Snyk - Shifting Security Left Through DevSecOps Developer-First Cloud-Native Solutions

Snyk - Shifting Security Left Through DevSecOps Developer-First Cloud-Native Solutions

Source: YouTube · DevOps & AI Toolkit · published Dec 1, 2020 · 25:06

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Snyk is introduced as a developer-friendly security solution that "shifts left" by integrating security early in development, enabling continuous vulnerability scanning across code, containers, and infrastructure 0:21.

Key Takeaways:
• Traditional security approaches are problematic because they're implemented late in development, causing significant rework 0:21
• "Shifting left" means integrating security early in development to catch vulnerabilities immediately as code is written 2:19
• Snyk provides comprehensive security scanning across multiple domains including open source dependencies, containers, and infrastructure as code 3:36
• Snyk identifies vulnerabilities and provides actionable recommendations to fix them, often by updating base images or dependencies 9:10
• Snyk integrates directly with Docker, allowing developers to scan images without installing additional tools 10:52

The presenter demonstrates how Snyk helped reduce vulnerabilities from five to one in a container image by following its recommendations, showing the practical value of early security integration.

Sources:

  • 0:21 Problems with traditional security approaches
  • 2:19 Explanation of "shifting left" concept
  • 3:36 Overview of Snyk's comprehensive capabilities
  • 9:10 Snyk's vulnerability fixing recommendations
  • 10:52 Docker integration feature

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

security that's uh that's the most dreaded topic for most of engineers in this industry of course excluding security experts if there is such thing as hatred among engineers for some topic that would be security and partly for a good reason because security traditionally is something shifted as far to the right as possible developers would work for days weeks months in the past it was even years and then all of a sudden one day a security report would arrive usually very close to the end of the process before releasing the production that would say basically hey look there are those tens or hundreds or thousands of items many of them are security gates without fixing those you cannot move forward and nobody wants to go back and redo change the dependencies because some are insecure change …