Company
Date Published
Author
Gareth Rushgrove
Word count
582
Language
English
Hacker News points
None

Summary

Snyk is a popular platform for identifying vulnerabilities and protecting open-source dependencies, and it has partnered with GitHub to integrate its security information into the native developer workflow through the launch of GitHub code scanning. With this integration, developers can now see Snyk's security information directly in their GitHub repositories, including vulnerabilities and security issues related to their application source code, assets, configuration files, etc. Additionally, Snyk's Container and Infrastructure as Code products are now compatible with GitHub code scanning, allowing developers to detect misconfigurations in their Kubernetes JSON and YAML files or Terraform code and surface those issues directly in GitHub. This integration aims to further embed security information into the developer workflow, making it easier for developers to identify and fix vulnerabilities before they reach production.