Snyk Pros

Nixon Bagalkoti - PeerSpot reviewer
Cyber Security Lead at a media company with 201-500 employees
A main feature of Snyk is that when you go with SCA, you do get properly done security composition, also from the licensing and open-source parameters perspective. A lot of companies often use open-source libraries or frameworks in their code, which is a big security concern. Snyk deals with all the things and provides you with a proper report about whether any open-source code or framework that you are using is vulnerable. In that way, Snyk is very good as compared to other tools.
View full review »
MG
Director of Architecture at a tech vendor with 201-500 employees
It is easy for developers to use. The documentation is clear as well as the APIs are good and easily readable. It's a good solution overall.
View full review »
Nawal Singh - PeerSpot reviewer
Senior DevSecOps/Cloud Engineer at Valeyo
It has a nice dashboard where I can see all the vulnerabilities and risks that they provided. I can also see the category of any risk, such as medium, high, and low. They provide the input priority-wise. The team can target the highest one first, and then they can go to medium and low ones.
Its reports are nice and provide information about the issue as well as resolution. They also provide a proper fix. If there's an issue, they provide information in detail about how to remediate that issue.
View full review »
Buyer's Guide
Snyk
November 2022
Learn what your peers think about Snyk. Get advice and tips from experienced pros sharing their opinions. Updated: November 2022.
655,113 professionals have used our research since 2012.
UmarQureshi - PeerSpot reviewer
Security Lead at a retailer with 10,001+ employees
I think all the standard features are quite useful when it comes to software component scanning, but I also like the new features they're coming out with, such as container scanning, secrets scanning, and static analysis with SAST.
View full review »
AP
Security Consultant
The advantage of Snyk is that Snyk automatically creates a pull request for all the findings that match or are classified according to the policy that we create. So, once we review the PR within Snyk and we approve the PR, Snyk auto-fixes the issue, which is quite interesting and which isn't there in any other product out there. So, Snyk is a step ahead in this particular area.
View full review »
NK
Cloud Security Engineer at a manufacturing company with 10,001+ employees
There are many valuable features. For example, the way the scanning feature works. The integration is cool because I can integrate it and I don't need to wait until the CACD, I can plug it in to our local ID, and there I can do the scanning. That is the part I like best.
View full review »
ZvikaRonen - PeerSpot reviewer
Chief Technology Officer at FOSSAware
The most valuable feature of Snyk is the software composition analysis.
View full review »
JH
Senior Devops at Appgate
Provides clear information and is easy to follow with good feedback regarding code practices.
View full review »
Danie Joubert - PeerSpot reviewer
Managing Director at ProQuanta
The solution has great features and is quite stable.
View full review »
DK
Security Solutions Architect at a tech services company with 51-200 employees
Snyk is a developer-friendly product.
View full review »

Snyk Cons

Nixon Bagalkoti - PeerSpot reviewer
Cyber Security Lead at a media company with 201-500 employees
It can be improved from the reporting perspective and scanning perspective. They can also improve it on the UI front.
View full review »
MG
Director of Architecture at a tech vendor with 201-500 employees
We would like to have upfront knowledge on how easy it should be to just pull in an upgraded dependency, e.g., even introduce full automation for dependencies supposed to have no impact on the business side of things. Therefore, we would like some output when you get the report with the dependencies. We want to get additional information on the expected impact of the business code that is using the dependency with the newer version. This probably won't be easy to add, but it would be helpful.
View full review »
Nawal Singh - PeerSpot reviewer
Senior DevSecOps/Cloud Engineer at Valeyo
It would be great if they can include dynamic, interactive, and run-time scanning features. Checkmarx and Veracode provide dynamic, interactive, and run-time scanning, but Snyk doesn't do that. That's the reason there is more inclination towards Veracode, Checkmarx, or AppScan. These are a few tools available in the market that do all four types of scanning: static, dynamic, interactive, and run-time.
We have to integrate with their database, which means we need to send our entire code to them to scan, and they send us the report. A company working in the financial domain usually won't like to share its code or any information outside its network with any third-party provider.
View full review »
Buyer's Guide
Snyk
November 2022
Learn what your peers think about Snyk. Get advice and tips from experienced pros sharing their opinions. Updated: November 2022.
655,113 professionals have used our research since 2012.
UmarQureshi - PeerSpot reviewer
Security Lead at a retailer with 10,001+ employees
For the areas that they're new in, it's very early stages for them. For example, their expertise is in looking at third-party components and packages, which is their bread-and-butter and what they've been doing for ages, but for newer features such as static analysis I don't think they've got compatibility for all the languages and frameworks yet.
View full review »
AP
Security Consultant
All such tools should definitely improve the signatures in their database. Snyk is pretty new to the industry. They have a pretty good knowledge base, but Veracode is on top because Veracode has been in this business for a pretty long time. They do have a pretty large database of all the findings, and the way that the correlation engine works is superb. Snyk is also pretty good, but it is not as good as Veracode in terms of maintaining a large space of all the historical data of vulnerabilities.
View full review »
NK
Cloud Security Engineer at a manufacturing company with 10,001+ employees
Basically the licensing costs are a little bit expensive.
View full review »
ZvikaRonen - PeerSpot reviewer
Chief Technology Officer at FOSSAware
The reporting mechanism of Snyk could improve. The reporting mechanism is available only on the higher level of license. Adjusting the policy of the current setup of recording this report is something that can improve. For instance, if you have a certain license, you receive a rating, and the rating of this license remains the same for any use case. No matter if you are using it internally or using it externally, you cannot make the adjustment to your use case. It will always alert as a risky license. The areas of licenses in the reporting and adjustments can be improve
View full review »
JH
Senior Devops at Appgate
The feature for automatic fixing of security breaches could be improved.
View full review »
Danie Joubert - PeerSpot reviewer
Managing Director at ProQuanta
The log export function could be easier when shipping logs to other platforms such as Splunk.
View full review »
DK
Security Solutions Architect at a tech services company with 51-200 employees
Compatibility with other products would be great.
View full review »
Buyer's Guide
Snyk
November 2022
Learn what your peers think about Snyk. Get advice and tips from experienced pros sharing their opinions. Updated: November 2022.
655,113 professionals have used our research since 2012.