Sorting through the fluff: Declutter and remediate container vulnerabilities with context

Sorting through the fluff: Declutter and remediate container vulnerabilities with context

Description:

"At Atlassian, 99% of services deployed to production are built on containers. When implementing container scanning company wide for the first time we were faced with tens of thousands of issues being found by Snyk across the organization.

We chose to go against the grain of using CVSS scores exclusively when assigning severity to tickets and instead examined the issues in the context of their target operating systems. By utilizing the distros' relative importance provided by Snyk, we ensured any asks of our engineers were actionable and assigned an appropriate severity level that matched the prioritization needed from them.

Combining this with the process of identifying containers built on "golden" base images or services using common sidecars, we not only ensure developers can focus on issues they actually have control over, but also improve our security posture by keeping these container images and sidecars up to date across all Atlassian services."

Intervenants:

Sharada Moorthy

Senior Product Security Engineer, Atlassian

Will Ratner

Senior Product Security Engineer, Atlassian

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk est une plateforme de sécurité des développeurs. S’intégrant directement aux outils, workflows et pipelines de développement, Snyk facilite la détection, la priorisation et la correction des failles de sécurité dans le code, les dépendances, les conteneurs et l’infrastructure en tant que code (IaC). Soutenu par une intelligence applicative et sécuritaire de pointe, Snyk intègre l'expertise de la sécurité au sein des outils de chaque développeur.

Démarrez gratuitementRéservez une démo en ligne

© 2024 Snyk Limited
Enregistré en Angleterre et au Pays de Galles

logo-devseccon