Cyber Security
4276 articles
4276 ARTICLES

So, you think your CI/CD environment is secure?
This post, co-written by Weaveworks and Snyk, explains how by using a GitOps continuous integration (CI)/continuous delivery (CD) pipeline combined with good security practices improves the overall security of your development workflow to Kubernetes.

10 npm Security Best Practices
Concerned about npm vulnerabilities? It is important to take npm security best practices into account for both frontend, and backend developers. Open source security auditing is a crucial part of shifting security to the left, and npm package security should be a top concern, as we see that even the official npm command line tool has been found to be vulnerable.

Introducing The Secure Developer community
Today Snyk is happy to announce the launch of The Secure Developer, a community and educational resource for all things security. We’ll bring together the greatest security experts to share their experiences on building security into their workflows, discussing tools that can help, and reviewing good and bad practices seen in the real world.

A serious security flaw in runC can result in root privilege escalation in Docker and Kubernetes
A security flaw discovered by Adam Iwaniuk and Borys Popławski and found in open source software runC was disclosed on February 11th, 2019 and described in CVE-2019-5736.

My first week at Snyk was at our All Hands Conference

How to Use GraphQL Nexus with a Database | Prisma
Learn how to connect GraphQL Nexus to a database with Prisma Client and the Nexus Prisma plugin.

Scanning Docker images for key binaries - going beyond package managers
We’re happy to share that we’ve just extended our Docker scans to now include scanning key binaries that were manually installed on the Docker image. Up until now, we only scanned OS packages that were installed by OS package managers such as dpkg, apk or rpm.

GraphQL Nexus: Code-First GraphQL Server Development | Prisma
Meet GraphQL Nexus, a code-first library for building GraphQL servers with type-safe schemas and a better developer workflow.

Cloud infrastructure drift: The good, the bad, and the ugly
Infrastructure misconfiguration is the leading cause of data breaches in the cloud, and a big reason misconfiguration happens is infrastructure configuration “drift.” While some drift events can lead to data breaches, not all of it is bad. Understanding the distinctions is important if you’re responsible for cloud security and compliance.

NumPy arbitrary code execution vulnerability
A recently discovered vulnerability in NumPy, the widely used open source package for scientific computing in Python, allows for the execution of arbitrary, potentially malicious code.

Launching .NET support for GitHub, Bitbucket and GitLab
As of today, Snyk enables importing, scanning and monitoring of .NET projects directly within GitHub, GitLab, and Bitbucket without having to move away to Snyk.
