Notifications
Clear all
AppSec
1
Posts
1
Users
0
Reactions
1
Views
Topic starter
18/07/2026 7:01 am
Hey everyone! Just finished rolling out Snyk across about 200 of our repos, mostly Node.js and Python. Super excited about the security boost! 😊
But wow, we got hit with a ton of false positives, especially in our Dockerfiles and CI configs. It was pretty overwhelming for us beginners. For example, Snyk kept flagging this base image line as high severity:
```dockerfile
FROM node:18-alpine
```
It said there were vulnerabilities in that image tag, but it's the official LTS version. Also had lots of noise from dev dependencies in `package.json`. How do you all manage this? I'd love some beginner-friendly advice on tuning Snyk to reduce the noise. Thanks so much for any help!