Snyk raises $7M to secure usage of open-source software for developers
British security firm Snyk Ltd. has raised $7 million in new funding for its protection service for developers who use open-source software.
The Series A round for the three-year-old startup was led by Boldstart Ventures and Canaan Partners and included Heavybit, FundFire, Peter McKay and others.
Described as a “developer-first security solution that helps you use open source code and stay secure,” Snyk continuously finds and fixes known vulnerabilities and license violations in open source dependencies. The service integrates into existing developer workflows, including integration with source control services such as GitHub and BitBucket, to monitor platforms as a service continuously as well as serverless apps in production.
In an interview with SiliconANGLE’s theCUBE in August, co-founder and Chief Executive Officer Guy Podjarny explained that oftentimes developers are not aware of just how much dependency there is on risky outside software packages. “Snyk deals with open-source security, specifically in Node.js in the world of NPM,” he said, referring to Node Package Manager. “NPM is amazing and allows us to build on the shoulders of giants. But there are some inherent security risks with just pulling code off the internet and running it in your application.”
Snyk appears to be finding a willing audience, with more thanr 120,000 developers using the platform, 100,000 projects protected and 350,000 downloads per month. The company has partnerships with Heroku, JFrog and Microsoft Sonar, and counts among its customers Google LLC, DigitalOcean Inc., Skyscanner Holdings Ltd., The New York Times Co. and SAP SE.
“Security controls must adapt to the new pace open source and cloud dictate,” Podjarny said. “Failing to do so is what led to the recent breaches at Equifax, Uber, and the Tesla cloud breach. We’re relying on strangers’ code to run the most sensitive aspect of our business, and do so at neck-breaking speed.”
Including the new round, Snyk has raised $10 million to date. The company said it will use the new funding to deploy additional product offerings that improve the secure usage of open source for developers.
Photo: SiliconANGLE
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.