Announcing the 2017 State of Open Source Security Report
Today we’re excited to launch the 2017 State of Open Source Security Report! The full report is available as a free PDF, and the highlights are collected online.

4276 articles
4276 ARTICLES
Today we’re excited to launch the 2017 State of Open Source Security Report! The full report is available as a free PDF, and the highlights are collected online.


Learn the basics of GraphQL schemas, type definitions, and resolvers, and how they fit together in GraphQL server development.

Whether a vulnerability is currently exposed or not matters, but only in prioritization. Where its exploitable today or not, leaving it unaddressed is a unnecessarily risky decision.

Learn about Apollo Client 2.0, including Apollo Link, local state management, cache updates, and the biggest changes from earlier Apollo Client releases.

One of the biggest bottlenecks in security is ’triaging’—the process of validating if a security alert is actually impacting your organization, sizing up the estimated impact, and figuring out how to resolve it. In this article, we’ll make the case that we should all be striving to skip triaging and focus on fixing vulnerabilities instead.

Earlier this year we ran a test on the top 5,000 URL’s on the web and found that 76.6% of them were running a JavaScript library with at least one known security vulnerability. It’s a frighteningly large number. That’s why we’re proud to announce that Snyk now powers the vulnerable JavaScript libraries linter in Microsoft’s Sonar—an open-source linting tool for developers.

Python 3 and Python 2 have various functional differences. On their own, they’re not necessarily better or worse (though arguably Python 3 should be an improvement), but any change may introduce risk. This post highlights and explains a few differences between the versions that have security implications.

Where just a few months ago we launched Snyk for Serverless, we are now taking it to the next level by launching the Snyk Heroku Add-On. The add-on is currently in beta, which means it’s free to try out! We’re looking for people to take it for a test drive and provide us with some feedback.

After years of preparation and debate, the General Data Protection Regulation (GDPR) was finally approved by the EU with enforcement starting as early as May 2018, at which time those organisations in non-compliance will face heavy fines. In this post we explain how that impacts companies using open-source and how they can protect themselves.



Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy