~900 repositories
“Implemented SAST and SCA scanning for ~900 repositories in less than a month”
As published on snyk.io. Captured by usedby on Oct 7, 2026.
What happened
Pomelo, a fintech company, uses Snyk's application security platform (Open Source and Code) to run SAST and SCA scanning across its repositories. It replaced a custom-built CircleCI security orb and connected Snyk to tools such as Jira, Slack, GitHub and CircleCI to build an end-to-end application security program.
Summary written by usedby from the source page, in English. The figures are those of Snyk and Pomelo, not ours.
- ~200 developers“Granted Snyk platform access to ~200 developers in under three weeks”
- 9,500“Resolved 9,500 vulnerabilities, for a total of 2,150 Highs and 200 Criticals (including 100 that contained mature exploits)”
When they started with Snyk, the Pomelo team set two goals: Covering all ~900 repositories with Snyk Granting Snyk platform access to all development teams (~200 developers) In less than a month, Pomelo and Snyk met both of these goals and rolled out security training for managers and engineers.
The most important thing for us is that you can manage the security test findings data from one place.
What the story claims, and what we checked
We compared the story with its live page on Oct 7, 2026.
- The figure: ~900 repositoriesCheckedPrinted word for word on the page, near the name of Pomelo.
- The passage quoted aboveCheckedCopied word for word from the page, near the name of Pomelo.
- Pomelo uses SnykCheckedConfirmed line. Latest check across sources: Oct 7, 2026.
- The result itselfNot checkedWe quote it; we did not measure it.




