5 ways to get Node.js vulnerability alerts

著者:

June 2, 2016

0 分で読めます

Here at Snyk, we maintain a database of known vulnerabilities in Node.js and front-end npm packages, called Vulnerability DB (also on GitHub). For each vulnerability, it includes a description of the vulnerability, additional references, and most importantly, how to remediate it. The remediations offered are typically either to upgrade to a new version of the package, or - for cases when you cannot or will not upgrade - to apply a patch created by the Snyk security team.

The best way to make sure your project (including all of its dependencies) is constantly monitored for new security risks is have Snyk monitor your specific dependencies for relevant new vulnerabilities. You can do so once using snyk wizard or track your dependencies continuously by adding snyk monitor to your deployment process. This way you’ll get a Snyk alert only for issues in the dependencies your specific project uses.

However, if you also want to get notified about all the new vulns we add to our DB, here are a few IFTTT recipes you’ll find useful.

Slack messages

Email messages

Twitter direct messages

Trello cards

Text messages

These notification methods are all based on the Vulnerability DB RSS feed — feel free to make your own recipes!

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk (スニーク) は、デベロッパーセキュリティプラットフォームです。Snyk は、コードやオープンソースとその依存関係、コンテナや IaC (Infrastructure as a Code) における脆弱性を見つけるだけでなく、優先順位をつけて修正するためのツールです。世界最高峰の脆弱性データベースを基盤に、Snyk の脆弱性に関する専門家としての知見が提供されます。

無料で始める資料請求

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon