Improved security testing for git-based Gradle projects using lockfile
Over the past year, we have been working hard to improve our testing for Gradle projects imported from Git repositories by making it more reliable, accurate, and scalable.

4276 articles
4276 ARTICLES
Over the past year, we have been working hard to improve our testing for Gradle projects imported from Git repositories by making it more reliable, accurate, and scalable.


Snyk’s Liran Tal shares ten tips for getting that Call For Papers (CFP) proposal accepted into a conference.

In this post, we will explore how Kubernetes container isolation impacts privilege escalation attacks. We will use common kernel exploitation techniques to figure out how container abstractions layers can hinder our path to that precious root shell.

In this article, we’re featuring 10 git aliases that can help with a faster and more productive git workflow as an individual, or within a team.


Most of the engineering managers I have met have assigned their senior engineers to lead all the critical features, but I would like to “turn the senior engineer around” and suggest the opposite: the more senior you are, the less you lead engineering efforts in the team.

Let’s take a look at some of the popular Infrastructure as Code tools and what security hardening measures you can apply at the code level to protect your applications and platforms.

Tips on how to get the most out of the Snyk CLI as a tool to test, monitor, and remediate known vulnerabilities in your applications

Command injection attacks—also known as operating system command injection attacks—exploit a programming flaw to execute system commands without proper input validation, escaping, or sanitization, which may lead to arbitrary commands executed by a malicious attacker.

This post suggests some best practices, and discusses how maintainers and developers can adopt DevSecOps tools for open source projects to better improve their security posture.

Welcome to the Snyk Monthly Vulnerability Profile. This month we’re looking at a buffer overflow vulnerability discovered in the FreeType package used by Chromium and the subsequent work by Snyk to locate open source packages impacted by inclusion of vulnerable Chromium components.

In this blog, we’ll discuss the release process for our Kubernetes Operator, and show how we’ve automated deploying the release across multiple repository targets.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy