Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

4 AWS reviews

External reviews

135 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Information Technology and Services

Very helpful and feature rich tool

  • July 13, 2024
  • Review provided by G2

What do you like best about the product?
Great integration with version control tools like Github and Bitbucket
What do you dislike about the product?
Initially when using Snyk it was a bit confusing, but since then they have improved all the UX and features.
What problems is the product solving and how is that benefiting you?
Using Snyk as our primary security tool offers us a lot of benefits from SAST to vulnerabiltiy scanning.


    NguyễnHuy

Supports multiple programming languages for security practices

  • May 28, 2024
  • Review provided by PeerSpot

What is our primary use case?

Snyk protects vulnerabilities in the code as usual, detects abnormal data flow inside the field, and similar tasks.

How has it helped my organization?

The specific feature of Snyk that has significantly improved my vulnerability management is its ability to identify vulnerabilities and suggest solutions to fix them. Snyk's automation capabilities streamline my security tasks by scanning code every time I commit.

What is most valuable?

Snyk's focus on security is a valuable feature. Also, Snyk supports multiple programming languages, which has positively affected my security practices. I use only two or three languages, and when I change the language in a file, it detects it in the same suite.

I find the AI-powered scanning beneficial. Using Snyk's AI-powered scanning, I can detect around ten or twenty errors in my project with about twenty thousand lines of code, so it helps improve my project by identifying a lot of potential vulnerabilities.

What needs improvement?

I use Snyk alongside Sonar, and Snyk tends to generate a lot of false positives. Improving the overall report quality and reducing false positives would be beneficial.

I don't need additional features; just improving the existing ones would be enough.

What do I think about the stability of the solution?

It scans the entire code really fast, and the auto-scan process is done repeatedly.

I would rate the stability of Snyk an eight out of ten.

What do I think about the scalability of the solution?

It detects issues really fast, but it still has a lot of false positives, and sometimes the suggestions aren't quite on point. This can sometimes lead to other vulnerabilities.

I would rate the scalability of Snyk a seven out of ten.

How was the initial setup?

I would rate the initial setup of Snyk a nine out of ten because it's straightforward. The web version is also easy to use. I'm working with both the web version and the IDE at the same time.

For deployment, I just link it to GitHub, upload the repository there and it automatically scans for any errors. It took around a minute to deploy Snyk.

What's my experience with pricing, setup cost, and licensing?

I'm currently using the free version, which the company offers before buying the full version. So, the price is affordable, especially for an enterprise.

Which other solutions did I evaluate?

I did evaluate other options before choosing Snyk. I only considered Sonar before Snyk, but I ended up with Snyk because it's faster and more focused on security.

What other advice do I have?

My advice for others considering using Snyk is to rely on it for security issues but still manually review your overall code. It's great for detecting syntax errors but might miss some broader issues, so it's important to do a thorough check yourself.

Based on my experience, I'd rate Snyk an eight overall. Its performance is indeed good.


    Ryan C.

Very quick to find security issues with code bases

  • March 20, 2024
  • Review provided by G2

What do you like best about the product?
I think it is so easy to use. I like that it includes solutions to the issues I have, it can quickly scan a codebase and will constantly scan it. We had no issues including it into our code base.
What do you dislike about the product?
The solutions sometimes overlap and don't coincide. Another issue I could say would be pricing.
What problems is the product solving and how is that benefiting you?
We have had some security issues in the code base we never would have realized without it.


    reviewer1165062

Possesses good ability to highlight security vulnerabilities

  • March 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the tool in my company to scan open-source projects.

What needs improvement?

I don't use Snyk anymore. The tool is just used in our company, but not by me anymore.

It is important that the solution has the ability to match up with the OWASP Top 10 list, especially considering that sometimes, it cannot fix certain issues. Users might face 100 vulnerabilities during the production phase, and they may not be able to fix them all. Different companies have different levels of risk appetite. In a highly regulated industry, users of the product should be able to fix all the vulnerabilities, especially the internal ones. The tool should provide more flexibility and guidance to help us fix the top vulnerabilities before we go into production.

For how long have I used the solution?

I have been using Snyk for three years. I am a user of the tool.

How are customer service and support?

The solution's technical support is okay. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

The product's price is okay. My company isn't actively looking for replacement tools.

What other advice do I have?

The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.

The integration features of the product are okay.

I recommend the product to those who want to buy it.

In a general sense, Snyk is a good product that can be used for governance. If you use a lot of open-source software, Snyk is an application testing tool you can buy.

I rate the tool a seven to eight out of ten.


    Jayashree Acharyya

Used for image scanning and identifying vulnerabilities, but its integration with other services could be improved

  • March 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

We are using an enterprise version of Snyk for image scanning. We use Snyk to identify and address vulnerabilities in our open-source dependencies and to scan the Docker images.

What is most valuable?

The solution's Open Source feature gives us notifications and suggestions regarding how to address vulnerabilities.

What needs improvement?

The solution's integration with JFrog Artifactory could be improved.

For how long have I used the solution?

We have been using Snyk for two years.

What do I think about the stability of the solution?

I rate the solution an eight out of ten for stability.

What do I think about the scalability of the solution?

We use Snyk for microservices, and more than 100 users use it in our organization twice a week.

I rate the solution a seven out of ten for scalability.

How are customer service and support?

The solution’s technical support team was involved during the architecture integration. We got their support, but I think we could probably get a faster response from them.

How would you rate customer service and support?

Neutral

How was the initial setup?

Snyk's initial setup is not very difficult.

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a seven out of ten.

What about the implementation team?

The solution's initial setup took a few weeks. The solution's deployment was done by our app system, and four people were highly engaged in this activity.

Which other solutions did I evaluate?

Before choosing Snyk, we were exploring different solutions like JFrog Xray and Aqua scan for image scanning. We chose Snyk because we could do both image scanning and SCA with it.

We are comparing Snyk with GitHub Advanced Security, which has a better vulnerability database. They have more vulnerabilities enlisted in their database.

What other advice do I have?

The solution has improved or streamlined our process a lot for securing container images. We wanted to make sure we are deploying the secure Docker images. Snyk allowed us to check whether it is following our standard of docker images or not.

We use Azure DevOps as our platform, and Snyk's integration with Azure DevOps was okay. However, Snyk's integration with JFrog Artifactory didn't go well. We use JFrog Artifactory to store the artifacts we download. We wanted to integrate Snyk with JFrog Artifactory to scan the binary artifacts we downloaded, but that broke our JFrog Artifactory for some reason. Instead of using it there, we are calling it directly from the pipeline.

Snyk's automation features significantly reduced remediation times a couple of times. Sometimes, our developers scan the code from the environment and find some Java vulnerabilities. We fixed those vulnerabilities in the lower environment itself. The solution does not require any maintenance.

The accuracy of Snyk's vulnerability detection is pretty good compared to other tools. I rate the solution's vulnerability detection feature an eight out of ten. I would recommend Snyk to other users because it is easy to implement and integrate with Azure DevOps and GitHub.

Overall, I rate the solution a seven out of ten.


    SHUBHAM BHINGARDE

An easy-to-use solution that can be used for the generation of SBOM

  • February 08, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Snyk for the generation of SBOM for Docker. We use it to check the standards of the CSI benchmark that we have implemented in the containers and the applications by Java Spring Boot.

What is most valuable?

The most valuable feature of Snyk is the SBOM.

What needs improvement?

It would be helpful if we get a recommendation while doing the scan about the necessary things we need to implement after identifying the vulnerabilities. In short, it will be a remediation for the vulnerabilities identified by Snyk.

For how long have I used the solution?

I have been using Snyk for two years.

What do I think about the stability of the solution?

Snyk is a stable solution.

What do I think about the scalability of the solution?

Snyk is a scalable solution. As we are an R&D organization, I am the only person managing the solution. However, there are almost 500 employees who are taking advantage of the report we have generated from the Snyk app.

How was the initial setup?

The solution is easy to use and implement.

What about the implementation team?

The deployment steps were easy. The solution's documentation is also easy to use. It took hardly one and a half hours to implement the solution. We implemented Snyk in our virtual private server (VPS).

For deployment, we followed the instructions and created a server for Snyk. Then, we integrated the server with the plug-in using Jenkins. We created a server for Snyk, then used the GitHub repository that mentioned the document and implemented the same. Later, we used the plug-in to connect the server to the Jenkins server.

When the pipeline was built, the process started, as we had mentioned the stage in the Jenkins file, to generate SBOMs and check whether the Docker images were compliant with CSI Benchmarks.

What's my experience with pricing, setup cost, and licensing?

Snyk is an expensive solution.

Which other solutions did I evaluate?

Before choosing Snyk, we evaluated a different tool named Dependency-Track. We chose Snyk because Dependency-Track only helped us identify the vulnerabilities in the libraries, and it couldn't solve the issues mentioned in the CIS benchmark.

What other advice do I have?

Snyk helped us identify the composition or the libraries we used in the project, which were vulnerable. It also helped us identify the license agreements from the vendor side.

Software conversion analysis is a mandatory thing that should be implemented in every organization. Most libraries or any third-party libraries are not considered under VAPT. We should also look after the composition of the libraries we use in the project. We should look after these libraries for vulnerabilities, and VAPT should be mandatory in every organization.

I rate Snyk a nine out of ten for the user-friendliness of its user interface.

Currently, my team is looking into whether version numbers are vulnerable. We are also considering the improvisations or research and development we need to do if we need the same library. There are some loopholes that even Snyk has not identified or that it might be working on. Since we have implemented it, we are looking after it.

If a developer requires a particular library with vulnerabilities, we check whether we are using the functions mentioned in the libraries in the project. If we are using it, we are trying to identify exactly which snippet is causing the error. If it is causing a vulnerability, we are considering how to improve it.

We need to think about the decisions we need to make after SCA. It would be a big relief for our organization if Snyk could provide a solution to identify the library snippet that is causing a future vulnerability. We are currently using a team of 30 people to identify this issue.

Overall, I rate Snyk an eight out of ten.


    Import and Export

Great vulnerability scanning tool

  • February 03, 2024
  • Review provided by G2

What do you like best about the product?
-Easy integration available for GIthub
-Vulenrabilities false positive rate is slightly better than other tools
-Can be easily integrated within CI/Cd pipline.
-Automatic code scanning and report generation available
-Works with almost all languages
-Very straightforward to use
What do you dislike about the product?
-Sometimes vulenrability reported are false positive and also rarely misses some of the genuine vulnerabilities.
What problems is the product solving and how is that benefiting you?
Snyk is a part of the CI/CD pipleline and performs static code scanning and basic sanity check of the code as a first level of testing. Snyk also provides remedition which is very useful. It has built in support for Github so we leverage snyk to perform regular scans on our codebase.


    Shashank N

A stable solution that provides excellent features and enables users to identify vulnerabilities in the application plug-ins

  • January 05, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the product mainly for software composition analysis. It is used to identify vulnerabilities in the application plug-ins. If we use Python 3.8, it’ll tell us that the version is outdated and that it has several vulnerabilities. It also helps in threat identification. It also provides infrastructure as code.

What is most valuable?

Static code analysis is one of the best features of the solution.

What needs improvement?

The product is very expensive.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

The product is stable.

What do I think about the scalability of the solution?

We have around 2000 users. Every developer in the organization has access to it.

How are customer service and support?

The support has improved a lot.

How would you rate customer service and support?

Neutral

How was the initial setup?

We use the SaaS version. The initial setup is easy. We just have to click the buttons.

What was our ROI?

I do not think that the tool is worth the money. A lot of free tools are available online.

What's my experience with pricing, setup cost, and licensing?

The solution costs half a million dollars per year. It depends on the number of users. If the number of users increases, the cost will increase further.

What other advice do I have?

People who want to use the product must utilize the code analysis on IDE. It would really help a lot of the developers. It performs the shift left concept very well. It is a very good tool, but the pricing is absurd. Overall, I rate the product an eight out of ten.


    Karthik Daunntless

Check vulnerabilities and rectify potential leaks in GitHub

  • December 15, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use Snyk to check vulnerabilities and rectify potential leaks in GitHub.

What needs improvement?

The tool's initial use is complex.

For how long have I used the solution?

I have been working with the product for three to four months.

What other advice do I have?

I rate the product an eight out of ten.


    ManishSaxena

A scalable tool that needs to add more vulnerability protection features

  • November 14, 2023
  • Review provided by PeerSpot

What is our primary use case?

The major problem my company found in relation to our customers was in the area of Zip Slip security as they don't have any security tools in place. My company's customers don't have any security tools integrated into the CI/CD pipelines they use in their company. With Snyk, SCA checks code and third-party dependencies upfront.

What is most valuable?

When it comes to Snyk, it is not about its features since it is a developer-focused tool, making it possible for developers to easily integrate the tool with other solutions. The automation part and reporting feature of the solution are good. Nowadays, people opt for Cloud Native Pod system architecture, under which good tools are offered to users to use for their applications.

What needs improvement?

I think Snyk should add more of a vulnerability protection feature in the tool since it is an area where it lacks. Snyk needs to focus on the area related to dependencies.

For how long have I used the solution?

I have been using Snyk for ten years.

What do I think about the scalability of the solution?

Snyk is a good and scalable tool. Some of our customers who get to use the scalability options go ahead and compare Snyk with other options like Veracode, which is a highly expensive tool that is also complex. Snyk is a simpler tool compared to Veracode.

My company deals with mostly medium-sized clients who use Snyk.

How are customer service and support?

In our company, the team I deal with, the delivery team, has never raised concerns regarding the support offered by Snyk. I hope the support offered by Snyk is fine.

Which solution did I use previously and why did I switch?

My company has dealt with SonarQube a lot in the past. It is not that my company switches over from one tool to another tool. The tools we use in my company depend on our customers. Some of my company's customers prefer SonarQube, while others prefer Snyk.

How was the initial setup?

The product's initial setup phase was easy.

The solution's deployment model varies from customer to customer. My company deals with a mix of clients, some of whom deploy the tool on the cloud while others deploy it on an on-premises model.

What's my experience with pricing, setup cost, and licensing?

Compared to Veracode, Snyk is definitely a cheaper tool. SonarQube's community version or enterprise version is mostly used, but price-wise, it is okay. The price depends on how many lines of code a customer uses in SonarQube.

What other advice do I have?

The major reason why customers prefer Snyk is that, nowadays, people are moving towards cloud-native tools. People also want a tool that offers safety and security, especially during the integration process and during the coding part. Snyk offers a set of much better features when compared to other tools like SonarQube or Veracode. Smaller companies can choose the team plan or enterprise version offered by Snyk. The major reason why people prefer Snyk is because of the security it offers.

I rate the overall tool a six or seven out of ten.