Understanding vulnerability risk is key to assessing your DevOps health. The Snyk integration with Compass connects vulnerability data from Snyk Open Source, Snyk Code, Snyk Container, and Snyk Infrastructure as Code. This gives development, security, and SRE teams an up-to-date status view to easily track critical and high severity vulnerabilities that put applications at risk. This integration simplifies software component security, allowing you to know your overall component health and build more secure applications. It also makes remediation faster and easier by showing which applications are impacted by vulnerabilities as well as the responsible owner. By identifying and remediating issues at the component level, it’s much easier to build secure applications.

Features
  • Build more secure applications: Spot vulnerabilities, evaluate affected apps, assign fixes swiftly for speedy, safe development
  • Simplify component security: Automate code scans, contextualize critical findings, and maintain DevOps agility
  • Track component health: Monitor vulnerabilities with timelines and scorecards to improve security and DevOps
Benefits
  • A complete view of software component risk
  • Automated discovery
  • Single source of vulnerability information
  • Easy-to-understand security scorecards
  • Regularly updated metrics
Prerequisites
  • Snyk Enterprise plan to use the Snyk app for Compass.
How it Works
  • Install and configure the Snyk App for Compass.
  • Monitor Git repositories with Snyk Code, Snyk Container, Snyk Infrastructure as Code, and/or Snyk Open Source.
  • View open critical and high-severity vulnerabilities in the Compass activity feed or scorecards. Data is refreshed hourly.
  • See which software components contain vulnerabilities and who owns the components.
  • Remediate vulnerabilities using Snyk.
Demo Video

Version:
NA

Integration Categories:
Vulnerability Management

Support:
https://developer.atlassian.com/support

Snyk Products:

Website

Contact