Enterprise security best practices for managing vulnerabilities at scale
How do you ensure effective security compliance across several teams when they experience an overwhelming number of vulnerabilities that need to be addressed?

4276 articles
4276 ARTICLES
How do you ensure effective security compliance across several teams when they experience an overwhelming number of vulnerabilities that need to be addressed?


Though it might seem a small step towards promoting D&I within our culture, creating inclusive job descriptions is something Snyk is focused on putting time into, and getting right.

This vulnerability report highlights several challenges that we face in the Node.js Security Working Group as security analysts who need to respond to security incidents.

This post discusses the OWASP Top 10 proactive controls and how to incorporate them into our web applications.

Even when running rootless, it’s always good practice to understand exactly what your container needs, and only give it those minimum permissions.

Prisma Studio is a visual database browser for viewing and editing application data, with filtering, pagination, and relation-aware workflows for Prisma projects.

During SnykCon 2020, author and researcher Gene Kim sat down with Snyk co-founder and President Guy Podjarny and a small group of Snyk VIPs to talk about (Sec)DevOps—where we started, how far we’ve come, and strategies for getting the most value out of the practice. This post contains a few of the most interesting takeaways from the conversation.

Snyk has had the ability to test your Docker images using our CLI for over a year now. With the latest release of the CLI, we’re improving the user experience for container users, as well as adding a few more useful features for advanced users.

At last week’s SnykCon, Snyk’s Co-founder and President Guy Podjarny sat down with Adrian Ludwig, CISO of Atlassian for a fireside chat about the modern security market, how his security team is structured, and how to help developers embrace security.

Prisma 2.10 added preview support for Microsoft SQL Server, expanding Prisma’s database coverage for teams building with SQL Server.

“The safest thing is to do nothing” is a great cliche, but in the case of software security, this is almost never the case. Starting with the very first line of code we write, the line has been crossed—we have introduced security risk that needs to be managed.

Welcome to the Snyk Monthly Vulnerability Profile. This month we’re looking at a Regular Expression Denial of Service (REDoS) vulnerability discovered in the popular UAParser JavaScript package.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy