4 ms·
What are your problems Snyk/Dependabot out of interest?
by jackpeterfletch 6y ago
What are your problems Snyk/Dependabot out of interest?
- jollofricepeas 6y agoDependabot doesn’t work well for a Fortune 50 company or any company with a large micro services pattern because app sec teams are small. It’s really hard to provide oversight or even counsel a development team if you have no centralized view into whats happening across your organization. That’s one problem but there are others like not keeping updated to the latest versions of languages and frameworks. Snyk like most security tools lacks perspective that takes business and how product teams work into consideration. I’ve heard good things about their container security tools but their appsec stuff doesnt appear to be worth it (they demoed for us recently). We don’t need yet another tool that offers up vulns in isolation of business context. A high vulnerability is not high if compensating controls and application value aren’t considered. That’s great your tool can be yet something else that bugs my devs come deploy time. Want to be worth it? Snyk should focus on moving security left into sprint planning. If not, then they are fundamentally selling the same tools as Veracode and Synopsys.