What is our primary use case?
My main use case for Snyk is to identify security vulnerabilities in application code and dependencies during the development lifecycle, before the code is deployed to production.
Once developers develop and push code to the repository, Snyk can scan the code and identify potential vulnerabilities early in the development process. Before implementing Snyk, we did not have a dedicated tool to identify vulnerabilities before deployment. This meant that some security issues could only be identified after the application was already deployed, where tools such as CrowdStrike could help detect security-related issues at the endpoint or runtime level.
With Snyk, we can shift security testing earlier in the Software Development Lifecycle (SDLC). Developers can identify and address vulnerabilities while they are developing and testing the application, rather than discovering them after deployment.
This is particularly important because we want to minimize the risk of security issues reaching production. Fixing vulnerabilities after deployment can potentially impact production environments and, ultimately, our customers. By integrating Snyk into our development and CI/CD process, we can identify vulnerabilities earlier, give developers an opportunity to remediate them before release, and improve the overall security and stability of our applications.
In summary, our primary goal is to shift security left by identifying and remediating vulnerabilities before code reaches production, reducing production risk and protecting our customers.
How has it helped my organization?
Snyk has had a significant positive impact on our organization by allowing us to identify and address security vulnerabilities earlier in the software development lifecycle. Before implementing Snyk, we did not have a dedicated tool to identify vulnerabilities in our code and dependencies before deployment.
After implementing Snyk, we were able to shift security testing to the development stage, allowing developers to identify and remediate vulnerabilities before the code reaches production. This has helped us reduce security risks, improve the overall quality of our code base, and avoid the additional time and effort involved in resolving vulnerabilities after deployment.
One of the most significant benefits has been the reduction in vulnerabilities across our services and dependencies. Previously, we were dealing with approximately 800–900 vulnerabilities across the dependencies used by our services. After implementing Snyk and following its recommendations, we have reduced these vulnerabilities by approximately 80–90%.
The remaining vulnerabilities are primarily associated with applications and code running on older infrastructure. We are actively working on migrating and modernizing these components, using Snyk's recommendations to identify the required remediation actions and prioritize improvements.
Overall, Snyk has helped us establish a more proactive security approach, reduce security-related incidents, improve code quality, and save development and operational time by addressing vulnerabilities before they reach production
What is most valuable?
These integrations are particularly valuable for our day-to-day development and security processes because they allow us to integrate vulnerability scanning directly into our existing development and CI/CD workflows. We can scan our code base and dependencies without requiring developers to use a completely separate process or tool. This makes security testing more seamless and helps us identify vulnerabilities before they reach production.
The ability to identify vulnerable dependencies is another feature I find very useful. Snyk not only identifies potential vulnerabilities but also provides recommendations that help developers understand the issue and determine the appropriate remediation approach. This makes it easier for our team to prioritize and resolve security issues.
From a usability perspective, I find Snyk straightforward and easy to work with. The dashboard provides clear visibility into vulnerabilities and helps us understand the overall security posture of our applications.
I also value Snyk's approach to security and data protection, particularly its focus on protecting customer data and maintaining appropriate security and privacy controls. This gives us additional confidence when using the platform as part of our development security process.
Regarding Snyk's AI capabilities, I find the results consistent and useful for supporting developers with security-related tasks. AI can help developers analyze issues and identify potential remediation approaches more efficiently, reducing the manual effort required. For us, this makes the overall vulnerability-management process faster and more effective while still allowing developers to review and validate the recommended actions.
Overall, the combination of CLI capabilities, CI/CD integrations, dependency analysis, ease of use, clear visibility, and AI-assisted security workflows makes Snyk a valuable tool for our development and security teams.
What needs improvement?
I think Snyk is already a strong and straightforward solution, particularly for organizations that want to identify vulnerabilities and dependency issues as early as possible in the development lifecycle. For small and mid-sized organizations, Snyk provides an effective way to introduce security scanning without making the development process overly complex.
The main area where I see an opportunity for improvement is pricing and licensing flexibility. While Snyk provides a strong set of features and I believe the functionality justifies the cost, more flexible pricing options could make the platform more accessible to smaller organizations and teams with limited security budgets.
For example, offering more flexible plans based on team size, usage, repositories, or scan volume could help smaller organizations adopt Snyk more easily and expand their usage as their environment grows.
Overall, I am satisfied with the product and its capabilities. My primary recommendation would be to make the pricing model more flexible while continuing to maintain the current level of security features and functionality.
For how long have I used the solution?
I have been using Snyk for around one year.
What do I think about the stability of the solution?
Yes, based on our experience, Snyk has been stable and reliable in our environment.
Since deploying Snyk, we have been able to use it consistently across our development and CI/CD workflows, including our code repositories, Snyk CLI, Jenkins pipelines, and Docker/container environments. We have not experienced significant stability issues that have affected our development or deployment processes.
The scanning process is straightforward, and the integration with our existing development tools has worked reliably. This is important for us because security scanning needs to be part of the development lifecycle without becoming a bottleneck for developers or delaying deployments.
Another positive aspect is the consistent visibility Snyk provides into vulnerabilities and dependencies. We can continue monitoring the code base, identify newly introduced vulnerabilities, and track remediation without having to change our workflow significantly.
Overall, based on our experience, Snyk has been a stable and dependable part of our application security process, and we have been able to use it consistently as our security requirements have grown.
What do I think about the scalability of the solution?
I would rate Snyk's scalability very highly. In our environment, Snyk has been easy to integrate into our existing development and CI/CD workflows, and it can scale as the number of repositories, developers, applications, and dependencies increases.
One of the biggest advantages is that Snyk can be integrated at multiple levels, including the developer's local environment, Snyk CLI, source-code repositories, Jenkins CI/CD pipelines, and Docker/container workflows. This allows us to maintain the same security approach as our development environment grows without requiring a completely different process for each application or team.
Snyk also provides centralized visibility into vulnerabilities and dependencies, which makes it easier for us to identify trends, prioritize risks, and track remediation across multiple projects. As we add more applications or repositories, we can continue applying the same vulnerability scanning and security practices.
For us, scalability is not only about handling more code. It is also about being able to scale security practices across the organization without significantly increasing operational complexity. Snyk has performed well in this area and fits our development environment as we continue to expand.
Overall, I would consider Snyk highly scalable for organizations that want to grow their application security program while keeping vulnerability management integrated with the existing development and CI/CD processes.
How are customer service and support?
I would evaluate Snyk's customer service and technical support positively. In our experience, the support has been responsive and helpful when we have needed assistance with the platform, integrations, or technical questions.
The documentation and available technical resources are also useful for troubleshooting and understanding how to configure Snyk within our development and CI/CD environment. This makes it easier for our team to resolve common issues independently.
Since we are using Snyk under an Enterprise licensing model, having access to appropriate technical support is important to us. Overall, we have had a good experience with Snyk's support, and it provides the level of assistance we expect from an enterprise security platform.
Which solution did I use previously and why did I switch?
No. We were not using any other dedicated solution for vulnerability scanning before implementing Snyk. We adopted Snyk as our first dedicated solution to identify vulnerabilities in code and dependencies during the development lifecycle.
How was the initial setup?
The initial setup was straightforward and relatively easy. Snyk integrates well with our existing development and CI/CD environment, so we did not need to make significant changes to our infrastructure or development processes.
We were able to integrate Snyk with our code repositories, Jenkins, Snyk CLI, and Docker/container environment and start scanning our code and dependencies for vulnerabilities.
The setup process was easy to understand, and the dashboard provided good visibility into the identified vulnerabilities and dependencies. Once the integrations were configured, our developers could incorporate Snyk into their existing development workflow without significant disruption.
Overall, I would describe the initial implementation as simple, well documented, and easy to manage, particularly for an organization that already has an established CI/CD environment.
What's my experience with pricing, setup cost, and licensing?
We are using Snyk under an Enterprise licensing model, which makes deployment and licensing management relatively straightforward for our organization. Since we have enterprise licensing, we do not have to manage separate licensing or deployment arrangements for individual users or environments.
We purchased Snyk directly from Snyk through an enterprise agreement, rather than through the AWS Marketplace or another third-party channel.
Overall, the setup and licensing experience has been straightforward, and the enterprise model provides the flexibility we need to integrate Snyk across our development and security workflows.
Which other solutions did I evaluate?
We evaluated different approaches and security solutions for identifying vulnerabilities in application code and dependencies, but Snyk stood out as the best fit for our requirements.
The main reason we selected Snyk was its ease of integration with our existing development and CI/CD environment, particularly with Jenkins, GitHub, Bitbucket, Docker, and the Snyk CLI. We wanted a solution that could be integrated into the development process without adding significant complexity for our developers.
Another key advantage was Snyk's ability to identify vulnerabilities in both the code and its dependencies at an early stage. The vulnerability information and remediation recommendations also made it easier for developers to understand and address the identified issues.
Some alternative approaches and tools can provide vulnerability scanning, but we found that they either required more effort to integrate into our existing workflow or did not provide the same combination of developer-focused security, dependency analysis, ease of use, and CI/CD integration that we were looking for.
Overall, Snyk provided the best balance of security coverage, ease of implementation, developer usability, and integration with our existing environment, which is why we selected it.
What other advice do I have?
I would rate Snyk 10 out of 10 overall.
Snyk is a strong fit for our use case because of its integration with our development environment, code repositories, local development editors, Snyk CLI, and Docker workflows. The ability to identify vulnerabilities early in the development lifecycle, including vulnerabilities in dependencies and container images, has helped us improve our code base and reduce security risks before applications reach production.
Snyk is already deployed and actively used within our organization, and it has become an important part of our development and security process.
My advice to other organizations, particularly small and mid-sized organizations, is to consider Snyk if they want to improve their application security without making the development process overly complicated. Snyk can help teams identify vulnerabilities in their code and dependencies at an early stage, understand remediation requirements, and track vulnerability trends over time.
For organizations looking to improve code quality, reduce dependency-related risks, and build security into the development lifecycle, I would strongly recommend Snyk.