7 ms·
I don't understand why Snyk is IN business in any way. Who really wants to upload his own code to a company that is specialized at searching security issues? H
by krater23 2mo ago
I don't understand why Snyk is IN business in any way. Who really wants to upload his own code to a company that is specialized at searching security issues?
How can I trust that they show me all findings they have instead of selling the best ones to some three letter organisations?
- LtWorf 2mo agoOne of their sales people made fun of me via email. Apparently they believe that not being their customers means you cannot possibly know if a dependency you use has an active CVE. Also they haven't figured out codeberg exists, so the resume page of a project of mine on snyk[1] still links to github and reports the project as "inactive", having the last commit 2 years ago, and the last release 2 months ago. I think it's quite telling of their quality. 1. https://security.snyk.io/package/pip/typedload https://security.snyk.io/package/pip/typedload
- tesnorindian 2mo agoOur employer uses it unaware of its links.