Links

GitHub Read-only Projects

Snyk offers GitHub Read-only Projects, providing the ability to monitor a public GitHub repository that is not owned by your Organization.

How GitHub Read-only Projects work

Adding a read-only Project lets you track the vulnerabilities in a Project your are considering using as a dependency, a Project you are already using as a stand-alone independent tool within your business, or any other public repository where you do not need to actively prevent or fix issues using Snyk.
The repository is tested daily using your Organization's GitHub credentials. These automated tests are not counted as part of the test limits related to your Snyk plan.
Unlike Projects imported through the Snyk GitHub integration, Projects that are imported or monitored with the read-only status cannot do the following:
  • Use automatic retesting when a pull request is merged
  • Commit tests on any PR raised, to detect (and optionally block) new vulnerabilities from being introduced
  • Use automated fix PRs to recommend minimal changes to fix vulnerabilities
  • Use automated dependency upgrade PRs, to keep dependencies up to date and help avoid new vulnerabilities and simplify fixing those that are found.
  • Use manual Fix PRs generated through Snyk to address specific issues chosen by the user

Monitoring a public repository

You can import a read-only Project via the Add project > Monitor public GitHub repos menu in the Dashboard and Projects tabs, or by going to Monitor public GitHub repositories.
Add project, Monitor public GitHub repos
Add project, Monitor public GitHub repos
  1. 1.
    Enter a public repository to monitor, following the format owner/repository.
  2. 2.
    When a valid repository name is entered, click + Add repo. The repository is quickly tested for a supported manifest file.
  3. 3.
    Enter the public repositories you want to monitor and select Import N repository/ies.
Add repo and Import repository or repositories
Add repo and Import repository or repositories
© 2023 Snyk Limited | All product and company names and logos are trademarks of their respective owners.