Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

4 AWS reviews

External reviews

140 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Lokesh T.

Developer Centric Platform || Snyk

  • January 24, 2025
  • Review provided by G2

What do you like best about the product?
Recently they came with feature called, Deep code AI, using this we can fix the issue for 1st party cod in IDE level
What do you dislike about the product?
It doesnt have On-prem, And also we cannot push the SAST results to the Dashboard from CLI
What problems is the product solving and how is that benefiting you?
Snyk is covering from code to cloud and back to code. Which means it is having a wide range of integration in each and every stage of SDLC


    meetharoon

Affordable tool boosts code scanning efficiency but faces integration hurdles

  • November 27, 2024
  • Review from a verified AWS customer

What is our primary use case?

I lead a code security practice for our organization. We integrated Snyk into our GitHub, using CLI to automatically scan codebases and identify issues. We are a large organization with three independent entities, consolidating Snyk across all entities.

We also provide access through numerous CI/CD tools. Our default implementation mechanism is CLI, but we also use the Web UI for a comprehensive view and recommendations.

How has it helped my organization?

For large organizations like ours, cost is a major factor. Snyk is the most cost-effective solution compared to others like Checkmarx.

We consolidated Snyk across three entities that used different tools. As a result, our organization became one of the largest in implementing Snyk.

What is most valuable?

The most important feature of Snyk is its cost-effectiveness compared to other solutions such as Checkmarx. It is easy to consolidate Snyk across multiple entities within a large organization.

Additionally, our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.

What needs improvement?

Snyk has several limitations, including issues with Gradle, NPM, and Xcode, and trouble with AutoPR. It lacks the ability to select branches on its Web UI, forcing users to rely on CLI or CI/CD for that functionality. These limitations were documented in a book that I wrote.

For how long have I used the solution?

We implemented Snyk starting last year, and it has been in use for around two and a half years.

What do I think about the scalability of the solution?

Snyk allows for scaling across large organizations, accommodating tens of thousands of applications and over 60,000 repositories, making it suitable for wide-scale deployment.

How are customer service and support?

Our organization maintains a good relationship with Snyk's customer support team. Despite potential variations in service quality for smaller organizations, our long-standing association has ensured smooth communication, resulting in favorable support experiences and satisfactory issue resolution.

Which solution did I use previously and why did I switch?

Previously, we used Synopsys Coverity and later migrated to Checkmarx and Mend before Snyk. Synopsys Coverity was costly, prompting a switch. Snyk's affordability and consolidating capabilities across the entities led to its adoption.

How was the initial setup?

The initial setup of Snyk is simple and straightforward compared to Synopsys Coverity, which is complex. Checkmarx falls in between, not too complicated or easy, but a reliable option. Snyk's ease of implementation makes it user-friendly.

What about the implementation team?

We have different teams managing aspects like licensing and engagement with the support team. They facilitate setup and maintenance, optimally integrating Snyk into our GitHub and CI/CD processes.

What's my experience with pricing, setup cost, and licensing?

Snyk is recognized as the cheapest option we have evaluated. In comparison to eight or nine other solutions, it ranks among the most affordable, providing cost-effective scalability across organizational units.

Which other solutions did I evaluate?

In my comparative evaluations, I considered tools like AppScan, Veracode, Checkmarx, Synopsys Coverity, and six to eight other alternatives.

What other advice do I have?

Snyk is optimal for organizations starting or looking for an affordable, effective tool. Despite false positives, it combines SAST, SCA, containers, and IaS in one Web UI. On a scale of one to ten, I rate Snyk at six.


    Diego Moreo

Enhancing security awareness, and finds major issues while managing risks effectively

  • October 07, 2024
  • Review provided by PeerSpot

What is our primary use case?

The main tool today is used to check for security issues in our products. We use it to analyze all the projects, and our security efforts are based partly on this tool.

How has it helped my organization?

There are major impacts related to increasing security awareness and managing risks. Snyk has been an essential tool in that aspect.

What is most valuable?

The valuable aspect is its security capabilities. The tool finds any major issue, and the code is blocked from being promoted to production until the issue is corrected.

What needs improvement?

I'm not responsible for the tool. As far as I know, there are no major concerns or features that we lack. We had some issues integrating into our pipeline, however, they were resolved.

For how long have I used the solution?

We have used Snyk for approximately one year.

What do I think about the stability of the solution?

There are no complaints from the security team. There seem to be no major issues of concern.

What do I think about the scalability of the solution?

The security team is responsible for this tool. I don't have more details, however, there are no complaints, so I believe that's okay.

How are customer service and support?

I don't know about the support or customer service details. It's another team's responsibility.

Which solution did I use previously and why did I switch?

I don't have experience with other products similar to Snyk.

What was our ROI?

I wouldn't be able to say what the company's ROI is.

What's my experience with pricing, setup cost, and licensing?

The pricing and setup are not my responsibilities, so I don't know any details.

Which other solutions did I evaluate?

I have not evaluated any other solutions.

What other advice do I have?

Based on our experience and what I have heard internally, I would recommend Snyk.

I'd rate the solution nine out fo ten.


    Computer & Network Security

Bad Customer support, Lots of bugs and a non-working product

  • August 21, 2024
  • Review provided by G2

What do you like best about the product?
Integrate with most major code repo's. but the integration is not amazing.
What do you dislike about the product?
Customer support is slow to respond, usually not helpful and ended up escalating to a developer, that's when we lost all contact and did not get a solution to a clear bug that prevents us from using the product.
Another really important note around SBOM, the CLI does not provide all the information that you get from the UI, the solution provided was to use another tool to extract data. not sure why we pay for a product if we need to use outside, 3rd party tools to get the information we need.
What problems is the product solving and how is that benefiting you?
Security scanning, SBOM.


    Nitish U.

Very Good SAST tool to begin with

  • August 19, 2024
  • Review provided by G2

What do you like best about the product?
Integration with both Bitbucket and Github, policy as a code,
What do you dislike about the product?
Too much unnecessary false positives, policy overrides, hard and complex to manage and track alerts
What problems is the product solving and how is that benefiting you?
Help in reducing efforts on Manual VAPT, helps in identifying muliple vuln in a single package thus reduces effort to mitigate vuln with minimum number of upgrades and patches


    Information Technology and Services

Very helpful and feature rich tool

  • July 13, 2024
  • Review provided by G2

What do you like best about the product?
Great integration with version control tools like Github and Bitbucket
What do you dislike about the product?
Initially when using Snyk it was a bit confusing, but since then they have improved all the UX and features.
What problems is the product solving and how is that benefiting you?
Using Snyk as our primary security tool offers us a lot of benefits from SAST to vulnerabiltiy scanning.


    NguyễnHuy

Supports multiple programming languages for security practices

  • May 28, 2024
  • Review provided by PeerSpot

What is our primary use case?

Snyk protects vulnerabilities in the code as usual, detects abnormal data flow inside the field, and similar tasks.

How has it helped my organization?

The specific feature of Snyk that has significantly improved my vulnerability management is its ability to identify vulnerabilities and suggest solutions to fix them. Snyk's automation capabilities streamline my security tasks by scanning code every time I commit.

What is most valuable?

Snyk's focus on security is a valuable feature. Also, Snyk supports multiple programming languages, which has positively affected my security practices. I use only two or three languages, and when I change the language in a file, it detects it in the same suite.

I find the AI-powered scanning beneficial. Using Snyk's AI-powered scanning, I can detect around ten or twenty errors in my project with about twenty thousand lines of code, so it helps improve my project by identifying a lot of potential vulnerabilities.

What needs improvement?

I use Snyk alongside Sonar, and Snyk tends to generate a lot of false positives. Improving the overall report quality and reducing false positives would be beneficial.

I don't need additional features; just improving the existing ones would be enough.

What do I think about the stability of the solution?

It scans the entire code really fast, and the auto-scan process is done repeatedly.

I would rate the stability of Snyk an eight out of ten.

What do I think about the scalability of the solution?

It detects issues really fast, but it still has a lot of false positives, and sometimes the suggestions aren't quite on point. This can sometimes lead to other vulnerabilities.

I would rate the scalability of Snyk a seven out of ten.

How was the initial setup?

I would rate the initial setup of Snyk a nine out of ten because it's straightforward. The web version is also easy to use. I'm working with both the web version and the IDE at the same time.

For deployment, I just link it to GitHub, upload the repository there and it automatically scans for any errors. It took around a minute to deploy Snyk.

What's my experience with pricing, setup cost, and licensing?

I'm currently using the free version, which the company offers before buying the full version. So, the price is affordable, especially for an enterprise.

Which other solutions did I evaluate?

I did evaluate other options before choosing Snyk. I only considered Sonar before Snyk, but I ended up with Snyk because it's faster and more focused on security.

What other advice do I have?

My advice for others considering using Snyk is to rely on it for security issues but still manually review your overall code. It's great for detecting syntax errors but might miss some broader issues, so it's important to do a thorough check yourself.

Based on my experience, I'd rate Snyk an eight overall. Its performance is indeed good.


    Ryan C.

Very quick to find security issues with code bases

  • March 20, 2024
  • Review provided by G2

What do you like best about the product?
I think it is so easy to use. I like that it includes solutions to the issues I have, it can quickly scan a codebase and will constantly scan it. We had no issues including it into our code base.
What do you dislike about the product?
The solutions sometimes overlap and don't coincide. Another issue I could say would be pricing.
What problems is the product solving and how is that benefiting you?
We have had some security issues in the code base we never would have realized without it.


    reviewer1165062

Possesses good ability to highlight security vulnerabilities

  • March 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the tool in my company to scan open-source projects.

What needs improvement?

I don't use Snyk anymore. The tool is just used in our company, but not by me anymore.

It is important that the solution has the ability to match up with the OWASP Top 10 list, especially considering that sometimes, it cannot fix certain issues. Users might face 100 vulnerabilities during the production phase, and they may not be able to fix them all. Different companies have different levels of risk appetite. In a highly regulated industry, users of the product should be able to fix all the vulnerabilities, especially the internal ones. The tool should provide more flexibility and guidance to help us fix the top vulnerabilities before we go into production.

For how long have I used the solution?

I have been using Snyk for three years. I am a user of the tool.

How are customer service and support?

The solution's technical support is okay. I rate the technical support an eight out of ten.

What's my experience with pricing, setup cost, and licensing?

The product's price is okay. My company isn't actively looking for replacement tools.

What other advice do I have?

The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.

The integration features of the product are okay.

I recommend the product to those who want to buy it.

In a general sense, Snyk is a good product that can be used for governance. If you use a lot of open-source software, Snyk is an application testing tool you can buy.

I rate the tool a seven to eight out of ten.


    Jayashree Acharyya

Used for image scanning and identifying vulnerabilities, but its integration with other services could be improved

  • March 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

We are using an enterprise version of Snyk for image scanning. We use Snyk to identify and address vulnerabilities in our open-source dependencies and to scan the Docker images.

What is most valuable?

The solution's Open Source feature gives us notifications and suggestions regarding how to address vulnerabilities.

What needs improvement?

The solution's integration with JFrog Artifactory could be improved.

For how long have I used the solution?

We have been using Snyk for two years.

What do I think about the stability of the solution?

I rate the solution an eight out of ten for stability.

What do I think about the scalability of the solution?

We use Snyk for microservices, and more than 100 users use it in our organization twice a week.

I rate the solution a seven out of ten for scalability.

How are customer service and support?

The solution’s technical support team was involved during the architecture integration. We got their support, but I think we could probably get a faster response from them.

How was the initial setup?

Snyk's initial setup is not very difficult.

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a seven out of ten.

What about the implementation team?

The solution's initial setup took a few weeks. The solution's deployment was done by our app system, and four people were highly engaged in this activity.

Which other solutions did I evaluate?

Before choosing Snyk, we were exploring different solutions like JFrog Xray and Aqua scan for image scanning. We chose Snyk because we could do both image scanning and SCA with it.

We are comparing Snyk with GitHub Advanced Security, which has a better vulnerability database. They have more vulnerabilities enlisted in their database.

What other advice do I have?

The solution has improved or streamlined our process a lot for securing container images. We wanted to make sure we are deploying the secure Docker images. Snyk allowed us to check whether it is following our standard of docker images or not.

We use Azure DevOps as our platform, and Snyk's integration with Azure DevOps was okay. However, Snyk's integration with JFrog Artifactory didn't go well. We use JFrog Artifactory to store the artifacts we download. We wanted to integrate Snyk with JFrog Artifactory to scan the binary artifacts we downloaded, but that broke our JFrog Artifactory for some reason. Instead of using it there, we are calling it directly from the pipeline.

Snyk's automation features significantly reduced remediation times a couple of times. Sometimes, our developers scan the code from the environment and find some Java vulnerabilities. We fixed those vulnerabilities in the lower environment itself. The solution does not require any maintenance.

The accuracy of Snyk's vulnerability detection is pretty good compared to other tools. I rate the solution's vulnerability detection feature an eight out of ten. I would recommend Snyk to other users because it is easy to implement and integrate with Azure DevOps and GitHub.

Overall, I rate the solution a seven out of ten.