SlideShare a Scribd company logo
Discovering and Fixing Dependency
Vulnerabilities for Kubernetes apps
with Snyk and Codefresh
Antoine Arlaud, Snyk & Dan Garfield, Codefresh
Dan
Garfield
Chief Evangelist
Antoine
Arlaud
Figure Stuff Out Engineer
Open Source
Is just awesome
A Small
Portion of
Your App is
Your Code
SOFTWARE STACK
Custom Code
“Your” application
Libraries
Open source code
Base Image
Basic OS with associated software
packages
SOFTWARE STACK
Custom Code
“Your” application
Libraries
Open source code
Base Image
Basic OS with associated software
packages
+53%
Vulnerabilitie
s Found in OSS
YoY
Source:
https://www.prnewswire.com/news-releases/open-source-vulnerabilities-soar-a
n-additional-40-percent-in-2017-300556046.html
SOFTWARE STACK
Custom Code
“Your” application
Libraries
Open source code
Base Image
Basic OS with associated software
packages
Pipelines and Automation
Ships your code seamlessly
Containers
New deliverables for dev teams
Security
Is everyone’s responsibility
Let’s bake this in
Both App sec and OS Sec
Try it:
https://github.com/snyk-playground/codefresh-pipeline-snyk
-app-docker-scan
OUR APP PIPELINE
Commit Dependency
Scan
Docker
Build
Image
Scan
App
Build
Push to Dockerhub
Codefresh
Plugins
Code Scan
Scan for vulnerabilities packages in
Go, NPM, Java, and many more.
Docker Scan
Finds vulnerabilities in RPM,
Debian, and Alpine Package
Managers
Try it:
https://github.com/snyk-playground/codefresh-pipeline-snyk
-app-docker-scan
T
Get 120 FREE builds/month
Codefresh.io
Learn more at
snyk.io

More Related Content

What's hot (20)

PDF
React Native: Is It Worth It? UA Mobile 2017.
UA Mobile
 
PDF
DevOps Illustrated - A practical approach
David Oguntade
 
PPTX
Concurrent version management(tortoise CVS)
Mirza_Mohtashim
 
PDF
Open Source Compliance for DevOps - OSCON 2017
Bianca Xue Jiang
 
PPTX
Protecting Applications with Lambda@Edge and OAuth
Allan Denot
 
PDF
Testing Microservices
Nathan Jones
 
PPTX
Presentazione resin.io
Gianluca Leo
 
PDF
Continuous Integration on my work
Mu Chun Wang
 
PDF
Simple Unit Testing in Appcelerator Titanium Alloy
Aaron Saunders
 
PDF
In graph we trust: Microservices, GraphQL and security challenges
Mohammed A. Imran
 
PDF
Continuous Integration for Titanium
Denver Sessink
 
PPTX
Beyond Continuous Delivery - Jenkins User Conference - 23 Oct 2014
Chris Hilton
 
PDF
TiCalabash and TiMocha: The keys to Better & More Stable Titanium Apps
Andrew McElroy
 
PPTX
Tests your pipeline might be missing
Gene Gotimer
 
PDF
OWASP Workshop: Docker Image Security Best Practices by Liran Tal - January 2020
Liran Tal
 
PPTX
All you need is Zap - Omer Levi Hevroni & Yshay Yaacobi - DevOpsDays Tel Aviv...
DevOpsDays Tel Aviv
 
PPTX
ATAGTR2017 Upgrading a mobile tester's weapons with advanced debugging
Agile Testing Alliance
 
PPTX
Continuous SDK
Johannes Ebner
 
PDF
Continuous delivery in Qbon
Jaric Kuo
 
React Native: Is It Worth It? UA Mobile 2017.
UA Mobile
 
DevOps Illustrated - A practical approach
David Oguntade
 
Concurrent version management(tortoise CVS)
Mirza_Mohtashim
 
Open Source Compliance for DevOps - OSCON 2017
Bianca Xue Jiang
 
Protecting Applications with Lambda@Edge and OAuth
Allan Denot
 
Testing Microservices
Nathan Jones
 
Presentazione resin.io
Gianluca Leo
 
Continuous Integration on my work
Mu Chun Wang
 
Simple Unit Testing in Appcelerator Titanium Alloy
Aaron Saunders
 
In graph we trust: Microservices, GraphQL and security challenges
Mohammed A. Imran
 
Continuous Integration for Titanium
Denver Sessink
 
Beyond Continuous Delivery - Jenkins User Conference - 23 Oct 2014
Chris Hilton
 
TiCalabash and TiMocha: The keys to Better & More Stable Titanium Apps
Andrew McElroy
 
Tests your pipeline might be missing
Gene Gotimer
 
OWASP Workshop: Docker Image Security Best Practices by Liran Tal - January 2020
Liran Tal
 
All you need is Zap - Omer Levi Hevroni & Yshay Yaacobi - DevOpsDays Tel Aviv...
DevOpsDays Tel Aviv
 
ATAGTR2017 Upgrading a mobile tester's weapons with advanced debugging
Agile Testing Alliance
 
Continuous SDK
Johannes Ebner
 
Continuous delivery in Qbon
Jaric Kuo
 

Similar to Discovering and Fixing Dependency Vulnerabilities for Kubernetes apps with Snyk and Codefresh (20)

PPTX
Software Composition Analysis Deep Dive
Ulisses Albuquerque
 
PDF
Building android apps with Gradle (GREACH 2015)
René Gröschke
 
PDF
Open-Source Security Management and Vulnerability Impact Assessment
Priyanka Aash
 
PDF
Snyk Intro - Developer Security Essentials 2022
Liran Tal
 
PPTX
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
PPTX
Transforming your Security Products at the Endpoint
Ivanti
 
PDF
.NET Core on Mac
Melania Andrisan (Danciu)
 
PDF
Mobile Apps Using AngularJS - Adam Klein @ AngularJS IL
Ron Gershinsky
 
PPTX
Contemporary software TRENDS SOFTWARE TRENDS
melissaguillermo
 
PDF
Php Dependency Management with Composer ZendCon 2016
Clark Everetts
 
PDF
Analysis of-quality-of-pkgs-in-packagist-univ-20171024
Clark Everetts
 
PPT
IBM AppScan Source - The SAST solution
hearme limited company
 
PDF
Dockercon 2018 EU Updates
Ajeet Singh Raina
 
PDF
Exploiting and analyzing Microsoft Surface Applications
Wardell Motley, NSA IAM\IEM
 
PDF
Securing Open Source Code in Enterprise
Asankhaya Sharma
 
ODP
Effective DevSecOps
Pawel Krawczyk
 
PDF
Php Dependency Management with Composer ZendCon 2017
Clark Everetts
 
PDF
Understanding SBOMs: An Introduction to Modern Development
Anchore
 
PDF
Deploying Containerised Open-Source CSP Platforms
Angel Borroy López
 
PDF
Know What’s in Your Containers! Manage and Secure all Open Source that Compos...
DevOps.com
 
Software Composition Analysis Deep Dive
Ulisses Albuquerque
 
Building android apps with Gradle (GREACH 2015)
René Gröschke
 
Open-Source Security Management and Vulnerability Impact Assessment
Priyanka Aash
 
Snyk Intro - Developer Security Essentials 2022
Liran Tal
 
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
Transforming your Security Products at the Endpoint
Ivanti
 
.NET Core on Mac
Melania Andrisan (Danciu)
 
Mobile Apps Using AngularJS - Adam Klein @ AngularJS IL
Ron Gershinsky
 
Contemporary software TRENDS SOFTWARE TRENDS
melissaguillermo
 
Php Dependency Management with Composer ZendCon 2016
Clark Everetts
 
Analysis of-quality-of-pkgs-in-packagist-univ-20171024
Clark Everetts
 
IBM AppScan Source - The SAST solution
hearme limited company
 
Dockercon 2018 EU Updates
Ajeet Singh Raina
 
Exploiting and analyzing Microsoft Surface Applications
Wardell Motley, NSA IAM\IEM
 
Securing Open Source Code in Enterprise
Asankhaya Sharma
 
Effective DevSecOps
Pawel Krawczyk
 
Php Dependency Management with Composer ZendCon 2017
Clark Everetts
 
Understanding SBOMs: An Introduction to Modern Development
Anchore
 
Deploying Containerised Open-Source CSP Platforms
Angel Borroy López
 
Know What’s in Your Containers! Manage and Secure all Open Source that Compos...
DevOps.com
 
Ad

More from Codefresh (20)

PDF
Detect, debug, deploy with Codefresh and Lightstep
Codefresh
 
PDF
CICD Pipelines for Microservices: Lessons from the Trenches
Codefresh
 
PDF
Simplify Your Code with Helmfile
Codefresh
 
PDF
Making the Most of Helm 3 with Codefresh
Codefresh
 
PDF
5 Simple Tips for Troubleshooting Your Kubernetes Pods
Codefresh
 
PDF
Best Practices for Microservice CI/CD: Lessons from Expedia and Codefresh
Codefresh
 
PDF
Hybrid CI/CD with Kubernetes & Codefresh
Codefresh
 
PDF
VM vs Docker-Based Pipelines
Codefresh
 
PDF
Why You Should be Using Multi-stage Docker Builds in 2019
Codefresh
 
PPTX
Deploy Secure Cloud-Native Apps Fast
Codefresh
 
PDF
CICD Pipelines for Microservices Best Practices
Codefresh
 
PDF
Codefresh CICD New Features Launch! May 2019
Codefresh
 
PDF
Terraform GitOps on Codefresh
Codefresh
 
PDF
Adding Container Image Scanning to Your Codefresh Pipelines with Anchore
Codefresh
 
PDF
Image scanning using Clair
Codefresh
 
PDF
Updating Kubernetes With Helm Charts: Build, Test, Deploy with Codefresh and...
Codefresh
 
PDF
Docker based-Pipelines with Codefresh
Codefresh
 
PDF
Automated Serverless Pipelines with #GitOps on Codefresh
Codefresh
 
PDF
Net Pipeline on Windows Kubernetes
Codefresh
 
PPTX
Multi-cloud CI/CD with failover powered by K8s, Istio, Helm, and Codefresh
Codefresh
 
Detect, debug, deploy with Codefresh and Lightstep
Codefresh
 
CICD Pipelines for Microservices: Lessons from the Trenches
Codefresh
 
Simplify Your Code with Helmfile
Codefresh
 
Making the Most of Helm 3 with Codefresh
Codefresh
 
5 Simple Tips for Troubleshooting Your Kubernetes Pods
Codefresh
 
Best Practices for Microservice CI/CD: Lessons from Expedia and Codefresh
Codefresh
 
Hybrid CI/CD with Kubernetes & Codefresh
Codefresh
 
VM vs Docker-Based Pipelines
Codefresh
 
Why You Should be Using Multi-stage Docker Builds in 2019
Codefresh
 
Deploy Secure Cloud-Native Apps Fast
Codefresh
 
CICD Pipelines for Microservices Best Practices
Codefresh
 
Codefresh CICD New Features Launch! May 2019
Codefresh
 
Terraform GitOps on Codefresh
Codefresh
 
Adding Container Image Scanning to Your Codefresh Pipelines with Anchore
Codefresh
 
Image scanning using Clair
Codefresh
 
Updating Kubernetes With Helm Charts: Build, Test, Deploy with Codefresh and...
Codefresh
 
Docker based-Pipelines with Codefresh
Codefresh
 
Automated Serverless Pipelines with #GitOps on Codefresh
Codefresh
 
Net Pipeline on Windows Kubernetes
Codefresh
 
Multi-cloud CI/CD with failover powered by K8s, Istio, Helm, and Codefresh
Codefresh
 
Ad

Recently uploaded (20)

PPTX
𝙳𝚘𝚠𝚗𝚕𝚘𝚊𝚍—Wondershare Filmora Crack 14.0.7 + Key Download 2025
sebastian aliya
 
PDF
From Chatbot to Destroyer of Endpoints - Can ChatGPT Automate EDR Bypasses (1...
Priyanka Aash
 
PDF
Java 25 and Beyond - A Roadmap of Innovations
Ana-Maria Mihalceanu
 
PDF
Why aren't you using FME Flow's CPU Time?
Safe Software
 
PDF
The Future of Product Management in AI ERA.pdf
Alyona Owens
 
PPTX
Enabling the Digital Artisan – keynote at ICOCI 2025
Alan Dix
 
PDF
Unlocking FME Flow’s Potential: Architecture Design for Modern Enterprises
Safe Software
 
PDF
Cracking the Code - Unveiling Synergies Between Open Source Security and AI.pdf
Priyanka Aash
 
PPTX
MARTSIA: A Tool for Confidential Data Exchange via Public Blockchain - Pitch ...
Michele Kryston
 
PDF
“MPU+: A Transformative Solution for Next-Gen AI at the Edge,” a Presentation...
Edge AI and Vision Alliance
 
PPTX
Paycifi - Programmable Trust_Breakfast_PPTXT
FinTech Belgium
 
PPTX
CapCut Pro Crack For PC Latest Version {Fully Unlocked} 2025
pcprocore
 
PDF
Plugging AI into everything: Model Context Protocol Simplified.pdf
Abati Adewale
 
PPTX
reInforce 2025 Lightning Talk - Scott Francis.pptx
ScottFrancis51
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PDF
Python Conference Singapore - 19 Jun 2025
ninefyi
 
PDF
Darley - FIRST Copenhagen Lightning Talk (2025-06-26) Epochalypse 2038 - Time...
treyka
 
PDF
ArcGIS Utility Network Migration - The Hunter Water Story
Safe Software
 
PDF
Open Source Milvus Vector Database v 2.6
Zilliz
 
PDF
Hello I'm "AI" Your New _________________
Dr. Tathagat Varma
 
𝙳𝚘𝚠𝚗𝚕𝚘𝚊𝚍—Wondershare Filmora Crack 14.0.7 + Key Download 2025
sebastian aliya
 
From Chatbot to Destroyer of Endpoints - Can ChatGPT Automate EDR Bypasses (1...
Priyanka Aash
 
Java 25 and Beyond - A Roadmap of Innovations
Ana-Maria Mihalceanu
 
Why aren't you using FME Flow's CPU Time?
Safe Software
 
The Future of Product Management in AI ERA.pdf
Alyona Owens
 
Enabling the Digital Artisan – keynote at ICOCI 2025
Alan Dix
 
Unlocking FME Flow’s Potential: Architecture Design for Modern Enterprises
Safe Software
 
Cracking the Code - Unveiling Synergies Between Open Source Security and AI.pdf
Priyanka Aash
 
MARTSIA: A Tool for Confidential Data Exchange via Public Blockchain - Pitch ...
Michele Kryston
 
“MPU+: A Transformative Solution for Next-Gen AI at the Edge,” a Presentation...
Edge AI and Vision Alliance
 
Paycifi - Programmable Trust_Breakfast_PPTXT
FinTech Belgium
 
CapCut Pro Crack For PC Latest Version {Fully Unlocked} 2025
pcprocore
 
Plugging AI into everything: Model Context Protocol Simplified.pdf
Abati Adewale
 
reInforce 2025 Lightning Talk - Scott Francis.pptx
ScottFrancis51
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
Python Conference Singapore - 19 Jun 2025
ninefyi
 
Darley - FIRST Copenhagen Lightning Talk (2025-06-26) Epochalypse 2038 - Time...
treyka
 
ArcGIS Utility Network Migration - The Hunter Water Story
Safe Software
 
Open Source Milvus Vector Database v 2.6
Zilliz
 
Hello I'm "AI" Your New _________________
Dr. Tathagat Varma
 

Discovering and Fixing Dependency Vulnerabilities for Kubernetes apps with Snyk and Codefresh