Snyk Runtime Sensor
SnykExternal reviews
140 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Constant security and shifting left with Snyk
What do you like best about the product?
Snyk can integrate with GitHub and constantly scan certain repositories for vulnerabilities and not just when new code is pushed to the repository, allowing the application to be secure even when it is not being worked upon. Excellent UI with great reporting and filtering capabilities, that is easy and intuitive to use. Snyk can automatically create pull requests for fixing fixable vulnerabilities and allowing the code owner to fix issues fast and easily.
What do you dislike about the product?
Snyk lacks the ability to export the data regarding the vulnerabilities to an external vendor such as Datadog, allowing the customer to graph, alert and process the data. Another great addition to a great tool would be the ability to know when the vulnerability was introduced or the release affecting the vulnerability.
What problems is the product solving and how is that benefiting you?
We use the GitHub integration and scan our Docker images during CI to find vulnerabilities before pushing to production. We also receive weekly emails regarding the security posture of our applications. Using Snyk, we are able to catch vulnerabilities and fix them easily with the help of Snyk's integrations.
Inconsistent reports, odd UX, incorrect documentation, time-sink for developers
What do you like best about the product?
Not sure I can think of anything nice to say here.
What do you dislike about the product?
The reports are often flat-out incorrect (particularly w/ licensing detections). Between that and the incredible inconsistencies between what the web app and CLI reports (the docs say the CLI should be more accurate/show more, but the opposite is true), and some very annoying/insanely unintuitive UX design choices, I have zero trust in what Snyk reports, and it's a complete pain to work with. And I know I'm not alone in this opinion, as I've tried before to assume that it's just my own experience, yet time and again I'm proven wrong on this point.
What problems is the product solving and how is that benefiting you?
To be fair, it has accurately reported on a couple of actual security vulnerabilities which we were able to address. Otherwise, it seems to cause more problems than it solves (and wastes both my own and the company's time and money as a result).
Snyk Anytime... Any Day !!!
What do you like best about the product?
Snyk is the single source of truth for Vulnerabilities in the composition of your software . The easy to use interface , the depth of information and the reach of scans simply make it Awesome...
What do you dislike about the product?
IT should list out issues under two categories , one which are fixable and the other group for which no fix is available , this will improve the user focus to a much larger extent.
What problems is the product solving and how is that benefiting you?
With Snyk we are providing a level of transparency on the vulnerability profile of software composition , this information is provided with evidence and with all the technical information related to the vulnerability. This improves the decision-making ability of the product owners to prioritize fixes when the resource bucket is limited.
Recommendations to others considering the product:
All i will say is that it is the best in the market today and is a one-stop solution to all your needs around supply chain security and software composition analysis.
Best tool for DevSecOps
What do you like best about the product?
Simple and straightforward.
Easy to use.Simple way integration clearly mention source and sink and give proper remediation.
It is helpful for developer and security engineer
Easy to use.Simple way integration clearly mention source and sink and give proper remediation.
It is helpful for developer and security engineer
What do you dislike about the product?
Need improvement in report creation.
Proper executive and technical report needed.
Some time getting problem in ci/cd pipelines from Jenkin.
Need proper step by step guide
Proper executive and technical report needed.
Some time getting problem in ci/cd pipelines from Jenkin.
Need proper step by step guide
What problems is the product solving and how is that benefiting you?
Easy to find accurate bugs from code and dependency.
Now it is compatible for containers orchestration cloud.
Problem solve like fixed lots of dependency issue and upgrade lots of code after Snyk scan.
Now it is compatible for containers orchestration cloud.
Problem solve like fixed lots of dependency issue and upgrade lots of code after Snyk scan.
Recommendations to others considering the product:
This is the best tool for DevSecOps. Easy to use and iron this out by analysis.
We are completely satisfied with services.
We love to use and give efficient result .
Our client also happy due to Snyk. Now Snyk our family.
This is our original feeling for Snyk.
We are completely satisfied with services.
We love to use and give efficient result .
Our client also happy due to Snyk. Now Snyk our family.
This is our original feeling for Snyk.
Snyk provides the informed and actionable results that others do not
What do you like best about the product?
Beyond the CLI and VS Code integration, seeing the exploit maturity and quick fixes right inline makes speedy work of fixing problems. Additionally, the ability to ignore certain findings and the rich filtering can help adjust the signal-to-noise to zero in on the most urgent problems.
What do you dislike about the product?
Perhaps due to my own ignorance as a newer user, it is disheartening to hit a wall with a vulnerability with "No remediation path available". But I doubt that is a failing of the Snyk tool and system.
What problems is the product solving and how is that benefiting you?
I started with my own personal site, and now progressing to other projects. I'm also introducing Snyk as an offering to my clients, and sincerely hope they adopt it so that we can all sleep better at night.
Recommendations to others considering the product:
The initial trial should be good enough to kick the tires on some low hanging fruit on a project, and get a feel for the experience. Beyond that, try the VS Code integration and CLI tool in a Ci/Cd pipeline to further test out the features and benefits.
A Great service for Source code analysis and vulnerability detection
What do you like best about the product?
Snyk offers automatic vulnerability detection for our GitHub repos, also it warns about the vulnerability impact, direct PR to our GitHub repo is another nice feature
What do you dislike about the product?
A few false positives in the code itself which nothing to do with security, most of the time the middleware that is not public and written by us
What problems is the product solving and how is that benefiting you?
Some critical vulnerabilities in our web application, where we are not aware of it, and most of the time we ignore to think about the vulnerability impact
Recommendations to others considering the product:
Snyk is a good service I have used. As a Web Developer, I know how hackers can break into our applications, though I develop websites keeping owasp in mind. Still, I am not sure of the third-party packages like npm. We should appreciate Snyk's work before using an outdated package we can see if that nmp package has any known vulnerabilities and avoid risks at the first stage
Snyk, your best friend to fix the vulnerability
What do you like best about the product?
Easy to use, even a beginner can use it without problem. Fast, the process very fast.
What do you dislike about the product?
some vulnerable cannot be fixed automatically
What problems is the product solving and how is that benefiting you?
some vulnerables related to docker image.
I can fix all critical and high severity issues in minutes
I can fix all critical and high severity issues in minutes
Absolutely seamless experience!
What do you like best about the product?
I could directly import all my repositories from Github version control to check for vulnerabilities using a single click! Also, the vulnerabilities are classified as Low, Medium, High, Critical, etc to help which ones require immediate fixing. The best part is that I can directly create a PR to fix those vulnerabilities and the whole process is so smooth.
What do you dislike about the product?
As of now, I haven't used any other tool as good as Snyk and would recommend trying this out at least once! I couldn't find anything which does not fit my needs.
What problems is the product solving and how is that benefiting you?
I am currently a student and an upcoming software engineer at a big software solutions company. I used Snyk once to test it out and would probably be using more in the future as well.
Scanning & enforcing our Infrastructure permissions & configurations using AWS IAM Role for Fugue
What do you like best about the product?
Fugue offers regulatory health checks in our AWS platform, evaluating our cloud compliance and matching it with our customer standards and organization policies. Ruleset definitions can be made through built-in privileges or custom privileges based on our requirements. It acts as a centralized posture management utility for our cloud platform for resource control access and security compliance.
What do you dislike about the product?
For our enterprise reporting, Fugue facilitates our AWS cloud footprint analytics which is customizable through its dashboard utility. These reports are securely stored in our Amazon S3 buckets and also shared with our clients through Amazon SNS subscription. Overall, I'm satisfied with the solutions offered by Fugue for our cloud resources & SDLC management.
What problems is the product solving and how is that benefiting you?
Before performing our deployments in our client environments, we need to ensure the security standards & configurations across multiple AWS regions. Fugue provides a Unified policy engine that is capable of overviewing our cloud compliance and governance both in the pre-deployment stage and post-deployment stage. Fugue Role needs to be assigned through AWS IAM service, and our IaC scripts are deployed with the help of the AWS CloudFormation stack feature. Prior to the deployment, scanning is done to ensure proper security audits, and rescanning can also be specified after the deployment is complete.
Fugue - stop searching!
What do you like best about the product?
Ease of use, nice user experience and look-and-feel, simple overview and fast SaaS service
What do you dislike about the product?
Nothing really, it was a bit clutterly in the beginning, but there has been a lot of improvements, keep up the good work with your backlog
What problems is the product solving and how is that benefiting you?
Fast and realiable results from the dashboard, easy to fix misconfigs and rules
showing 91 - 100