Snyk provides a critical security layer for CommunityBridge, a new Linux Foundation platform
We’re delighted to announce a new partnership with the Linux Foundation to support the launch of CommunityBridge.

4276 articles
4276 ARTICLES
We’re delighted to announce a new partnership with the Linux Foundation to support the launch of CommunityBridge.


This week I had the pleasure of running the Security Transformation track at QCon London. Our track tackled this very topic, and I was thrilled to have great speakers on it in Michael Brunton-spall, Gareth Rushgrove, Shraya Ramani and Kevin Gilpin. It was also great to see strong attendance (100 people at least) at every session, showing developers care to learn more about security and evolve their own security practices!

In the spirit of Interntional Women’s Day, Snyk wants to take a moment to celebrate the contributions of the women in our company and to invite our community in London to our International Women’s Day event.

n this post, we’ll look deeper into Docker images and the container ecosystems that were covered in our State of Open Source Security report, including our finding that the top ten Docker images contain over 8,000 vulnerable paths.

Snyk now integrates with Bitbucket Pipes, which allows Bitbucket users to secure their continuous integration/continuous delivery (CI/CD) workflow by finding, fixing and monitoring open-source vulnerabilities (vulns) in their application or docker image dependencies.

Only one in three developers can address a high or critical-severity vulnerability in a day or less. The more we use open source software, the more risk we accumulate as we’re including someone else’s code that could potentially contain vulnerabilities now or in the future.

A worrying 27% of respondents stated they do not have any proactive or automatic way to find out about newly discovered vulnerabilities in their applications. 37% of users of users don’t implement any sort of security testing during CI.

A good number of security vulnerabilities are discovered and fixed in non-official channels. We measured Snyk DB to uncover 67% more vulnerabilities than public databases. In 2018, new disclosures for npm grew by 47%, and Maven Central grew by 27%

Maintainers stated their security knowledge is improving but not high enough, averaging 6.6/10, and 1 in 4 open source maintainers do not audit their code bases.

Regex for for a single-threaded runtime could be devastating. We’ve also detected that the npm ecosystem has seen the most XSS vulnerabilities, Maven Central and PyPI follow next.

we found that 44% of docker image scans had known vulnerabilities, and for which there were newer and more secure base image available. Most vulnerabilities originate in the base image you selected. For that reason, remediation should focus on base image fixes.

Welcome to the first edition of a new exploit series we’re calling “Snyking In”! We’ll be looking at various security vulnerabilities, demonstrating how they can be exploited, as well as the potential risk they pose to your data and systems.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy