Snyk Runtime Sensor
SnykExternal reviews
144 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Tried on docker images well suited.
What do you like best about the product?
Dependency and vulnerability scanning with report excellent.
What do you dislike about the product?
Only support less than 2GB images needed
What problems is the product solving and how is that benefiting you?
overview about security issues for prod
Well architected
What do you like best about the product?
Seamless integrations with repo and IDE. The initialization in Visual Studio code was ridiculously smooth and did not take manual config.
What do you dislike about the product?
It leaves behind clutter branches, etc. There is probably an easy way to clean them up other than manual deletion (if they are out of date) but I just don't know it.
What problems is the product solving and how is that benefiting you?
Actionable intelligence on package security
Must needed tool for software supply chain security
What do you like best about the product?
Easy to use cli and native integration with "docker scan" command.
What do you dislike about the product?
Sometimes synk cannot identify/scan binaries that were copied into the container image
What problems is the product solving and how is that benefiting you?
Synk helps us scan the codebase with SAST to find any security issues and does an excellent job of scanning container images for vulnerabilities.
Does not allow you making mistakes you did not know you make
What do you like best about the product?
It is easy to use and developer friendly. You can easily test a project locally or let snyk monitor the project from the ci. The quality gate makes sure, you do not introduce new mistakes in your merge requests.
What do you dislike about the product?
The need for a Snyk Broker when working with a self hosted Gitlab instance. We recently moved from the Gitlab SaaS service to a self hosted environment. It was partly our mistake for not reading the Snyk documentation well enough, but now we need a broker for it to monitor our projects
What problems is the product solving and how is that benefiting you?
Snyk monitors our projects for security mistakes in the dependencies. Some projects are on a security only maintenance mode, which is a lot easier with Snyk. But it also monitors the main projects and makes it easy to fix security issues
very good so far, need a little improvment in the user experience.
What do you like best about the product?
I like how it can analyze the package.json file in a node.js project and the fix pulls. Also, I like that it's free.
What do you dislike about the product?
I wish you had added a better way to handle multiple analysis options in a single project. For example, I have a nodeJS project with a package.json and code analysis; they have different pages on the UI, and as I tested, there is no easy way to navigate from one to another. Although they are in the same project, it seems that they are treated as two different projects
What problems is the product solving and how is that benefiting you?
Fixing vulnerabilities in my codebase and keeping up-to-date with security fixes. I previously did not care about vulnerabilities as it required time that I don't have, but when it comes to production in a sensitive field, I realize that a small error could lead to a law suite.
With Fugue's Unified Policy Engine we can consistently govern security & compliance across our SDLC
What do you like best about the product?
Fugue is efficient when it comes to defining remediation approaches for every violations. It manages runtime security for our cloud-native applications & detects both regular and complicated vulnerabilities. It also provides one-click compliance reporting, which is fast & convenient for our AWS infrastructure requirements.
What do you dislike about the product?
We can easily enable automated remediation features for resources that are deployed in the Production environment. It dramatically reduces various risks, underutilized resource expenditures & compliance governance. We are satisfied with the services offered by Fugue for our security policies & posture management.
What problems is the product solving and how is that benefiting you?
Fugue effectively simplifies time spent on manual audits & tracking vulnerabilities for our AWS deployments. With its configuration management tool, we can evaluate misconfigurations & drifts between Dev, QA and Prod environments. It offers many pre-built rules for our compliance framework. We ensure that all policies are adequately poised across our SDLC with the aid of its Unified Policy Engine.
Snyk - a one stop solution for your security needs
What do you like best about the product?
He fact that one can easily add the projects connected to a version control system on the fly and run scans for detecting security issues scheduled too!
What do you dislike about the product?
Nothing as of now I came across to comment
What problems is the product solving and how is that benefiting you?
Snyk quickly helped us assess if our projects ran into log4j security threats
Snyk is good, easy and accurate results. Very helpful to mitigate the Vulnerabilities .
What do you like best about the product?
Easy to maintain, ui is very interactive no need of doing the longer installation. Developer friendly.
What do you dislike about the product?
Nothing as such, i liked the tool because of its simplicity.
What problems is the product solving and how is that benefiting you?
Mitigating the errors
Snyk Review
What do you like best about the product?
Snyk is a tool worth investing in.
We have been using it's open source version/SCA for some time and it rightly keeps the developer-first approach.
It's good to see that it has integration with the majority of CI/CD tools.
Good luck and keep innovating!
We have been using it's open source version/SCA for some time and it rightly keeps the developer-first approach.
It's good to see that it has integration with the majority of CI/CD tools.
Good luck and keep innovating!
What do you dislike about the product?
We have however to validate the scorecard with other sources too and be 100% sure that a vulnerability is claimed as serious as depicted.
What problems is the product solving and how is that benefiting you?
We like a unified UI showing vulnerabilities ordered by the scores and the proposals to mitigate them.
It is very easy to integrate with pielines
What do you like best about the product?
Integration with pipelines and cheap. Snyk works extremely well with the poetry.lock files
What do you dislike about the product?
npm integration not working well. it's a bit more complicated with the setup.py workflow we currently have in the libraries.
What problems is the product solving and how is that benefiting you?
snyk works great with poetry lock files but is complicated with setup.py files in repositories
showing 31 - 40