January 2023 Summaries
7 posts from Snyk
Filter
Month:
Year:
Post Summaries
Back to Blog
Snyk has partnered with ServiceNow to integrate its security insights into the platform, providing a single view of an organization's application security posture and enabling faster remediation, better collaboration, and reduced risk. The integration addresses the gap in visibility between development and security teams by tracking application vulnerabilities across the software development lifecycle (SDLC), allowing both teams to work together more effectively. With this partnership, Snyk customers can bring their existing data into ServiceNow, automating ticket creation, prioritization, and risk calculation, and sharing vulnerability information with other teams for maximum collaboration and transparency.
Jan 24, 2023
633 words in the original blog post.
Snyk continued to expand its developer-centric approach to software security in 2022 by adding several key enhancements to its existing solutions, including features to improve coding practices, identify vulnerable libraries and packages, and detect vulnerabilities in containers. The company introduced new language server support for easier integration with IDEs, expanded vulnerability detection capabilities for open source software packages, and added a software bill of materials (SBOM) feature to provide a complete view of an application's dependencies. Additionally, Snyk improved its container security features by adding base image detection and upgrade recommendations, as well as custom/golden base image support. These enhancements aim to improve the overall security of software supply chains and reduce the cost and friction associated with finding and fixing vulnerabilities.
Jan 12, 2023
1,390 words in the original blog post.
Snyk has announced the second wave of new companies joining its Technology Alliance Partner Program (TAPP), which enables software companies to build, integrate, and go-to-market with Snyk security solutions quickly and securely. Since launching the program last year, 26 new partners have joined, nearly tripling the total number of participants, demonstrating a growing need for a developer-first security ecosystem. The new partners include FossID, which brings C/C++ support and enhanced license compliance to Snyk Open Source, as well as other companies representing diverse technologies such as workflow automation, development platforms, and asset intelligence. These partners will receive turn-key technical and marketing resources to build new Snyk Apps and gain access to go-to-market collateral, sales training, and more, enabling them to create competitive advantage in developer-first security.
Jan 12, 2023
444 words in the original blog post.
The Kübler-Ross Model of open source security evolution suggests that organizations go through five stages: Denial, Anger, Bargaining, Depression, and Acceptance, as they come to terms with the extent of their reliance on open source software. To effectively embrace this role, Open Source Program Offices (OSPOs) need to bring security expertise into their teams, participate in forums like the Open Source Security Foundation's "End User" working group, and start thinking about software bill of materials (SBOM). This includes hiring or bringing in security experts, using tools like Snyk's dev-first tooling for one-click fixes for vulnerable dependencies, and starting to prioritize open source security in their development, build, and deployment processes.
Jan 12, 2023
783 words in the original blog post.
Snyk has made significant investments in improving its performance, adding new ecosystems, and supporting the enterprise in 2022. The company's Snyk Code platform has seen tremendous growth, with over 600% growth in protected projects, thanks to improvements in scalability, performance, and availability. These enhancements include optimizing the scanning engine for faster results, enabling large mono-repos to be scanned quickly and accurately, and adding interfile analysis capabilities. Additionally, Snyk has expanded its ecosystem support to include Maven, C/C++, Nexus, Gradle, and Go, with new integrations and features being released in 2023. The company has also been working on enhancing its enterprise offerings, including a new user experience, powerful reporting, and single-tenant deployment options. With a strong focus on research, development, security engineering, product management, support, technology field, sales, and marketing, Snyk aims to continue providing innovative, fast, and reliable app security solutions in 2023.
Jan 11, 2023
1,554 words in the original blog post.
Snyk has been at the forefront of developer-first application security, but realized that cloud security still follows the traditional "deploy, detect, and respond" model. They aim to break this paradigm by empowering developers to proactively secure the cloud through code (IaC) from the start. In 2022, Snyk introduced various capabilities such as IaC security checks in IDEs, Terraform Cloud and Enterprise integration, unified policy engine for all IaC and cloud workflows, and drift detection capabilities. These features enable developers to secure infrastructure earlier in the SDLC, provide context to cloud issues, and unify security across the SDLC from code to cloud. Snyk plans to continue enhancing their capabilities in 2023, including tying back cloud issues to code assets, enforcing security policies across the SDLC, and strengthening ruleset and engine's filtering capabilities for infrastructure as code.
Jan 11, 2023
1,211 words in the original blog post.
In 2022, the Snyk platform experienced significant growth, enabling over 2,500 customers to import over 6.7 million projects, execute over 3 billion tests, and fix over 5 million issues. The platform's modularity, extensibility, consistency, scalability, and security were strengthened throughout the year. Major performance improvements were introduced in some areas within the Snyk UI, and new reporting capabilities provided users with comprehensive coverage across all components of modern applications. In addition, the discovery of 1100+ zero-day vulnerabilities was achieved through improved research methodologies and automated AI-powered processes. The platform's extensibility was also strengthened with a new REST API and Snyk Apps, enabling customers and partners to customize and automate Snyk workflows. New deployment options were introduced for organizations needing complete data isolation, and developer education and learning resources were expanded. Looking forward to 2023, plans include enhancing the shared user experience across all Snyk products and improving working with the platform at scale.
Jan 09, 2023
2,059 words in the original blog post.