Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

4 AWS reviews

External reviews

135 reviews
from and

External reviews are not included in the AWS star rating for the product.


3-star reviews ( Show all reviews )

    meetharoon

Affordable tool boosts code scanning efficiency but faces integration hurdles

  • November 27, 2024
  • Review from a verified AWS customer

What is our primary use case?

I lead a code security practice for our organization. We integrated Snyk into our GitHub, using CLI to automatically scan codebases and identify issues. We are a large organization with three independent entities, consolidating Snyk across all entities.

We also provide access through numerous CI/CD tools. Our default implementation mechanism is CLI, but we also use the Web UI for a comprehensive view and recommendations.

How has it helped my organization?

For large organizations like ours, cost is a major factor. Snyk is the most cost-effective solution compared to others like Checkmarx.

We consolidated Snyk across three entities that used different tools. As a result, our organization became one of the largest in implementing Snyk.

What is most valuable?

The most important feature of Snyk is its cost-effectiveness compared to other solutions such as Checkmarx. It is easy to consolidate Snyk across multiple entities within a large organization.

Additionally, our integration of Snyk into GitHub allows us to automatically scan codebases and identify issues, which has improved efficiency.

What needs improvement?

Snyk has several limitations, including issues with Gradle, NPM, and Xcode, and trouble with AutoPR. It lacks the ability to select branches on its Web UI, forcing users to rely on CLI or CI/CD for that functionality. These limitations were documented in a book that I wrote.

For how long have I used the solution?

We implemented Snyk starting last year, and it has been in use for around two and a half years.

What do I think about the scalability of the solution?

Snyk allows for scaling across large organizations, accommodating tens of thousands of applications and over 60,000 repositories, making it suitable for wide-scale deployment.

How are customer service and support?

Our organization maintains a good relationship with Snyk's customer support team. Despite potential variations in service quality for smaller organizations, our long-standing association has ensured smooth communication, resulting in favorable support experiences and satisfactory issue resolution.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, we used Synopsys Coverity and later migrated to Checkmarx and Mend before Snyk. Synopsys Coverity was costly, prompting a switch. Snyk's affordability and consolidating capabilities across the entities led to its adoption.

How was the initial setup?

The initial setup of Snyk is simple and straightforward compared to Synopsys Coverity, which is complex. Checkmarx falls in between, not too complicated or easy, but a reliable option. Snyk's ease of implementation makes it user-friendly.

What about the implementation team?

We have different teams managing aspects like licensing and engagement with the support team. They facilitate setup and maintenance, optimally integrating Snyk into our GitHub and CI/CD processes.

What's my experience with pricing, setup cost, and licensing?

Snyk is recognized as the cheapest option we have evaluated. In comparison to eight or nine other solutions, it ranks among the most affordable, providing cost-effective scalability across organizational units.

Which other solutions did I evaluate?

In my comparative evaluations, I considered tools like AppScan, Veracode, Checkmarx, Synopsys Coverity, and six to eight other alternatives.

What other advice do I have?

Snyk is optimal for organizations starting or looking for an affordable, effective tool. Despite false positives, it combines SAST, SCA, containers, and IaS in one Web UI. On a scale of one to ten, I rate Snyk at six.


    Nitish U.

Very Good SAST tool to begin with

  • August 19, 2024
  • Review provided by G2

What do you like best about the product?
Integration with both Bitbucket and Github, policy as a code,
What do you dislike about the product?
Too much unnecessary false positives, policy overrides, hard and complex to manage and track alerts
What problems is the product solving and how is that benefiting you?
Help in reducing efforts on Manual VAPT, helps in identifying muliple vuln in a single package thus reduces effort to mitigate vuln with minimum number of upgrades and patches


    Information Technology and Services

Very helpful and feature rich tool

  • July 13, 2024
  • Review provided by G2

What do you like best about the product?
Great integration with version control tools like Github and Bitbucket
What do you dislike about the product?
Initially when using Snyk it was a bit confusing, but since then they have improved all the UX and features.
What problems is the product solving and how is that benefiting you?
Using Snyk as our primary security tool offers us a lot of benefits from SAST to vulnerabiltiy scanning.


    Jayashree Acharyya

Used for image scanning and identifying vulnerabilities, but its integration with other services could be improved

  • March 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

We are using an enterprise version of Snyk for image scanning. We use Snyk to identify and address vulnerabilities in our open-source dependencies and to scan the Docker images.

What is most valuable?

The solution's Open Source feature gives us notifications and suggestions regarding how to address vulnerabilities.

What needs improvement?

The solution's integration with JFrog Artifactory could be improved.

For how long have I used the solution?

We have been using Snyk for two years.

What do I think about the stability of the solution?

I rate the solution an eight out of ten for stability.

What do I think about the scalability of the solution?

We use Snyk for microservices, and more than 100 users use it in our organization twice a week.

I rate the solution a seven out of ten for scalability.

How are customer service and support?

The solution’s technical support team was involved during the architecture integration. We got their support, but I think we could probably get a faster response from them.

How would you rate customer service and support?

Neutral

How was the initial setup?

Snyk's initial setup is not very difficult.

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a seven out of ten.

What about the implementation team?

The solution's initial setup took a few weeks. The solution's deployment was done by our app system, and four people were highly engaged in this activity.

Which other solutions did I evaluate?

Before choosing Snyk, we were exploring different solutions like JFrog Xray and Aqua scan for image scanning. We chose Snyk because we could do both image scanning and SCA with it.

We are comparing Snyk with GitHub Advanced Security, which has a better vulnerability database. They have more vulnerabilities enlisted in their database.

What other advice do I have?

The solution has improved or streamlined our process a lot for securing container images. We wanted to make sure we are deploying the secure Docker images. Snyk allowed us to check whether it is following our standard of docker images or not.

We use Azure DevOps as our platform, and Snyk's integration with Azure DevOps was okay. However, Snyk's integration with JFrog Artifactory didn't go well. We use JFrog Artifactory to store the artifacts we download. We wanted to integrate Snyk with JFrog Artifactory to scan the binary artifacts we downloaded, but that broke our JFrog Artifactory for some reason. Instead of using it there, we are calling it directly from the pipeline.

Snyk's automation features significantly reduced remediation times a couple of times. Sometimes, our developers scan the code from the environment and find some Java vulnerabilities. We fixed those vulnerabilities in the lower environment itself. The solution does not require any maintenance.

The accuracy of Snyk's vulnerability detection is pretty good compared to other tools. I rate the solution's vulnerability detection feature an eight out of ten. I would recommend Snyk to other users because it is easy to implement and integrate with Azure DevOps and GitHub.

Overall, I rate the solution a seven out of ten.


    ManishSaxena

A scalable tool that needs to add more vulnerability protection features

  • November 14, 2023
  • Review provided by PeerSpot

What is our primary use case?

The major problem my company found in relation to our customers was in the area of Zip Slip security as they don't have any security tools in place. My company's customers don't have any security tools integrated into the CI/CD pipelines they use in their company. With Snyk, SCA checks code and third-party dependencies upfront.

What is most valuable?

When it comes to Snyk, it is not about its features since it is a developer-focused tool, making it possible for developers to easily integrate the tool with other solutions. The automation part and reporting feature of the solution are good. Nowadays, people opt for Cloud Native Pod system architecture, under which good tools are offered to users to use for their applications.

What needs improvement?

I think Snyk should add more of a vulnerability protection feature in the tool since it is an area where it lacks. Snyk needs to focus on the area related to dependencies.

For how long have I used the solution?

I have been using Snyk for ten years.

What do I think about the scalability of the solution?

Snyk is a good and scalable tool. Some of our customers who get to use the scalability options go ahead and compare Snyk with other options like Veracode, which is a highly expensive tool that is also complex. Snyk is a simpler tool compared to Veracode.

My company deals with mostly medium-sized clients who use Snyk.

How are customer service and support?

In our company, the team I deal with, the delivery team, has never raised concerns regarding the support offered by Snyk. I hope the support offered by Snyk is fine.

Which solution did I use previously and why did I switch?

My company has dealt with SonarQube a lot in the past. It is not that my company switches over from one tool to another tool. The tools we use in my company depend on our customers. Some of my company's customers prefer SonarQube, while others prefer Snyk.

How was the initial setup?

The product's initial setup phase was easy.

The solution's deployment model varies from customer to customer. My company deals with a mix of clients, some of whom deploy the tool on the cloud while others deploy it on an on-premises model.

What's my experience with pricing, setup cost, and licensing?

Compared to Veracode, Snyk is definitely a cheaper tool. SonarQube's community version or enterprise version is mostly used, but price-wise, it is okay. The price depends on how many lines of code a customer uses in SonarQube.

What other advice do I have?

The major reason why customers prefer Snyk is that, nowadays, people are moving towards cloud-native tools. People also want a tool that offers safety and security, especially during the integration process and during the coding part. Snyk offers a set of much better features when compared to other tools like SonarQube or Veracode. Smaller companies can choose the team plan or enterprise version offered by Snyk. The major reason why people prefer Snyk is because of the security it offers.

I rate the overall tool a six or seven out of ten.


    KienNguyen1

Provides good scalability, but its reporting feature needs improvement

  • September 13, 2023
  • Review provided by PeerSpot

What is most valuable?

The product's most valuable features are an open-source platform, remote functionality, and good pricing.

What needs improvement?

Snyk's API and UI features could work better in terms of speed. Additionally, they could optimize and provide better reports, including reports for security, technical, and developer level.

For how long have I used the solution?

We have been using Snyk for two and a half years.

What do I think about the stability of the solution?

I rate the platform's stability an eight or nine out of ten. Sometimes, we encounter downtime issues, but it has quick recovery. It impacts our system and needs improvement for better outcomes during the development phase.

What do I think about the scalability of the solution?

We have 20 to 50 Snyk users in the development team of our organization. It is a scalable product.

How are customer service and support?

The technical support services are available quickly for developers. However, they should improve their speed of response for customers.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Checkmarx and some other open-source software.

How was the initial setup?

The initial setup is neither difficult nor easy. However, it works slowly. It takes some weeks or months to complete the process.

What's my experience with pricing, setup cost, and licensing?

The product has good pricing.

What other advice do I have?

I recommend Snyk to others and rate it a seven out of ten.


    Computer Software

Tool for managing your open source vulnerabilities

  • September 08, 2023
  • Review provided by G2

What do you like best about the product?
Snyk give you a good coverage for your open source vulnerabilities, license probelm and basic static code analysis.
What do you dislike about the product?
The integration part can be misleading, for a real detection you need to integrate it into the ci/cd, and the simple detection of requirements files is not working for all use cases.

Dashboards and reporting can be improved and better organized.
What problems is the product solving and how is that benefiting you?
Detection and prioritization of vulnerabilities


    RumyTaulu

It's good for identifying security errors, but we have problems integrating it with our CI/CD solution

  • May 23, 2023
  • Review provided by PeerSpot

What is our primary use case?

I use Snyk to review my code.

What is most valuable?

Snyk helps me pinpoint security errors in my code.

What needs improvement?

Sometimes we have problems upgrading a library because it's too old. The only thing we can do is use another library.

What do I think about the scalability of the solution?

It is easy to scale Snyk once you install it, but it depends on your cloud service provider. Everything will scale smoothly if you have the correct cloud server settings.

How are customer service and support?

I rate Snyk support eight out of 10.

How would you rate customer service and support?

Positive

How was the initial setup?

Setting up Snyk is relatively complex if you're working with multiple developers who use different IDEs. It can be complicated if, for example, one developer uses Visual Studio and another developer uses a different editor.

Snyk is cloud-based. We use Bamboo for CI/CD, and we had problems integrating Snyk with it. Ultimately, we got the two solutions to work together, but it was difficult.

What's my experience with pricing, setup cost, and licensing?

I rate Snyk three out of 10 for affordability. The price is relatively high, but it's worth it.

What other advice do I have?

I rate Snyk seven out of 10.


    Alexander O.

Useful tool that could have a better layout

  • July 28, 2022
  • Review provided by G2

What do you like best about the product?
Helpful in identifying issues with your dependencies and provides upgrade pathways for this so you can keep your application secure. It also scans you code and looks for security issues which also helps
What do you dislike about the product?
The User Interface of the Application is a little overwhelming with a lot going on. It is also not clear how to dismiss issues found in the scan if they are not issues for your application
What problems is the product solving and how is that benefiting you?
It is helping us create a business case to speed the time to upgrade our dependencies and we can point to issues that have been found. It also helps us find out which part of our applications to focus on first.


    Computer Software

A Great service for Source code analysis and vulnerability detection

  • March 03, 2022
  • Review provided by G2

What do you like best about the product?
Snyk offers automatic vulnerability detection for our GitHub repos, also it warns about the vulnerability impact, direct PR to our GitHub repo is another nice feature
What do you dislike about the product?
A few false positives in the code itself which nothing to do with security, most of the time the middleware that is not public and written by us
What problems is the product solving and how is that benefiting you?
Some critical vulnerabilities in our web application, where we are not aware of it, and most of the time we ignore to think about the vulnerability impact
Recommendations to others considering the product:
Snyk is a good service I have used. As a Web Developer, I know how hackers can break into our applications, though I develop websites keeping owasp in mind. Still, I am not sure of the third-party packages like npm. We should appreciate Snyk's work before using an outdated package we can see if that nmp package has any known vulnerabilities and avoid risks at the first stage