GitHub Read-only Projects
Snyk offers GitHub Read-only Projects, providing the ability to monitor a public GitHub repository that is not owned by your Organization.
Adding a read-only Project lets you track the vulnerabilities in a Project your are considering using as a dependency, a Project you are already using as a stand-alone independent tool within your business, or any other public repository where you do not need to actively prevent or fix issues using Snyk.
The repository is tested daily using your Organization's GitHub credentials. These automated tests are not counted as part of the test limits related to your Snyk plan.
Unlike Projects imported through the Snyk GitHub integration, Projects that are imported or monitored with the read-only status cannot do the following:
- Use automatic retesting when a pull request is merged
- Commit tests on any PR raised, to detect (and optionally block) new vulnerabilities from being introduced
- Use automated dependency upgrade PRs, to keep dependencies up to date and help avoid new vulnerabilities and simplify fixing those that are found.
- Use manual Fix PRs generated through Snyk to address specific issues chosen by the user
You can import a read-only Project via the Add project > Monitor public GitHub repos menu in the Dashboard and Projects tabs, or by going to Monitor public GitHub repositories.
Add project, Monitor public GitHub repos
- 1.Enter a public repository to monitor, following the format owner/repository.
- 2.When a valid repository name is entered, click + Add repo. The repository is quickly tested for a supported manifest file.
- 3.Enter the public repositories you want to monitor and select Import N repository/ies.
Add repo and Import repository or repositories