9 ms·
Snyk: Find and fix vulnerabilities in open-source dependencies
- d1str0 6y agoHow is this different from their paid, as a service version? Are we just paying for easy integration?
- timdorr 6y agoIt isn't. This is just the CLI client to their API service. All scanning happens on their servers based on data extracted by the CLI.
- Aeolun 6y agoI was under the impression there’s no scanning as such whatsoever? It just sends a list of your packages and figures out which one should be upgraded based on what they know.
- agbell 6y agoYep, it's based on the package dependencies you list, looking for packages with know reported issues.
- deleted 6y ago[deleted]
- ImpressiveWebs 6y agoIf it helps, I did a paid review of Snyk in a recent issue of my newsletter: https://mailchi.mp/webtoolsweekly/web-tools-394 https://mailchi.mp/webtoolsweekly/web-tools-394 It’s a good tool, and from what I can tell, the free version is probably enough for most small teams or sole developers. The main benefit of the paid plans seems to be the scanning on private repos and the unlimited tests for 10+ developers. But like I said, the free plan is plenty to work with.
- emersonrsantos 6y agoWhat’s the difference to npm audit?
- ajacksified 6y agoI'm not convinced their tools are better than npm audit + a license checker package, although I suppose it's nice if you want a dashboard that works for many languages instead of just Node. I've been very disappointed with their PR tools, and ended up turning off their automated PRs on _their suggestion_. (They will create dozens or hundreds of PRs to update dependencies, rather than rewriting them. Dependabot is 100x better to work with.)
- mehagar 6y agoThey use a different vulnerability database. Snyk's contains vulnerabilities that NPM's doesn't have, and vice versa. We're using them both in combination.
- slow_donkey 6y agoIt costs a lot. Especially any add-ons they upsell you on
- Twirrim 6y ago"What is snyk", shoves what looks to be a picture and leaves it at that. Eventually I clicked on it and discovered it's a video. Why not just take 5 minutes to write a quick blurb rather than making people watch a video?
- jollofricepeas 6y agoSnyk isn’t great to be honest and neither is Dependabot though I like the latter better. GitHub is the only company uniquely positioned to fix/profit from the major problem of insecure FOSS toolchains but for whatever reason they are dragging their feet on it. Features I’d like to see from GH: - Private package repository. Each package includes metadata and rank based upon if its actively maintained or includes vulns. Being a GitHub Sponsor would be mandatory for all companies using the service. - License audit: At the click of a button or api request fetch licenses for each dependency listed in your repo’s requirements.txt, gemfile, package.JSON etc. Extra points if it can flag problematic licenses automagically - Dynamic scanning: They are already offering static scans against source code might as well go a step further - Automagic secure code checklists: Scan my PR’s code and dependencies then generate a checklist for my dev teams use case. - Signed-off Exceptions: Give me the option to configure better notifications and more accountability for Dependabot. If I haven’t addressed a vulnerability then automatically communicate the risk to a reviewer. - Centralized dashboard: Let me view all vulnerabilities for all repos for my organization in one place
- sverhagen 6y agoAnd some people might feel all of that is not GitHub's job. Maybe because they like the tools that are familiar to their technology stack, for better or worse. And maybe GitHub doesn't feel like stepping into that minefield?
- underwater 6y agoGithub own npm. They're absolutely the right company to do this.
- jollofricepeas 6y agoI disagree completely. They have already stepped their foot into application security in a big way. See: https://github.com/features/security https://github.com/features/security With a little bit more concentrated effort, they could take major market share from Veracode, Synopsys and every other appsec outfit for lunch.
- ericmcer 6y agoThese confuse me because they don't align with yarn/npm audit. Which one is right? It is pretty unrealistic to dig into it myself.
- fulafel 6y agoGenerally these scanners can have two possible opinions about a dependency: "contains security bug" and "don't know" - they can't prove absence of vulnerabilities. So if tool A flags a dependency and tool B doesn't, both are likely right, and you should treat it as a flagged dependency.
- andrew_ 6y agoUntil these alerts get better at understanding context of use of a dependency, they're going to remain mostly noise. Regardless, users will obsess over them. As a maintainer, the number of issues that get opened for dependency alerts is just annoying. No, I don't care about the "low" level vulnerability on a RegExp DDoS possibility of a dependency in my development-time tool that would require a dev to DDoS themselves.
- chewyfruitloop 6y agowe have this thrust on us ... we get pull requests for point release updates but it misses entire versions it decides that packages that have legitimately been forked by a manufacturer should be replaced by the original package because it has a version bump generally it been a pain in the backside