TrustRadius Insights for Snyk are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.
Pros
Integration with CI/CD tools: Users appreciate Snyk's integration with CI/CD tools, finding it beneficial for their development process. Several reviewers have mentioned how this integration has improved their workflow and made it easier to incorporate security measures into their continuous integration and deployment pipelines.
Identifying and updating code to keep it secure: The ability to identify and update code to keep it secure is seen as a valuable feature by users. Many reviewers have praised Snyk for its effectiveness in pinpointing vulnerabilities in their codebase and providing guidance on how to resolve them, ensuring that their software remains secure.
Helpful in identifying issues with dependencies: Users find Snyk helpful in identifying issues with dependencies and providing upgrade pathways for resolving them. Numerous reviewers have mentioned that Snyk's dependency scanning capabilities have been instrumental in uncovering vulnerabilities and guiding them towards the necessary updates or patches.
We use Snyk as a mandatory pre-deployment test that is run on all pipelines before code can be sent to production. Any vulnerabilities identified are raised as tickets in Jira and assigned to the relevant team for remediation with a link to the relevant Synk page for more details on the vulnerability and how it can be fixed.This is then linked to our internal processes on how quickly the vulnerability needs to be remediated based on the CVSS score.
Pros
Reliable
Up to date
Easy to use
Clear guidance
Cons
Its a bit costly
Likelihood to Recommend
Snyk is great for monitoring library vulnerabilities which would be very difficult to keep on top of without a tool like this. We integrate it with our deployment pipelines in Gitlab to run on all the applications that are then deployed to AWS.
There is some overlap with the SAST checks that are performed by Amazon Inspector but neither covers the whole spectrum of what we need so we currently need to use both but Snyk is a key part of our defence in depth strategy.
VU
Verified User
Manager in Corporate (Information Technology & Services company, 10,001+ employees)