Company
Date Published
Author
Noa Korem
Word count
776
Language
English
Hacker News points
None

Summary

Snyk now integrates with Bitbucket Pipes, allowing users to secure their continuous integration/continuous delivery (CI/CD) workflow by finding and fixing open-source vulnerabilities in their application or Docker image dependencies. With the integration, Snyk scans dependencies for vulnerabilities as part of the CI/CD workflow, gates the process according to configuration, and includes a patch module to fix vulnerabilities. The Snyk pipe also monitors deployed code for new vulnerabilities and notifies users when new relevant vulnerabilities are discovered. Additionally, Snyk offers Docker image scanning, allowing users to test for vulnerabilities in their Docker images. The integration provides a comprehensive security interface across the development workflow, including source code management, pipeline, and deployment phases.