Hacker News new | ask | show | jobs
by game_the0ry 13 hours ago
I wonder if tools like this will put companies like snyk out of business. We use snyk at work and I have not been satisfied.
2 comments

I like to think it just upped the bar, but good durable expertise will need to rise with it.
Why would a few code snippets put Snyk out of business?
I don't understand why Snyk is IN business in any way. Who really wants to upload his own code to a company that is specialized at searching security issues?

How can I trust that they show me all findings they have instead of selling the best ones to some three letter organisations?

Our employer uses it unaware of its links.
One of their sales people made fun of me via email. Apparently they believe that not being their customers means you cannot possibly know if a dependency you use has an active CVE.

Also they haven't figured out codeberg exists, so the resume page of a project of mine on snyk[1] still links to github and reports the project as "inactive", having the last commit 2 years ago, and the last release 2 months ago. I think it's quite telling of their quality.

1. https://security.snyk.io/package/pip/typedload