We use cookies to ensure you get the best experience on our website.Read moreRead moreGot it

close
  • Products
    • Products
      • Snyk Code (SAST)
        Secure your code as it’s written
      • Snyk Open Source (SCA)
        Avoid vulnerable dependencies
      • Snyk Container
        Keep your base images secure
      • Snyk Infrastructure as Code
        Develop secure cloud infrastructure
      • Snyk Cloud
        Keep your cloud environment secure
    • Solutions
      • Application security
        Build secure, stay secure
      • Software supply chain security
        Mitigate supply chain risk
      • Cloud security
        Build and operate securely
    • Platform
      • What is Snyk?
        Developer-first security in action
      • Developer security platform
        Modern security in a single platform
      • Security intelligence
        Comprehensive vulnerability data
      • License compliance management
        Manage open source usage
      • Snyk Learn
        Self-service security education
  • Resources
    • Using Snyk
      • Documentation
      • Vulnerability intelligence
      • Product training
      • Support & services
      • Support portal & FAQ’s
      • User hub
    • learn & connect
      • Blog
      • Community
      • Events & webinars
      • DevSecOps hub
      • Developer & security resources
    • Listen to the Cloud Security Podcast, powered by Snyk
  • Company
    • About Snyk
    • Customers
    • Partners
    • Newsroom
    • Snyk Impact
    • Contact us
    • Jobs at Snyk We are hiring
  • Pricing
Log inBook a demoSign up
All articles
  • Application Security
  • Cloud Native Security
  • DevSecOps
  • Engineering
  • Partners
  • Snyk Team
  • Show more
    • Vulnerabilities
    • Product
    • Ecosystems
secure containerized applications
Cloud Native SecurityPartners

Snyk and Docker partner to secure containerized applications

Jim Armstrong
Jim ArmstrongMay 19, 2020

We are excited to announce our latest partnership, this time with the biggest name in the container industry—Docker. For the first time, Docker, the favorite container development tool for millions of developers, will provide native vulnerability detection and fixes, powered by Snyk. Together, Snyk and Docker will help developers securely build and use containers and open source. Development teams can create and ship their container-based applications with confidence, without requiring an advanced background in security and operating system administration. 

Security will be part of the Docker development workflow

Container security latest trend
Container security latest security trend

According to Snyk’s State of Open Source Security report, 54% of developers currently do not test their container images during development, and yet there was a 4x increase in reported operating system vulnerabilities, in 2018. But if you’re a developer, you’ve likely run `docker build`, `docker run`, and `docker push` commands. Now imagine running a `docker scan` and, within a few seconds, you get a report of all your container image vulnerabilities. What’s more, because the scans are powered by Snyk you get guidance geared to helping developers fix the reported issues.

Simplified workflows designed for developer-first security

If you’ve ever read a CVE report for a vulnerability, you know it tells you which files are affected by a certain vulnerability. But in the context of container building, developers’ responsibility mainly lies in picking the appropriate base image and adding it in their tools, rather than handpicking or recompiling vulnerable dependencies. Put these two together, and the typical laundry list of container vulnerabilities is of little use and very far from being actionable

Snyk provides fix guidance targeted at developers using containers. For issues introduced by your base images, Snyk helps you select Docker Official images from the same family with fewer vulnerabilities, and alerts you when Docker pushes updates to the base image you’re currently using, as shown in the example below for the `node:10.4.0` base image.

 snyk offer docker official images from the same family with fewer vulnerabilities

For issues in user layers, Snyk directs you to the line in your Dockerfile that introduces a particular vulnerability. Snyk’s ability to show the Dockerfile detail along with full dependency tree information makes it simple to figure out how to fix the problem.

snyk directs you to the line in your dockerfile that introduces vulnerability

Snyk and Docker increase developer efficiency to secure containerized applications

Finding out that your application or containers have serious vulnerabilities is never pleasant, particularly when it comes late in the deployment cycle and blocks apps from reaching production. Even worse is getting a long list of vulnerabilities written for hardcore security practitioners with fixes that assume you’re a sysadmin maintaining operating systems in a virtual machine.

In the same way that Docker made containers easy to use for developers, Snyk helps developers use containers and open source and stay secure making docker security more accessible. Only when security is embedded into developers’ workflow is it possible to scale security while increasing the pace of application delivery. With the integration of Snyk’s developer-focused image scanning technology and vulnerability database into Docker, developers get continuous security at the desktop level and throughout the inner and outer loop development process. 

Snyk is coming soon to a Docker near you

The Snyk and Docker partnership marks the first security integration for Docker, with Snyk as the exclusive provider of native vulnerability scanning to Docker services used by millions of developers who gain continuous security integrated into their inner-loop development process. 

We’re excited about the work both teams are doing to deliver the industry’s first combined container development and application security tools. Snyk is also proud to be a Platinum sponsor of DockerCon, kicking off May 28 at 9:00 am PT / 12:00 pm ET / 4:00 pm GMT. Snyk CEO, Peter McKay, will be joining Docker CEO Scott Johnston on theCube at 5:30 ET / 2:30 PT to talk about the partnership. For Docker’s perspective on the new partnership, check out Docker’s blog post and the joint Docker/Snyk press release. 

Two other snykers will also be presenting sessions at DockerCon. Sign up for DockerCon to attend the sessions below:

  • Gareth Rushgrove, Snyk Product Director: Building a Docker Image Packaging Pipeline Using GitHub Actions at 3:00 pm ET / 12:00 pm PT
  • Jim Armstrong, Snyk Product Marketing Director: Your Container Has Vulnerabilities…Now What? at 6:30 pm ET / 3:30 pm PT

Stay secure!

Discuss this blog on Discord

Join the DevSecOps Community on Discord to discuss this topic and more with other security-focused practitioners.

GO TO DISCORD
Footer Wave Top
Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment
Develop Fast.
Stay Secure.
Snyk|Open Source Security Platform
Sign up for freeBook a demo

Product

  • Developers & DevOps
  • Vulnerability database
  • API status
  • Pricing
  • IDE plugins
  • What is Snyk?

Resources

  • Snyk Learn
  • Blog
  • Security fundamentals
  • Resources for security leaders
  • Documentation
  • Snyk API
  • Disclosed vulnerabilities
  • Open Source Advisor
  • FAQs
  • Website scanner
  • Code snippets
  • Japanese site
  • Audit services
  • Web stories

Company

  • About
  • Snyk Impact
  • Customers
  • Jobs at Snyk
  • Snyk for government
  • Legal terms
  • Privacy
  • Press kit
  • Events
  • Security and trust
  • Do not sell my personal information

Connect

  • Book a demo
  • Contact us
  • Support
  • Report a new vuln

Security

  • JavaScript Security
  • Container Security
  • Kubernetes Security
  • Application Security
  • Open Source Security
  • Cloud Security
  • Secure SDLC
  • Cloud Native Security
  • Secure coding
  • Python Code Examples
  • JavaScript Code Examples
  • Code Checker
  • Python Code Checker
  • JavaScript Code Checker
Snyk|Open Source Security Platform

Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.

Resources

  • Snyk Learn
  • Blog
  • Security fundamentals
  • Resources for security leaders
  • Documentation
  • Snyk API
  • Disclosed vulnerabilities
  • Open Source Advisor
  • FAQs
  • Website scanner
  • Code snippets
  • Japanese site
  • Audit services
  • Web stories

Track our development

© 2023 Snyk Limited
Registered in England and Wales
Company number: 09677925
Registered address: Highlands House, Basingstoke Road, Spencers Wood, Reading, Berkshire, RG7 1NT.
Footer Wave Bottom