UPDATED 09:00 EDT / MARCH 29 2018

INFRA

Snyk teams with Google to detect JavaScript vulnerabilities in Chrome Lighthouse

Security firm Snyk Ltd. today said it has partnered with Google LLC to power the vulnerable JavaScript libraries audit in Google Chrome’s Lighthouse, an automated developer tool for improving the quality of web apps.

The integration of Snyk’s open-source vulnerabilities data into Lighthouse is aimed at developing more secure web applications by making developers aware of securities in their code, so it’s easier to take action on them.

The Snyk data will be offered through Lighthouse’s “Best Practices” audit that detects front-end JavaScript libraries in use with a known security vulnerability by testing against Snyk’s vulnerability database. If any known security issues are detected, the developer receives a detailed report of each vulnerability with a link to Snyk to resolve the issues.

“In early 2017, researchers found that 37 percent of sites had at least one client-side JavaScript library containing a known security vulnerability,” Snyk Chief Executive Guy Podjarny said in a statement. “Recently, we completed a report noting that the reality was worse: 77 percent of the top 433,000 URLs used a JavaScript library with a known security issue. Recognizing the importance of the issue, Snyk collaborated with the Lighthouse team to audit vulnerable JavaScript libraries. This integration applies an extra layer of visibility for developers as we work toward making the web more secure by default.”

Snyk has been growing in popularity as developers become more aware of security vulnerabilities in open source software and code, much of which is commonly used in most web applications. Snyk’s data also integrates into existing developer workflows, including source control services such as GitHub and BitBucket.

In an interview with SiliconANGLE’s theCUBE in August, Podjarny explained that oftentimes developers are not aware of just how much dependency there is on risky outside software packages. “Snyk deals with open-source security, specifically in Node.js in the world of NPM,” he said, referring to Node Package Manager. “NPM is amazing and allows us to build on the shoulders of giants. But there are some inherent security risks with just pulling code off the internet and running it in your application.”

The company raised $7 million earlier this month from Boldstart Ventures, Canaan Partners, Heavybit and FundFire. As of its last round, Snyk said that it had more than 120,000 developers using the platform, 100,000 projects protected and 350,000 downloads per month.

Image: Google

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.