature, and import a looping space background, ship interior video, webcam feed, and Snyk ship image as layered sources. Chroma key filters remove green backgrounds from the interior and ship assets, while resizing and positioning align the layers around the camera feed; an optional semi-transparent ship-window overlay can complete the effect. After activating OBS’s virtual camera, the completed scene can be selected as a video source in compatible calling or streaming applications, and the same techniques can be used to create additional custom scenes.
May 04, 2022 1,010 words in the original blog post.
The npm ecosystem has seen a rise in malicious packages being released, which can lead to dependency injection and security vulnerabilities. To protect applications from these threats, developers should perform due diligence by understanding the functionality of their chosen open source packages and using tools like Snyk Advisor to gauge support and identify potential vulnerabilities. Building dependency trees can also help spot packages added through a library or dependency, making it easier to generate a software bill of materials. Additionally, regular scanning with a software composition analysis tool like Snyk Open Source can provide ongoing alerts for new vulnerabilities and suggest remediations, helping developers maintain application security.
May 04, 2022 1,141 words in the original blog post.
Snyk has integrated its Infrastructure as Code (IaC) security capabilities with HashiCorp Terraform Cloud, providing a streamlined and secure way to provision and manage public cloud infrastructure. This integration allows developers to easily identify and fix IaC misconfigurations and noncompliant security issues while coding, reducing the risk of insecure infrastructure before it's deployed. The Snyk Terraform run task provides immediate feedback on security and compliance, using static analysis to compare IaC files against predefined security rules and custom policies. This integration enables developers to automate IaC security and compliance in workflows, detecting drifted and missing resources, and providing structured security context and fix guidance for each issue. The Snyk Terraform Cloud integration aims to make Terraform Cloud workflows one of the safest ways to provision and manage cloud infrastructure, shifting IaC security left to become an integral part of the development process.
May 04, 2022 762 words in the original blog post.
Building Docker images in a Kubernetes cluster is becoming increasingly common among engineers, as it offers several benefits such as automation, consistency, and monitoring of microservices. However, this approach also presents technical hurdles that require workarounds. Several tools are available to build Docker images in a Kubernetes cluster, including Buildah, img, kaniko, Docker in Docker, Sysbox Enterprise Edition, BuildKit CLI, Jib for Java containers, KO for Go applications, and others. These tools offer varying levels of security, convenience, and compatibility with different environments. The Docker in Docker method is commonly used in CI/CD pipelines but has security concerns and limitations, whereas kaniko provides a secure way to build Docker images without relying on a Docker daemon. Kaniko works by running the Dockerfile commands individually, taking snapshots of the userspace after each command, and appending them to the base layer. Creating a Kubernetes Secret for kaniko is necessary for authentication with Docker Hub, and the tool integrates seamlessly with other tools such as GitHub, Jenkins, and Snyk for container security. By using kaniko, developers can build and deploy Docker images from their Kubernetes cluster securely and efficiently.
May 03, 2022 1,557 words in the original blog post.
Snyk provides various ways to ignore security issues, including using the Snyk CLI, API, UI, or .snyk policy file. The method used depends on the specific use case and organization's policies. Ignoring vulnerabilities is necessary for development teams to prioritize their work effectively, but it should not be a default practice. Not all vulnerabilities are equal, and some can be ignored due to lack of fix availability, irrelevance, or other characteristics. Security solutions must enable developers to suppress vulnerabilities while providing security teams with control over who ignores what. The Snyk platform provides tools such as automated pull requests, security policies, and the .snyk policy file to help manage ignores in a measured way. It is essential to review ignores on a regular basis and set the right balance between developer productivity and security measures.
May 03, 2022 1,845 words in the original blog post.
Snyk and StackHawk have formed a strategic alliance to provide modern, developer-first security testing solutions for application teams, equipping them with tools that help catch vulnerabilities early in the development lifecycle, utilizing automated testing to find and fix issues before release. The partnership aims to bring a holistic, scalable approach to securing the software development lifecycle (SDLC) through a best-in-class application security solution. With Snyk and StackHawk's solutions, DevOps teams can automate open source vulnerability management across the SDLC, leveraging both static and dynamic testing in CI/CD pipelines, providing alerts for identified security issues early in the SDLC. The alliance offers developer-friendly application security testing tools that cover modern applications' needs, including microservices, APIs, languages, and open source dependencies. Automated AppSec testing is also integrated into CI/CD pipelines, enabling comprehensive, correlated scan results within StackHawk by way of a new Snyk Code tab on the Finding Details page of every connected project.
May 02, 2022 716 words in the original blog post.