Company
Date Published
Author
Brian Piper
Word count
685
Language
English
Hacker News points
None

Summary

LiveRamp, a data connectivity company, was concerned about being infected with Log4Shell, a popular open source logging library vulnerability. They used Snyk to secure their CI/CD pipeline and remediated the issue, discovering that 23% of their Java projects contained the vulnerability. Snyk helped them scan containers in GCR for Log4j, which was labor-intensive but valuable for understanding container images and prioritizing remediation efforts. The company set up a pecking order for remediation, fixing customer-facing apps first, followed by internal apps. They learned the importance of having a software bill of materials (SBOM) to better understand their infrastructure dependencies. With Snyk's help, LiveRamp was able to remediate all instances of Log4Shell before the end of the year, improving their security posture and visibility into open source dependencies.