Snyk, the $8.5 billion developer-focused security company that recently scored $600 million in late-stage funding, continued its buying spree with CloudSkiff.

Paris-based CloudSkiff created driftctl, an open source tool for drift detection, that Snyk says will boost its Snyk Infrastructure as Code (IaC) product capabilities — and it’s going to continue investing in the project’s open source development.

Driftctl catches drift outside of a developer’s infrastructure code, and this provides an important tool to identify discrepancies post deployment, Snyk co-founder and President Guy Podjarny explained.

“It might have changed because of a security flaw, but most of the time it changes because there was some ad-hoc problem in the infrastructure, or somebody wants to access some system and therefore just opened a port, or wanted to gather some data and therefore changed some permissions,” he said. “Development today is very fast moving, and that type of occurrence happens a lot.”

Customers wanted these drift-detection capabilities, and they seemed to be a “natural evolution” for the Snyk IaC product, Podjarny added. “It’s well aligned with the test and guardrails that developers put into their pipelines.”

CloudSkiff Deal Is Snyk’s Fourth in 12 Months

Snyk didn’t disclose financial details about the CloudSkiff deal, which is its fourth acquisition in the last 12 months. The three others were FossID, Manifold, and DeepCode. Snyk acquired FossID to expand its license compliance and C/C++ capabilities. Meanwhile, DeepCode provides real-time semantic code analysis, and Manifold has a cloud-native marketplace for developers.

Building security into the fabric of software development is a big feat that has many moving pieces, that, on one hand, each require its own expertise, and on the other hand, need to be woven together into a single platform,” Podjarny said.

The vendor aims to make developers’ lives “easier, not harder,” and to this end it built a platform and standalone products, he added. “The best-of-breed products have specific expertise around them — we built our R&D organization and really the entire company to be very modular,” Podjarny said. “And that allows us to acquire companies to serve additional aspects of security today.”

This includes products that find and fix vulnerabilities in application code, containers, infrastructure as code, and — Snyk’s original product — open source code.

“We built a platform, and we make these acquisitions and allow us to build on it,” Podjarny said. “What’s really important though is that while we will acquire and provide some of these capabilities, this problem is bigger than what we alone can solve. And so a key investment that we have is around being a platform that the ecosystem builds on.”

While Snyk has always used APIs to integrate with other security tools, at its annual SnykCon event last month it launched a new platform called Snyk App, which is based on the latest version of OpenAPI and allows a one-click way to embed Snyk’s security within existing developer workflows.

Snyk Impact

Also at the event, the company announced Snyk Learn, a free, self-paced security education portal for developers and a new social and environmental impact program called Snyk Impact.

To kick off the new environmental, social, and governance (ESG) program, Snyk contributed 100% of SnykCon sponsorship proceeds as well as matching up to $100,000 raised at SnykCon via the Snyk Community Impact Center. Those proceeds went to its initial tech nonprofit partners, which all work to furthering diversity in the tech industry: AIEDU, CareerVillage, DevelopforGood, FastForward, LearningEquality, and UPchieve.

Over the next few months, the company plans to introduce specific commitments around diversity and inclusion and incorporating more sustainability practices into its planning and business practice.

Snyk achieved CarbonNeutral certification last year.