Discovering and Fixing Dependency
Vulnerabilities for Kubernetes apps
with Snyk and Codefresh
Antoine Arlaud, Snyk & Dan Garfield, Codefresh
Dan
Garfield
Chief Evangelist
Antoine
Arlaud
Figure Stuff Out Engineer
Open Source
Is just awesome
A Small
Portion of
Your App is
Your Code
SOFTWARE STACK
Custom Code
“Your” application
Libraries
Open source code
Base Image
Basic OS with associated software
packages
SOFTWARE STACK
Custom Code
“Your” application
Libraries
Open source code
Base Image
Basic OS with associated software
packages
+53%
Vulnerabilitie
s Found in OSS
YoY
Source:
https://www.prnewswire.com/news-releases/open-source-vulnerabilities-soar-a
n-additional-40-percent-in-2017-300556046.html
SOFTWARE STACK
Custom Code
“Your” application
Libraries
Open source code
Base Image
Basic OS with associated software
packages
Pipelines and Automation
Ships your code seamlessly
Containers
New deliverables for dev teams
Security
Is everyone’s responsibility
Let’s bake this in
Both App sec and OS Sec
Try it:
https://github.com/snyk-playground/codefresh-pipeline-snyk
-app-docker-scan
OUR APP PIPELINE
Commit Dependency
Scan
Docker
Build
Image
Scan
App
Build
Push to Dockerhub
Codefresh
Plugins
Code Scan
Scan for vulnerabilities packages in
Go, NPM, Java, and many more.
Docker Scan
Finds vulnerabilities in RPM,
Debian, and Alpine Package
Managers
Try it:
https://github.com/snyk-playground/codefresh-pipeline-snyk
-app-docker-scan
T
Get 120 FREE builds/month
Codefresh.io
Learn more at
snyk.io

More Related Content

PPTX
Ciao: Continuous Integration for Apps on OpenStack
PDF
Delivery pipelines at Symphony Talent - Present and Future
PPTX
Don’t Ignore GitHub Security Alerts, Automate Them Into Your Workflow.
PDF
Securing containers by Breaking In - Liran Tal - DevSecCon Tel Aviv 2019
PDF
Security in serverless world
PDF
Professional iOS development
PDF
Monkey talk
PPTX
Test Design for Continuous Integration and Delivery (2020)
Ciao: Continuous Integration for Apps on OpenStack
Delivery pipelines at Symphony Talent - Present and Future
Don’t Ignore GitHub Security Alerts, Automate Them Into Your Workflow.
Securing containers by Breaking In - Liran Tal - DevSecCon Tel Aviv 2019
Security in serverless world
Professional iOS development
Monkey talk
Test Design for Continuous Integration and Delivery (2020)

What's hot (20)

PDF
React Native: Is It Worth It? UA Mobile 2017.
PDF
DevOps Illustrated - A practical approach
PPTX
Concurrent version management(tortoise CVS)
PDF
Open Source Compliance for DevOps - OSCON 2017
PPTX
Protecting Applications with Lambda@Edge and OAuth
PDF
Testing Microservices
PPTX
Presentazione resin.io
PDF
Continuous Integration on my work
PDF
Simple Unit Testing in Appcelerator Titanium Alloy
PDF
In graph we trust: Microservices, GraphQL and security challenges
PDF
Continuous Integration for Titanium
PPTX
Beyond Continuous Delivery - Jenkins User Conference - 23 Oct 2014
PDF
TiCalabash and TiMocha: The keys to Better & More Stable Titanium Apps
PPTX
Tests your pipeline might be missing
PDF
OWASP Workshop: Docker Image Security Best Practices by Liran Tal - January 2020
PPTX
All you need is Zap - Omer Levi Hevroni & Yshay Yaacobi - DevOpsDays Tel Aviv...
PPTX
ATAGTR2017 Upgrading a mobile tester's weapons with advanced debugging
PPTX
Continuous SDK
PDF
Continuous delivery in Qbon
React Native: Is It Worth It? UA Mobile 2017.
DevOps Illustrated - A practical approach
Concurrent version management(tortoise CVS)
Open Source Compliance for DevOps - OSCON 2017
Protecting Applications with Lambda@Edge and OAuth
Testing Microservices
Presentazione resin.io
Continuous Integration on my work
Simple Unit Testing in Appcelerator Titanium Alloy
In graph we trust: Microservices, GraphQL and security challenges
Continuous Integration for Titanium
Beyond Continuous Delivery - Jenkins User Conference - 23 Oct 2014
TiCalabash and TiMocha: The keys to Better & More Stable Titanium Apps
Tests your pipeline might be missing
OWASP Workshop: Docker Image Security Best Practices by Liran Tal - January 2020
All you need is Zap - Omer Levi Hevroni & Yshay Yaacobi - DevOpsDays Tel Aviv...
ATAGTR2017 Upgrading a mobile tester's weapons with advanced debugging
Continuous SDK
Continuous delivery in Qbon
Ad

Similar to Discovering and Fixing Dependency Vulnerabilities for Kubernetes apps with Snyk and Codefresh (20)

PPTX
Software Composition Analysis Deep Dive
PDF
Building android apps with Gradle (GREACH 2015)
PDF
Open-Source Security Management and Vulnerability Impact Assessment
PDF
Snyk Intro - Developer Security Essentials 2022
PPTX
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
PPTX
Transforming your Security Products at the Endpoint
PDF
.NET Core on Mac
PDF
Mobile Apps Using AngularJS - Adam Klein @ AngularJS IL
PPTX
Contemporary software TRENDS SOFTWARE TRENDS
PDF
Php Dependency Management with Composer ZendCon 2016
PDF
Analysis of-quality-of-pkgs-in-packagist-univ-20171024
PPT
IBM AppScan Source - The SAST solution
PDF
Dockercon 2018 EU Updates
PDF
Exploiting and analyzing Microsoft Surface Applications
PDF
Securing Open Source Code in Enterprise
ODP
Effective DevSecOps
PDF
Php Dependency Management with Composer ZendCon 2017
PDF
Understanding SBOMs: An Introduction to Modern Development
PDF
Deploying Containerised Open-Source CSP Platforms
PDF
Know What’s in Your Containers! Manage and Secure all Open Source that Compos...
Software Composition Analysis Deep Dive
Building android apps with Gradle (GREACH 2015)
Open-Source Security Management and Vulnerability Impact Assessment
Snyk Intro - Developer Security Essentials 2022
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
Transforming your Security Products at the Endpoint
.NET Core on Mac
Mobile Apps Using AngularJS - Adam Klein @ AngularJS IL
Contemporary software TRENDS SOFTWARE TRENDS
Php Dependency Management with Composer ZendCon 2016
Analysis of-quality-of-pkgs-in-packagist-univ-20171024
IBM AppScan Source - The SAST solution
Dockercon 2018 EU Updates
Exploiting and analyzing Microsoft Surface Applications
Securing Open Source Code in Enterprise
Effective DevSecOps
Php Dependency Management with Composer ZendCon 2017
Understanding SBOMs: An Introduction to Modern Development
Deploying Containerised Open-Source CSP Platforms
Know What’s in Your Containers! Manage and Secure all Open Source that Compos...
Ad

More from Codefresh (20)

PDF
Detect, debug, deploy with Codefresh and Lightstep
PDF
CICD Pipelines for Microservices: Lessons from the Trenches
PDF
Simplify Your Code with Helmfile
PDF
Making the Most of Helm 3 with Codefresh
PDF
5 Simple Tips for Troubleshooting Your Kubernetes Pods
PDF
Best Practices for Microservice CI/CD: Lessons from Expedia and Codefresh
PDF
Hybrid CI/CD with Kubernetes & Codefresh
PDF
VM vs Docker-Based Pipelines
PDF
Why You Should be Using Multi-stage Docker Builds in 2019
PPTX
Deploy Secure Cloud-Native Apps Fast
PDF
CICD Pipelines for Microservices Best Practices
PDF
Codefresh CICD New Features Launch! May 2019
PDF
Terraform GitOps on Codefresh
PDF
Adding Container Image Scanning to Your Codefresh Pipelines with Anchore
PDF
Image scanning using Clair
PDF
Updating Kubernetes With Helm Charts: Build, Test, Deploy with Codefresh and...
PDF
Docker based-Pipelines with Codefresh
PDF
Automated Serverless Pipelines with #GitOps on Codefresh
PDF
Net Pipeline on Windows Kubernetes
PPTX
Multi-cloud CI/CD with failover powered by K8s, Istio, Helm, and Codefresh
Detect, debug, deploy with Codefresh and Lightstep
CICD Pipelines for Microservices: Lessons from the Trenches
Simplify Your Code with Helmfile
Making the Most of Helm 3 with Codefresh
5 Simple Tips for Troubleshooting Your Kubernetes Pods
Best Practices for Microservice CI/CD: Lessons from Expedia and Codefresh
Hybrid CI/CD with Kubernetes & Codefresh
VM vs Docker-Based Pipelines
Why You Should be Using Multi-stage Docker Builds in 2019
Deploy Secure Cloud-Native Apps Fast
CICD Pipelines for Microservices Best Practices
Codefresh CICD New Features Launch! May 2019
Terraform GitOps on Codefresh
Adding Container Image Scanning to Your Codefresh Pipelines with Anchore
Image scanning using Clair
Updating Kubernetes With Helm Charts: Build, Test, Deploy with Codefresh and...
Docker based-Pipelines with Codefresh
Automated Serverless Pipelines with #GitOps on Codefresh
Net Pipeline on Windows Kubernetes
Multi-cloud CI/CD with failover powered by K8s, Istio, Helm, and Codefresh

Recently uploaded (20)

PDF
Architecture types and enterprise applications.pdf
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PPTX
2018-HIPAA-Renewal-Training for executives
PDF
Taming the Chaos: How to Turn Unstructured Data into Decisions
PPT
Module 1.ppt Iot fundamentals and Architecture
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
A comparative study of natural language inference in Swahili using monolingua...
PPTX
Microsoft Excel 365/2024 Beginner's training
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PPTX
Modernising the Digital Integration Hub
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
Enhancing emotion recognition model for a student engagement use case through...
PPTX
Custom Battery Pack Design Considerations for Performance and Safety
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
PPTX
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
PDF
Consumable AI The What, Why & How for Small Teams.pdf
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
DOCX
search engine optimization ppt fir known well about this
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
Architecture types and enterprise applications.pdf
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
2018-HIPAA-Renewal-Training for executives
Taming the Chaos: How to Turn Unstructured Data into Decisions
Module 1.ppt Iot fundamentals and Architecture
Zenith AI: Advanced Artificial Intelligence
A comparative study of natural language inference in Swahili using monolingua...
Microsoft Excel 365/2024 Beginner's training
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
Modernising the Digital Integration Hub
The influence of sentiment analysis in enhancing early warning system model f...
Enhancing emotion recognition model for a student engagement use case through...
Custom Battery Pack Design Considerations for Performance and Safety
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
A Late Bloomer's Guide to GenAI: Ethics, Bias, and Effective Prompting - Boha...
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
Consumable AI The What, Why & How for Small Teams.pdf
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
search engine optimization ppt fir known well about this
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...

Discovering and Fixing Dependency Vulnerabilities for Kubernetes apps with Snyk and Codefresh