Company
Date Published
Author
Brian Piper
Word count
888
Language
English
Hacker News points
None

Summary

Kroger, a large retail giant with 2,700 stores and 400,000 employees, faces unique challenges in securing its digital supply chain due to its massive scale. To address these challenges, Kroger has implemented a shift-left approach using the full Snyk platform, integrating security practices early in the software development life cycle. This approach allows Kroger to navigate its diverse technology stack efficiently and mitigate risk proactively. The company uses Snyk Code for cross-cutting visibility into issues and to take a proactive stance on security, leveraging tools like Snyk to maximize efficiency despite its vast scale. Kroger's goal is to balance security measures with developer autonomy, ensuring the codebase is rock-solid while allowing developers to experiment with new packages. The company has successfully automated the generation of Software Bill of Materials (SBOMs) and is exploring their practical applications beyond vulnerability identification, including AI governance and compliance.