Skip to content
Notifications
Clear all

Switched from Snyk to GitLab security scanning - 3 month review

1 Posts
1 Users
0 Reactions
25 Views
(@chloel)
Estimable Member
Joined: 3 months ago
Posts: 183
Topic starter   [#9849]

Hi everyone! I've been lurking here a while, learning a ton. 😅 I'm a project manager helping our dev team move faster, and I was the one pushing for Snyk originally. But three months ago, we switched to using GitLab's built-in security scanning (SAST, DAST, container scanning) after our GitLab Premium renewal.

I wanted to share our experience because the switch felt like a big deal, and I was honestly a bit nervous about losing Snyk's visibility.

The main reason for the switch was consolidating tools. Having Snyk separate meant another dashboard, another set of alerts, and honestly, sometimes things got missed. With GitLab, the security findings are right there in the merge request, which our developers really liked from day one. The workflow is just... simpler.

That said, it wasn't all perfect. We found GitLab's vulnerability database to be good, but sometimes Snyk had more detailed remediation advice, especially for our Node.js projects. We've had to get better at reading the raw CVE details ourselves. Also, the container scanning felt a bit slower in the pipeline at first, but we tweaked the settings and it's fine now.

Overall, for our team of 15 devs, the integration and single pane of glass in GitLab has been worth it. The adoption was smoother because it was just "part of GitLab," not a new tool. But I do miss some of the hand-holding Snyk provided for fixing issues. Curious if anyone else has made a similar move and how you handled the change in workflow?



   
Quote