# Homepage

Scan, prioritize, and fix vulnerabilities in your code, open-source dependencies, container images, and cloud configurations.

Check out the latest [updates in the Snyk user documentation](/whats-new).

<table data-view="cards" data-full-width="false"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-type="content-ref"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Discover Snyk</strong></td><td>New to Snyk? Learn what it is, what's new, what languages are supported, and how to get started.</td><td><a href="/files/X8vRj3GBLlQAA9wHr1RJ">/files/X8vRj3GBLlQAA9wHr1RJ</a></td><td></td><td><a href="/pages/lEsBvabZM8V481dNuDL1">/pages/lEsBvabZM8V481dNuDL1</a></td></tr><tr><td><strong>Platform administration</strong></td><td>Set up and run Snyk: SSO, Snyk hierarchy, user roles, and Snyk Broker.</td><td><a href="/files/5QipPmOj5gIK8SaGohlB">/files/5QipPmOj5gIK8SaGohlB</a></td><td><a href="/spaces/IgtgtomLQ2TUgSKOMSAm">/spaces/IgtgtomLQ2TUgSKOMSAm</a></td><td><a href="/spaces/IgtgtomLQ2TUgSKOMSAm">/spaces/IgtgtomLQ2TUgSKOMSAm</a></td></tr><tr><td><strong>Scan, fix, and prevent</strong></td><td>Find, fix, and prevent issues across your software development lifecycle. Prioritize fixes and enforce policies.</td><td><a href="/files/0fmlPcQghhuQQKBiNuPd">/files/0fmlPcQghhuQQKBiNuPd</a></td><td><a href="/spaces/BJO0IZx7zB6bOkotxQP2">/spaces/BJO0IZx7zB6bOkotxQP2</a></td><td><a href="/spaces/BJO0IZx7zB6bOkotxQP2">/spaces/BJO0IZx7zB6bOkotxQP2</a></td></tr><tr><td><strong>Developer tools</strong></td><td>Bring security into your workflow with the Snyk CLI, IDE plugins, SCM and CI/CD integrations, and the Snyk API.</td><td><a href="/files/tQt5L9Wbqfq1qtHU7l0u">/files/tQt5L9Wbqfq1qtHU7l0u</a></td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf">/spaces/IEEjSXQQu36y0vmFV8zf</a></td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf">/spaces/IEEjSXQQu36y0vmFV8zf</a></td></tr><tr><td><strong>Agent security</strong></td><td>Secure AI-driven development with Snyk Studio, Agent Scan, and Agent Guard.</td><td><a href="/files/xZ1QAXwIWxWZuTbqonwq">/files/xZ1QAXwIWxWZuTbqonwq</a></td><td><a href="/spaces/N5N885PkllOWeBmgm3Bp">/spaces/N5N885PkllOWeBmgm3Bp</a></td><td><a href="/spaces/N5N885PkllOWeBmgm3Bp">/spaces/N5N885PkllOWeBmgm3Bp</a></td></tr><tr><td><strong>Snyk data and governance</strong></td><td>How Snyk handles your data: generative AI use, residency, and compliance.</td><td><a href="/files/d4tFm38qE8CbTqg0ocpt">/files/d4tFm38qE8CbTqg0ocpt</a></td><td><a href="/spaces/ELvljsaLKPkSpffOkmsQ">/spaces/ELvljsaLKPkSpffOkmsQ</a></td><td><a href="/spaces/ELvljsaLKPkSpffOkmsQ">/spaces/ELvljsaLKPkSpffOkmsQ</a></td></tr></tbody></table>


# What's Snyk?

Snyk is a developer security platform that finds and fixes vulnerabilities in code, open source, containers, infrastructure as code, and live apps.

Snyk is a platform that allows you to scan, prioritize, and fix security vulnerabilities in your code, open-source dependencies, container images, infrastructure as code configurations, and after your web application or API is live. The Snyk platform uses a risk-based approach, focusing security efforts on issues that matter, and eliminating the noise of vulnerabilities that have no meaningful impact.

To manage and govern the security program, Snyk gives security teams immediate visibility into coverage and business context across all application assets, smart policies to automate and scale in large environments, and analytics and reporting to measure the performance of your security program.

* Snyk Open Source and Snyk Code: see Supported languages, package managers, and frameworks.
* Snyk Secrets: see [Snyk Secrets](https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-secrets).
* Snyk Container: see [Supported operating system distributions](https://docs.snyk.io/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container).
* Snyk Infrastructure as Code: see [Supported IaC and cloud providers](https://docs.snyk.io/scan-with-snyk/snyk-iac/supported-iac-languages-cloud-providers-and-cloud-resources).
* Snyk Essentials: see [Snyk Essentials](https://docs.snyk.io/scan-with-snyk/snyk-essentials).
* Snyk API & Web: see [Snyk API & Web](https://snyk.io/product/dast-api-web/).

## The Snyk developer-first approach

Snyk provides visibility in a developer's workflow and actionable insights. The benefit is engaging developers in security practices as part of their development work. Thus, the focus is on building a secure application rather than overhead-intensive work, such as putting in hard quality assurance gates.

Developers now assemble applications with a combination of proprietary and open-source code, run that code in containers, and then deploy with infrastructure as code configurations using technologies like Kubernetes and Terraform.

A robust security process secures each component where they are built and maintained. Snyk integrates into DevOps processes to work with developers using the methods each prefers, while following and supporting industry best practices. Snyk integrates directly into your IDEs, workflows, and automation pipelines to add security expertise to your toolkit.

## Use Snyk in your workflow

* Secure your code: use [Snyk Open Source](https://docs.snyk.io/scan-with-snyk/snyk-open-source) to fix vulnerabilities in your open source dependencies and [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) to fix vulnerabilities in your source code.
* Secure your secrets: use [Snyk Secrets](https://docs.snyk.io/scan-with-snyk/snyk-secrets) to detect hard-coded secrets, credentials, and API keys across the IDE, CLI, SCM, and pull request checks.
* Secure your containers: use [Snyk Container](https://docs.snyk.io/scan-with-snyk/snyk-container) to fix vulnerabilities in container images and Kubernetes applications.
* Secure your infrastructure: use [Snyk Infrastructure as Code](https://docs.snyk.io/scan-with-snyk/snyk-iac) (IaC) to fix misconfigurations in Terraform, CloudFormation, Kubernetes, and Azure templates.
* Secure your APIs and web applications: use [Snyk API & Web](https://snyk.io/product/dast-api-web/) to discover and test the security of all your APIs and web apps, including those AI-generated.

## Choose how to run Snyk

You can run Snyk in the following ways:

* Web: the Snyk Web UI ([app.snyk.io](https://app.snyk.io)) provides a browser-based experience with functions such as configuration settings, filtering and fixing discovered issues, and reports.
* [CLI](https://docs.snyk.io/snyk-cli): the Snyk Command Line Interface enables you to run vulnerability scans on your local machine and integrate Snyk into your pipeline.
* [IDEs](https://docs.snyk.io/integrations/snyk-ide-plugins-and-extensions): the Snyk IDE integrations enable you to embed Snyk in your development environment.
* [API](https://docs.snyk.io/snyk-api/snyk-api): the Snyk API enables you to integrate with Snyk programmatically, tuning Snyk security automation to your specific workflows.

## What can Snyk integrate with?

Snyk integrations for your software development process allow you to integrate Snyk into your development and security processes, including source control, IDE, CI/CD, and many others.

For details, see [Integrate with Snyk](https://docs.snyk.io/integrations/integrate-with-snyk).

## **What does Snyk cost?**

Snyk has several pricing plans available, from free to Enterprise. See [Snyk Pricing Plans](https://snyk.io/plans/).

Snyk offers a trial of the platform, but this has imposed feature limitations. See Trial limitations.

## What happens to my data?

For details on Snyk handling, see [How Snyk handles your data](https://docs.snyk.io/how-snyk-handles-your-data).


# Glossary

Definitions of Snyk platform terms and security concepts used throughout the Snyk documentation

## A

### ADE

An Agentic Development Environment (ADE), also known as an Agentic IDE, is a engineering workspace where AI agents execute defined tasks.

### Advisor

See [Snyk Advisor](https://snyk.io/advisor/).

### Agent

A software entity that uses an artificial intelligence model to reason, make decisions, and take autonomous actions to achieve a goal. It uses LLMs and various tools, memory, and external systems, not just generated text, to accomplish a specific task on the user’s behalf.

### Agent frameworks

Software libraries and platforms that provide the tools to build, manage, and coordinate the behavior of autonomous AI agents.

### AI evaluation

The process of measuring an AI system’s performance, quality, and safety against defined goals and benchmarks, using tests, metrics, and human judgement.

### Agentic

The ability of an AI system to plan, reason, and act independently toward a goal without explicit human instruction. Following multiple instructions, it can determine the next steps by itself, without direction.

### AI observability

The ability to monitor and trace the internal behavior, performance, and decision-making processes of AI systems in real time. It’s critical for traceability, especially in the context of complex, distributed, or agentic systems.

### AI orchestration

The management and coordination of multiple AI models, agents, and tools to complete complex tasks as a unified system, using frameworks.

### AI runtime

The execution environment where AI models actually run in production, and, based on a trained model or agent and input executes inference or actions and returns results. For example laptops or endpoints, a container, or the cloud.

### AI training

The process of teaching an AI model how to perform tasks. It involves feeding the model large datasets so it can learn patterns, facts, and how to respond to different situations.

### AI-SPM

AI Security Posture Management (AISPM) is a category of security tooling focused on discovering, monitoring, and governing artificial intelligence systems, including their models, data sources, and infrastructure.

### Asset (Snyk Essentials)

A Snyk Essentials asset is an identifiable entity that is part of an application, and relevant for security and developers. Snyk is generally focused on the development stages of application software, secures repository assets containing software package assets, and builds artifacts like container image assets.

### Application (Snyk Essentials)

An application is software that serves a business purpose and consists of assets that form the app. Organizations often define the scope of an application differently.

### Application graph

Represents the mapping of security issues, application assets, relationships between assets, and all relevant contextual information.

## B

### Base image

The parent image used to construct a container image, usually defined in the `FROM` directive in a Dockerfile. Base images themselves can be constructed from other base images.

### Broker

See [Snyk Broker](https://docs.snyk.io/enterprise-setup/snyk-broker).

### Build system

A system that takes the source code and builds the deployable application (such as a container).

### Business context

Information related to the organization's objectives, priorities, and regulatory requirements, such as criticality of the application to the business, compliance standards, data sensitivity, and potential impact on revenue or reputation.

## C

### CI/CD

Continuous integration (CI), continuous delivery (CD), and continuous deployment (CD) together comprise a Software Development Lifecycle (SDLC) model, guiding developers to automate the development and delivery of small, frequent changes. This ensures all team members have access to the latest codebase and can ensure the compatibility of committed code during development. See [Snyk CI/CD](https://docs.snyk.io/integrate-with-snyk/continuous-integration-ci-and-continuous-delivery-cd) for details of Snyk CI/CD integrations.

### Class (Snyk Essentials)

A way to assign business context to assets and categorize an asset based on the business criticality. Assets can be assigned Classes A, B, C, or D, where Class A (assets that are business critical, deal with sensitive data, are subject to compliance, and so on) is the most important, and Class D (test apps, sandbox environments, and so on) the least important. Assets are assigned Class C by default. A class can be used in policies as well as defined in a policy.

### CLI

Command Line Interface. A text-based tool that interacts with an operating system or application by typing specific commands into a terminal to perform tasks and automate workflows. See [Snyk CLI](#snyk-cli).

### Cloud Native Application Security

Implementing security throughout the CI/CD pipeline, automating security embedding in microservices, and maximizing repetition to reduce the introduction of vulnerabilities. Snyk provides a comprehensive [CNAS platform](https://snyk.io/product/cloud-native-application-security/). See [Cloud-native security guide for building secure applications](https://snyk.io/learn/cloud-native-security-for-cloud-native-applications/).

### Code assets (Snyk Essentials)

A hierarchical list of all assets retrieved from the scanned repositories.

### Command directive

A Command directive is a type of [Directive](#directive) that is manually invoked by you or an AI agent to codify and standardize complex rulesets. For more information, visit [Command directives](https://docs.snyk.io/agent-security/snyk-studio/directives#command-directives).

### Container

Containers allow you to package applications and their dependencies together to be deployed as a single runnable unit. A container is an abstraction provided by the operating system kernel that allows a process to be isolated from other processes running on the system. See also [Snyk Container.](#snyk-container)

### Container engine

For users, an application that takes a container image and turns it into a running container. Container engines typically interface with container registries and run containers. Examples of container engines include Docker, CRI-O, and LXC.

### Container image

One or more files that, when instantiated by a container engine or runtime, provide a running container. Images are the packaging and distribution format for containers.

### Container registry

A server that provides a mechanism to store and retrieve container images.

### Context window

The maximum amount of information that an artificial intelligence model can consider and remember at a single point in time during a conversation or task.

### Controls (Snyk Essentials)

The security controls associated with the asset. Navigate to the Snyk Essentials Controls section to see all available statuses for security controls.

### Coverage (Snyk Essentials)

An assessment of whether applicable assets are scanned and tested by security tools (like Snyk Open Source, for instance), as it relates to an application security program. A type of policy that allows you to specify what controls should be applied and, optionally, how often it needs to be run.

### Coverage gap (Snyk **Essentials**)

An assessment of all assets that fall "out of policy" and do not satisfy the coverage criteria you have specified, due to infrequent scanning or no scanning at all.

### CVE

Common Vulnerabilities and Exposures. A widely-used identifier for a well-known vulnerability.

### CVSS

Common Vulnerability Scoring System. An industry standard to assess the severity of vulnerabilities, using a score of 0 (lowest) to 10 (highest). Snyk uses CVSS.

### CWE

Common Weakness Enumeration. An online glossary that categorizes software and hardware weaknesses into different types, for example, CWE-20: Input Validation.

## D

### DAST

Dynamic Application Security Testing. A security analysis technique that tests a running application from the outside to find security issues. See also [SAST](#sast).

### Directive

A directive is a rule (also known as a command, instruction, and more) that guides an AI agent to produce code in the specified method. Snyk offers code examples for different directive types to implement in your organization and potentially distribute company-wide if you operate in an enterprise model. This is used in context with Snyk Studio. To learn more, visit [Directives](https://docs.snyk.io/agent-security/snyk-studio/directives).

### Dependency

When your application uses another package, this other package becomes a dependency in your own software.

* A direct dependency is a package you include in your own Project.
* An indirect dependency (also known as a deep, chained, or transitive dependency), is a package that is used by one of your direct dependencies.

### Dependency tree

Also known as Dependency path. A hierarchical graph showing the dependencies of a software application. This includes both direct and indirect dependencies and thus may be many levels deep.

### Development context

Application development information and requirements in an Organization include ownership, development tools, environments, teams, workflows, and processes.

### DevOps

A set of cultural philosophies, practices, and tools that combine software development and IT operations to shorten the systems development lifecycle.

### DevSecOps

Integrate security seamlessly and transparently into emerging agile IT and DevOps development.

### Docker

A platform that allows developers to package applications and all their dependencies into standardized units called containers.

### Dockerfile

A text file format used to build container images using Docker. The Dockerfile contains all the commands needed to construct the final image, including specifying the parent base image.

## E

### Embedded agent

An AI assistant built directly into an existing software application or workflow to provide assistance in context.

### Environment

Can refer to a cloud environment, a [Project attribute](https://docs.snyk.io/manage-risk/snyk-projects/project-attributes), or an interface for working with Snyk, such as the Snyk [CLI](#cli), [Web UI](#snyk-web-ui), or an [IDE](#ide).

### Exploit

A demonstration of how a vulnerability can be taken advantage of. When an exploit is widely published, it is commonly referred to as an exploit "in the wild". See [View exploits](https://docs.snyk.io/manage-risk/prioritize-issues/view-exploits).

### Exploit Maturity

A measure of how practical an exploit for a vulnerability is, based on whether the exploit is in the wild, and how "helpful" the exploit is to attackers.

## F

### Fixable / Partially fixable

A measure of whether a vulnerability can be fixed by Sny by applying a patch, upgrade, or pin. See [Vulnerability fix types](https://docs.snyk.io/manage-risk/prioritize-issues/fix-vulnerabilities/vulnerability-fix-types).

### Fix PR

A pull request with an automatic fix for discovered vulnerabilities that Snyk can offer the user. See [Automated fix PRs](https://docs.snyk.io/manage-risk/prioritize-issues/fix-vulnerabilities/automated-fix-prs).

## G

### Git

A distributed version control system for tracking changes in source code during software development.

### Group

In Snyk, a Group is the top-level entity used to manage multiple Organizations, centralize billing, and enforce global security policies across an entire company.

### Guardrail directive

A Guardrail directive is a type of [Directive](#directive) that is automatically injected into AI agent interactions to govern AI agent behavior. For more information, visit [Guardrail directives](https://docs.snyk.io/agent-security/snyk-studio/directives#guardrail-directives).

## H

### Helm

A package manager for Kubernetes that simplifies the deployment and management of applications using reusable configuration files called charts. A Helm chart contains all the necessary resource definitions (YAML templates) and parameters required to deploy a specific application or service to a cluster.

### Hook (Snyk Studio)

Hooks are automated processes that execute skills or tools at specific points in an agent lifecycle.

## I

### IaC

Infrastructure as Code. See [Snyk Infrastructure as Code.](#snyk-infrastructure-as-code)

### IDE

Integrated Development Environment. An application that has facilities for software development, typically with a source code editor, build automation tools, and a debugger.

### Image

The stored instance of a container that holds a set of software needed to run an application.

### Image layer

Container images typically consist of several different file system layers, which are combined together at runtime into a single file system.

### Inference

The real-time process of using a trained AI model to generate an output from new input data without changing the model's parameters.

### Integrations

Third-party products, applications, and platforms that Snyk works with, for example, SCM systems such as GitHub. See [Integrate with Snyk](https://docs.snyk.io/integrate-with-snyk).

### Issue

A license problem, vulnerability, or misconfiguration identified and listed by Snyk. See [Find and manage priority issues](https://docs.snyk.io/manage-risk/prioritize-issues).

### Issue (Snyk **Essentials**)

An issue is a security problem identified by a Snyk security product when testing an asset that AppSec teams need to remediate.

### Issues prioritization (Snyk **Essentials**)

Provides a centralized view of all the issues identified by Snyk with additional asset context. This empowers AppSec teams to better triage and remediate issues in Snyk.

### Issue context (Snyk **Essentials**)

Information surrounding a particular security issue that serves as objective risk factors, such as issue severity level, availability of a fix, and exploit maturity.

## K

### Kubernetes

An open-source orchestration platform that automates the deployment, scaling, and management of containerized applications.

## L

### Library

A specific type of package.

### License policy

A set of criteria for evaluating open-source license issues. License policies enable you to set the severity level and define legal instructions for each license. See [License policies](https://docs.snyk.io/manage-risk/policies/license-policies).

### LLM

Large Language Model. A type of AI model trained on vast amounts of data to understand, generate, and reason over human language and code. It understands logic, reasoning, and grammar, but it’s based on static knowledge.

### LLM red teaming

The practice of stress-testing AI models to discover security, safety, and reliability flaws through simulated adversarial attacks. As opposed to DAST (focused on code security issues), it looks for behavior-based security issues in running AI systems.

## M

### Manifest

A file containing metadata about other files in a package.

### MCP

Model Context Protocol. An open standard that allows developers to create secure, bidirectional connections between AI-powered tools and their data sources. Visit [Agentic security with Snyk Studio](https://docs.snyk.io/agent-security/snyk-studio).

### Monitor

The `snyk monitor` command tests a Project and uploads the results to Snyk. See the CLI help for [Monitor](https://docs.snyk.io/snyk-cli/commands/monitor).

## N

### NLP

Natural Language Processing.The technology that enables computers to understand, interpret, and generate human language. It is used with chatbots, threat detection, and intelligence gathering.

### NPX

`npx` (Node Package Execute) is a command-line tool bundled with `npm` that allows you to run `Node.js` packages without requiring installation.

## O

### OAuth

An open-standard authorization protocol that allows a third-party application to access a user's data without ever seeing their login credentials.

### OCI

Open Container Initiative. An independent body set up to facilitate collaboration on standards for containers, to ensure they are interoperable between vendor solutions.

### Organization

An Organization in Snyk is a way to collect and organize your Projects. Members of Organizations have access to these Projects. See [Manage Groups and Organizations](https://docs.snyk.io/enterprise-setup/organizations-and-groups).

### Origin or source

The identifier for the ecosystem that a Target exists in. Snyk can scan Projects from multiple integrations, including CLI, API, GitHub, Kubernetes, and others. See [Snyk Projects](https://docs.snyk.io/manage-risk/snyk-projects).

## P

### Package

A group of files and additional metadata about those files, used by package managers.

### Package assets (Snyk **Essentials**)

Package assets are created when you scan the dependencies of a Project through package management systems or by using the Snyk CLI. This enables Snyk Essentials to identify and analyze the security vulnerabilities of the packages used within a Project, offering insights into possible risk exposures and providing recommendations for mitigation.

### Package manager

A set of tools that automate and manage packages of bundled files, and are usually specific to a language. For example, npm.

### Package registry

A software package hosting service that allows customers to host packages and code in one place.

### PAT

A Personal Access Token (PAT) is a unique string used as an alternative to a password to authenticate a specific user when accessing Snyk using the API or CLI.

### Pinnable

A fix type. Define and "pin" a specific version of an indirect dependency to avoid a direct dependency pulling in a vulnerable version.

### Policy

See [license policy](#license-policy), [security policy](#security-policy), and [`.snyk` policy](#snyk-policy).

### **Policy (Snyk Essentials)**

A way to automate actions in certain conditions, like classifying and tagging assets with business context. You can also use a policy to configure actions, such as sending a message or setting the coverage gap control, using a Policy builder UI.

### PR

Pull Request. Allows a user to exchange changes made to the source code and collaborate with others on the same branch.

### PR Checks

Use Snyk PR Checks to prevent new security issues from entering your codebase by automatically scanning code changes in real time as soon as you submit a pull request (PR) in your source code manager (SCM). See [Run PR Checks](https://docs.snyk.io/scan-with-snyk/pull-requests/pull-request-checks).

### Priority Score

Snyk scores issues, including vulnerabilities and licenses for Open Source, to help prioritize the treatment of each one. Scores are based on multiple factors, including the CVSS score, and range from 0 (low) to 1000 (high). See [Priority Score](https://docs.snyk.io/manage-risk/prioritize-issues/priority-score).

### Project

An external item scanned by Snyk with configuration to define how to run that scan. Projects appear on the **Projects** menu on the Snyk dashboard. See also [Target](#target). For details, see [Snyk Projects](https://docs.snyk.io/manage-risk/snyk-projects).

### Prompt

The input or set of instructions provided to an AI model that defines what task to perform, what context to use, and how it should respond.

## R

### Reachability

Whether an application contains code that will hit a vulnerable code path during execution. See [Reachable vulnerabilities](https://docs.snyk.io/manage-risk/prioritize-issues/reachability-analysis).

### Registry

See [Container registry](#container-registry) or [Package registry](#package-registry).

### Remediation directive

A Remediation directive is a type of [Command directive](#command-directive) that triggers a full, end-to-end security remediation playbook that results in a secure pull request. For more information, visit [Remediation directives](https://docs.snyk.io/agent-security/snyk-studio/directives#remediation-directives).

### Repository

A storage area that contains all elements necessary for the distribution of an application.

### Repository assets (Snyk **Essentials**)

A repository asset is created by discovering the repositories directly in the SCM when such integration is configured. Alternatively, a repository asset can be created by scanning a repository (by Snyk or third-party tools) as long as the scanned code is identified with a specific repository.

### Resource

A cloud infrastructure entity such as an AWS S3 bucket, Identity and Access Management (IAM) role, or Virtual Private Cloud (VPC) flow log.

### Risk score

A value assigned to an issue, ranging from 0 to 1,000, representing the risk imposed on your environment.

### Rule

A security policy that checks cloud infrastructure and infrastructure as code (IaC) for misconfigurations that can lead to security problems, or a security rule used by Snyk Code when scanning your source code for vulnerabilities. For more information, see [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) and [IaC custom rules](https://docs.snyk.io/scan-with-snyk/snyk-iac/custom-rules).

## S

### SARIF

Static Analysis Results Interchange Format. A standard, JSON-based format for the output of static analysis tools.

### SAST

Static Application Security Testing. A security analysis technique that examines static source code to identify potential vulnerabilities without running the application. See also [DAST](#dast), [Snyk Code](#snyk-code), and [Snyk Infrastructure as Code](#snyk-infrastructure-as-code).

### SBOM

Software Bill Of Materials. A list of components in a piece of software.

### SCA

Software Composition Analysis. A security analysis technique that is used to identify open-source and third-party components in use in an application, their known security vulnerabilities, and typically also adversarial license restrictions. Not to be confused with [Static Code Analysis](#static-code-analysis). See also [Snyk Open Source](#snyk-open-source).

### Scanned artifacts (Snyk **Essentials**)

A scanned artifact in Snyk Essentials is an entity detected by Snyk that cannot be identified as a repository asset because it does not include identifying information, such as a Git remote URL.

### SCM

Source Code Management. Also known as a code repository (repo) or version control system. The method used by developers to store their source code and track changes to code. SCM helps resolve conflicts when merging updates from multiple contributors. GitHub is an example of a common SCM system. See [Git repositories (SCMs)](https://docs.snyk.io/integrate-with-snyk/git-repository-scm-integrations).

### SCM Repository freshness (Snyk **Essentials**)

The SCM Repository freshness provides an immediate understanding of the current status of your repositories, including the date of the last commit. This assists you in quickly identifying active and dormant Projects and helps you with the decision-making regarding maintenance, security patching, and resource allocation. Reflects the status of the repository and the date of the last commit.

### SDLC

Software Development Lifecycle. A process followed by a development team, describing how to develop and maintain software.

### Secret

A secret is a piece of sensitive data (eg, API key, token, passwords, private key) which is used to grant access to protected resources, such as cloud infrastructure, third party SaaS offerings, or databases. See [Snyk Secrets](https://docs.snyk.io/scan-with-snyk/snyk-secrets).

### Secure at inception directive

A Secure at inception directive is a type of [Guardrail directive](https://docs.snyk.io/agent-security/snyk-studio/directives#guardrail-directives), used with Snyk Studio and your coding assistant. For more information, visit [Secure at inception directives](https://docs.snyk.io/agent-security/snyk-studio/directives#secure-at-inception-directives).

### Security policy

A set of criteria for evaluating open-source vulnerabilities. Security policies enable you to set custom rules to automatically prioritize or de-prioritize specific vulnerabilities. See [Security policies](https://docs.snyk.io/manage-risk/policies/security-policies).

### Service account

A non-human identity used to authenticate automated processes, such as CI/CD pipelines, to Snyk without being tied to a specific individual's credentials.

### Severity

A severity level is applied to a vulnerability or a license issue, to indicate the risk for that item in an application. See [Severity levels](https://docs.snyk.io/manage-risk/prioritize-issues/severity-levels).

### Skill (Snyk Studio)

Skills are packaged instructions (containing specialized procedures and knowledge) loaded on demand to guide agent actions. They can be triggered by [Hooks](#hook-snyk-studio).

### Snapshot

An individual report within the test history of a Project. Includes a tree of dependencies and a list of vulnerabilities that were accurate at the time the test was conducted.

### `.snyk` policy

A policy file that Snyk uses to define certain analysis behaviors and to specify patches for the CLI and CI/CD plugins. See [The .snyk file](https://docs.snyk.io/manage-risk/policies/the-.snyk-file).

### Snyk

A platform providing Cloud Native Application Security (CNAS) solutions, allowing developers to own and build security for the whole application, from code and open source to containers and cloud infrastructure. Snyk is also the company providing the Snyk platform. See [Getting started](https://docs.snyk.io/getting-started).

### Snyk Advisor

A free web application that allows you to compare software packages across open-source ecosystems. It provides insights into the overall health of a particular package by combining community and security data into a single unified view. See [Snyk Advisor](https://snyk.io/advisor/).

### Snyk API

A Snyk tool that enables developers to integrate programmatically with Snyk. See [Snyk API](https://docs.snyk.io/snyk-api).

### Snyk Apps

Snyk Apps are the modern and preferred way to build integrations with Snyk, exposing fine-grained scopes for accessing resources over the Snyk APIs, powered by OAuth 2.0 for a developer-friendly experience. See [Snyk Apps](https://docs.snyk.io/snyk-api/snyk-apps).

### Snyk Broker

A client/server system that serves as an agent or proxy, allowing Snyk to scan private customer environments: Jira, code repositories, or container registries. Snyk Broker relays messages and allows users to filter which messages are allowed through, for example, allowing users to expose only some GitHub APIs to Snyk. See [Snyk Broker](https://docs.snyk.io/enterprise-setup/snyk-broker).

### Snyk CLI

A Snyk platform tool that enables developers to find and fix known vulnerabilities in dependencies, using a command line interface. See [Snyk CLI](https://docs.snyk.io/snyk-cli).

### Snyk Code

A Snyk product. A SAST product enabling developers to find and fix vulnerabilities in your proprietary application code. See [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code).

### Snyk Container

A Snyk product. Enables developers to find and fix vulnerabilities in container images and Kubernetes applications. See [Snyk Container](https://docs.snyk.io/scan-with-snyk/snyk-container).

### Snyk Infrastructure as Code

A Snyk product. Enables developers to find and fix vulnerabilities in Kubernetes, Helm, and Terraform configuration files. See [Snyk IaC](https://docs.snyk.io/scan-with-snyk/snyk-iac).

### Snyk Learn

An interactive education platform that provides developers with bite-sized lessons and structured learning paths to master secure coding and product best practices.

### Snyk MCP Server

An MCP server that enables easy integration with coding assistants, providing security context to AI agents. This runs locally using the Snyk CLI. For more information, visit [Agentic security with Snyk Studio](https://docs.snyk.io/agent-security/snyk-studio).

### Snyk Open Source

A Snyk product. Enables developers to find and fix open-source vulnerabilities. See [Snyk Open Source](https://docs.snyk.io/scan-with-snyk/snyk-open-source).

### Snyk plugin

A library used by the Snyk CLI to scan a certain language or build system.

### Snyk Secrets

A Snyk product. Enables developers to find hardcoded credentials in repositories by providing accurate scanning across plain text files. See [Snyk Secrets](https://docs.snyk.io/scan-with-snyk/snyk-secrets).

### Snyk Studio

Snyk Studio embeds Snyk's AI security platform capabilities into any AI-native workflow. Snyk Studio is built on two core use cases: '[Secure at Inception](#secure-at-inception),' which proactively prevents new, AI-generated vulnerabilities using configurable directives, and 'Intelligent Remediation,' which clears existing security backlogs at scale.

### Snyk Security Intelligence

A component powering the Snyk cloud-native application security platform.\
Incorporates the Snyk Intel Vulnerability DB: the Snyk database of vulnerabilities, providing detailed information and fix advice for known vulnerabilities. See [Vulnerability DB](https://snyk.io/vuln).

### Snyk web UI

The browser-based environment that provides users access to Snyk functions.

### Social Trends

Snyk shows a Trending banner on issues that are being actively discussed on X (formerly known as Twitter). See [Vulnerabilities with Social Trends](https://docs.snyk.io/manage-risk/prioritize-issues/vulnerabilities-with-social-trends).

### Source

See [Origin](#origin-or-source).

### SPDX

Software Package Data Exchange. A file format used to document information on the software licenses under which a piece of computer software is distributed. See [SPDX](https://spdx.dev/).

### SSO

An authentication method that allows users to access multiple, independent software systems or applications using a single set of login credentials.

### Static Code Analysis

A technique for examining source code to identify issues related to code quality, structure, or performance, such as determining code reachability or spotting potential inefficiencies. While this technique may address security concerns, its primary focus is often broader, covering various aspects of code health. In contrast, Static Application Security Testing ([SAST](#sast)) specifically targets the identification of security vulnerabilities within the code, such as coding flaws that could lead to security risks.

## T

### Target

Representation of an external resource Snyk has scanned. All [Snyk Projects](#project) are associated with a parent Target. One Target may relate to many Projects. The structure of the Target depends on the [origin](#origin-or-source).

### **Tags (Snyk Essentials)**

A way to categorize assets. Helps you recognize or handle assets differently according to mutual properties. Assets can be filtered by their tags in the inventory or when creating policy rules. A tag can be automatically assigned to an asset, or the asset can be tagged by a policy you created. GitHub and GitLab topics are treated as asset tags, and you can use them for creating policies.

### Tenant

The top level of the Snyk hierarchy. It encompasses all your Groups and Organizations and all their corresponding Snyk work items. For more information, see [Tenants, Groups, and Organizations](https://docs.snyk.io/enterprise-setup/organizations-and-groups).

## U

### Upgradable / Patchable

A fix type: a problem can be fixed by upgrading a version of a package or by applying a patch.

## V

### Vector DB

Vector database. A database that stores information as numerical representations, and it enables users to retrieve the most semantically relevant information instead of keyword matches.

### Vulnerability

A security vulnerability that was identified by Snyk. See [Manage vulnerabilities](https://docs.snyk.io/manage-risk/prioritize-issues).

## W

### Webhook

A way for an app to provide other applications with real-time information. Snyk uses webhooks to check changes in code. See [Snyk Webhooks](https://docs.snyk.io/integrate-with-snyk/snyk-webhooks).

### Web UI

See [Snyk Web UI](#snyk-web-ui).

### Workspaces (SCM integrations)

A Snyk feature. This enables Snyk to ingest shallow copies of your Git repositories for scanning, resulting in precise and reliable vulnerability scans.

See [Workspaces for SCM integrations](https://docs.snyk.io/integrate-with-snyk/git-repository-scm-integrations/workspaces-for-scm-integrations).


# Snyk release process

How Snyk releases features through stages from alpha to general availability, and what each stage means for access and documentation.

{% hint style="info" %}
Not all features follow all these stages, and timelines for each feature vary.
{% endhint %}

## Feature release stages

Snyk features are provided to users in the following release stages.

<table><thead><tr><th width="130.39453125">Stage</th><th width="195.8680419921875">Description</th><th>Available to</th><th>Access</th><th>Docs</th></tr></thead><tbody><tr><td>Alpha</td><td>Internal release only</td><td>Snyk internal users, potentially some design partners</td><td>Controlled</td><td>No documentation provided</td></tr><tr><td>Closed Beta</td><td>The first customer-facing rollout of a feature</td><td>A preselected group of users</td><td>Invitation only</td><td>Provided but not public</td></tr><tr><td>Early Access</td><td>Feature is tested and ready for use, but not available by default. See <a href="#early-access-features">Early Access features</a></td><td>All users on an opt-in basis. This may include some additional purchase costs</td><td>Opt-in: on request through Snyk account team, or using Snyk Preview</td><td>Public documentation</td></tr><tr><td>General Availability</td><td>Feature is fully enabled</td><td>All users, subject to standard feature availability</td><td>Available by default</td><td>Public documentation</td></tr></tbody></table>

## Feature lifecycle stages

<table><thead><tr><th width="130.26171875">Stage</th><th>Description</th><th width="131.5997314453125">Available to</th><th>Access</th><th>Docs</th></tr></thead><tbody><tr><td>Deprecated</td><td>The feature is available, but use is discouraged. See <a href="#deprecated-features">Deprecated features</a></td><td>Active users only</td><td>Available by default</td><td>Public documentation, with the Release status at the top of the page</td></tr><tr><td>End of support</td><td>No new support tickets will be answered. See <a href="#end-of-support-features">End of support features</a></td><td>Active users only</td><td>Available by default</td><td>Public documentation, with the Release status at the top of the page</td></tr><tr><td>End of Life</td><td>The feature is no longer available</td><td>No users</td><td>Not available</td><td>No documentation available</td></tr></tbody></table>

## Brownouts

Brownouts occur when Snyk temporarily suspends an API endpoint or a feature, making it unavailable for use. This situation indicates that the resource or service is still operational, but its performance is reduced compared to its normal or expected capacity.

## Features status

### Early Access features

* [Snyk GitHub Cloud App](/developer-tools/integrations/scm-integrations/organization-level-integrations/github-cloud-app)
* [Automatically created Project collections](/scan-fix-and-prevent/scan-with-snyk/snyk-projects/automatically-created-project-collections)
* [Fix code vulnerabilities automatically](/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically)
* Risk Management
  * [Risk Score](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/risk-score)
  * [Reachability analysis](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/reachability-analysis)
  * [Breakability risk levels](/scan-fix-and-prevent/fix/snyk-pull-or-merge-requests/breakability-risk-levels)
* Universal Broker
* Language support
  * [Snyk CLI pnpm support](/supported-languages/supported-languages-list/javascript#support-for-pnpm)
  * [Improved Gradle SCM scanning](/supported-languages/supported-languages-list/java-and-kotlin/git-repositories-with-maven-and-gradle#improved-gradle-scm-scanning)
  * [CLI support for uv](/supported-languages/supported-languages-list/python/support-for-uv)
  * SCM integration for uv
* Reports
  * [Repositories tested in CI/CD report](/scan-fix-and-prevent/prevent/analytics/reports-tab/prevention-reports#repositories-tested-in-ci-cd-report)
* [Snyk 2.0 platform improvements](/snyk-2.0-platform-improvements)

### Deprecated features

Deprecated features are outdated and will be removed in the future. The documentation page will announce the transition of a feature to Deprecated six months before its start date.

* Snyk Code Quality is deprecated.
* Snyk Code Local Engine is deprecated.
* Apps API has the following deprecated endpoints:
  * **Revoke app bot authorization** endpoint
    * The [Revoke app bot authorization](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-revoke-app-bot-authorization) endpoint is deprecated.
    * Use the [Revoke app authorization for a Snyk Group with install ID](/developer-tools/snyk-api/api-endpoints-index-and-tips#revoke-app-authorization-for-a-snyk-group-with-install-id) endpoint.
  * **Create a new app for an organization** endpoint
    * The [Create a new app for an organization](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-create-a-new-app-for-an-organization) endpoint is deprecated.
    * Use the [Create a new Snyk App for an organization](/developer-tools/snyk-api/api-endpoints-index-and-tips#create-a-new-snyk-app-for-an-organization) endpoint.
  * **Get a list of apps created by an organization** endpoint
    * The [Get a list of apps created by an organization](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-get-a-list-of-apps-created-by-an-organization) endpoint is deprecated.
    * Use the new [Get a list of apps created by an organization](/developer-tools/snyk-api/api-endpoints-index-and-tips#get-a-list-of-apps-created-by-an-organization) endpoint.
  * **Update app attributes that are name, redirect URIs, and access token time to live** endpoint
    * The [Update app attributes that are name, redirect URIs, and access token time to live](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-update-app-attributes-that-are-name-redirect-uris-and-access-token-time-to-live) endpoint is deprecated.
    * Use the [Update app creation attributes such as name, redirect URIs, and access token time to live using the App ID](/developer-tools/snyk-api/api-endpoints-index-and-tips#update-app-creation-attributes-such-as-name-redirect-uris-and-access-token-time-to-live-using-the-ap) endpoint.
  * **Get an app by client id** endpoint
    * The [Get an app by client id](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-get-an-app-by-client-id) endpoint is deprecated.
    * Use the [Get a Snyk App by its App ID](/developer-tools/snyk-api/api-endpoints-index-and-tips#get-a-snyk-app-by-its-app-id) endpoint.
  * **Delete an app** endpoint
    * The [Delete an app](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-delete-an-app) endpoint is deprecated.
    * Use the [Delete a Snyk App by its App ID](/developer-tools/snyk-api/api-endpoints-index-and-tips#delete-an-app-by-its-app-id) endpoint.
  * **Manage client secrets for an app** endpoint
    * The [Manage client secrets for an app](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-manage-client-secrets-for-an-app) endpoint is deprecated.
    * Use the [Manage client secret for non-interactive Snyk App installations](/developer-tools/snyk-api/api-endpoints-index-and-tips#manage-client-secret-for-non-interactive-snyk-app-installations) endpoint.
  * **Get a list of app bots authorized to an organization** endpoint
    * The [Get a list of app bots authorized to an organization](/developer-tools/snyk-api/api-endpoints-index-and-tips#deprecated-get-a-list-of-app-bots-authorized-to-an-organization) endpoint is deprecated.
    * Use the [Get a list of apps installed for an organization](/developer-tools/snyk-api/api-endpoints-index-and-tips#get-a-list-of-apps-installed-for-an-organization) endpoint.
  * [Integration with Google Container Registry (GCR)](/scan-fix-and-prevent/scan-with-snyk/snyk-container/container-registry-integrations/integrate-with-google-container-registry-gcr) is deprecated.

### End of support features

When a feature transitions to end-of-support, both development and support work are terminated.

The documentation page will announce the transition of a feature to End of Support six months before its start date.

### End of Life features

A feature can also be the subject of an end-of-life event, meaning that the feature or capability impacted by this process ceases to exist and is removed from the product and public documentation.

API endpoints have a dedicated section for the end-of-life process and also provide details about the migration steps. Navigate to the [API End of Life process and migration guides](/developer-tools/snyk-api/api-end-of-life-eol-process-and-migration-guides) for more details.


# What's new?

Recent updates to Snyk products and documentation, including new features, changes, and knowledge base improvements

The most recent updates include significant changes to the user docs, such as features added or removed, structural changes that affect how you find relevant information, and other improvements to enhance your interaction with the Snyk knowledge base.

## July 2026

### Evo by Snyk

* Evo by Snyk is now public. Visit [Overview of Evo by Snyk](https://docs.snyk.io/agent-security/evo-by-snyk/overview) for more details.
* Agentic Development Security (ADS) is now GA, including Agent Behavior Governance, AI-SPM, and platform surfaces such as Evo Chat and Inventory. Visit [Agent Behavior Governance](https://docs.snyk.io/agent-security/evo-by-snyk/agentic-development-security-ads/agent-behavior-governance) for more details.

### Snyk Code

* OWASP and CWE mappings expanded, and the Snyk Code security rule pages now map each rule to the OWASP Top 10 2025, OWASP API Top 10 (2023), and OWASP Mobile Top 10 (2024), and note CWE Top 25 (MITRE) inclusion. Visit [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) for more details.
* Rule Extensions is now GA, and impact testing is available in the Snyk Web UI, in addition to the API. Visit [Rule Extensions](https://docs.snyk.io/scan-with-snyk/snyk-code/rule-extensions) for more details.

### Snyk Secrets

* Snyk Secrets is now GA, with documentation across the Snyk CLI, SCM integrations, and the VS Code, Visual Studio, Eclipse, and JetBrains IDE plugins. Visit [Secrets scanning in the SCM](https://docs.snyk.io/developer-tools/integrations/scm-integrations/secrets-scanning-in-the-scm) for more details.
* The `snyk secrets test` command is now available for scanning secrets from the command line. Visit [Secrets scanning in the Snyk CLI](https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/secrets-scanning-in-the-snyk-cli) for more details.

### Snyk API & Web

* Bruno collections are now GA. You can now create an API target from a Bruno collection and configure its authentication. Visit [Configure an API target with a Bruno collection](https://docs.snyk.io/scan-with-snyk/snyk-api-web/configure-targets/configure-authentication/configure-an-api-target-with-a-bruno-collection) for more details.
* Automated target authentication configuration is now documented on a dedicated page. Visit [Automate authentication configuration](https://docs.snyk.io/scan-with-snyk/snyk-api-web/configure-targets/configure-authentication/automate-authentication-configuration) for more details.

### Other updates

* Unified IDE configuration is now GA across the Snyk IDE plugins. Visit [Unified IDE configuration dialog](https://docs.snyk.io/developer-tools/integrations/snyk-ide-plugins-and-extensions/unified-ide-configuration-dialog) for more details.
* Snyk Container now reports vulnerabilities in the Go standard library, identified from the Go version recorded in the binary. Visit [Application vulnerabilities in Snyk Container and Snyk Open Source](https://docs.snyk.io/scan-with-snyk/snyk-container/how-snyk-container-works/application-vulnerabilities-in-snyk-container-and-snyk-open-source) for more details.
* Notification emails for new vulnerabilities are now off by default, and a new section documents notification precedence rules. Visit [Manage notifications](https://docs.snyk.io/platform-administration/snyk-platform-administration/manage-notifications) for more details.
* Snowflake Data Share added two fields to the prevention events dataset, `finding_branch_key` and `finding_asset_key`. Visit [Data share data dictionary](https://docs.snyk.io/manage-risk/analytics/reports-tab/reporting-and-bi-integrations-snowflake-data-share/data-share-data-dictionary) for more details.

## June 2026

### Snyk CLI

* Project tags can now be set from the command line: the `snyk code test` command documents the new `--project-tags=<TAG>[,<TAG>...]` option, used with `--report` to apply comma-separated `key=value` tags (set `--project-tags=` to clear them). Visit [snyk code test](https://docs.snyk.io/developer-tools/snyk-cli/commands/code-test) for more details.
* AI-BOM language support has expanded: the `snyk aibom` command now generates a CycloneDX v1.6 AI-BOM for Projects written in Python, Java, JavaScript, or Go, up from Python only. Visit [snyk aibom](https://docs.snyk.io/developer-tools/snyk-cli/commands/aibom) for more details.
* Upgrading is now documented on a dedicated page: the Snyk CLI docs add an "Upgrade the Snyk CLI" page covering how to update existing installations. Visit [Upgrade the Snyk CLI](https://docs.snyk.io/developer-tools/snyk-cli/upgrade-the-snyk-cli) for more details.
* Standalone installation instructions were improved to clarify how to download and install the CLI binary directly. Visit [Install or update the Snyk CLI](https://docs.snyk.io/developer-tools/snyk-cli/install-or-update-the-snyk-cli) for more details.

### Snyk Container

* Alpine 3.24 is now listed among the operating system distributions supported by Snyk Container. Visit [Operating system distributions supported by Snyk Container](https://docs.snyk.io/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) for more details.
* OpenJDK coverage improved: the "How Snyk Container works" documentation removes the previous openjdk8 limitation. Visit [How Snyk Container works](https://docs.snyk.io/scan-with-snyk/snyk-container/how-snyk-container-works) for more details.

### Snyk Open Source

* uv support was added: Snyk documents source-control-management (SCM) support for the Python uv package manager, available in Early Access. Visit [Snyk for Python](https://docs.snyk.io/supported-languages/supported-languages-list/python).
* Go private dependencies are now documented: the Go language page adds setup guidance for scanning Projects that use private modules. Visit [Snyk for Go](https://docs.snyk.io/supported-languages/supported-languages-list/go) for more details.
* Package repository integrations expanded for Go: Snyk adds new setup pages for the Nexus and Artifactory repository managers with Go. Visit [Package repository integrations](https://docs.snyk.io/scan-with-snyk/snyk-open-source/package-repository-integrations) for more details.

### Snyk API & Web

* Snyk API & Web (DAST) documentation is now live at docs.snyk.io, featuring a new overview that describes the product for dynamic application and API security testing. Visit [Overview of Snyk API & Web](https://docs.snyk.io/scan-with-snyk/snyk-api-web/overview-snyk-api-web).
* Getting-started content was published for the product, including setup pages for adding users and enabling two-factor authentication. Visit [Snyk API & Web](https://docs.snyk.io/scan-with-snyk/snyk-api-web/overview-snyk-api-web) for more details.

### Other updates

* Plan and billing information is now documented in a new tenant administration page that describes plan details and billing. Visit [Plan and billing](https://docs.snyk.io/platform-administration/snyk-hierarchy/tenant/plan-and-billing) for more details.
* SSO custom mapping assertions documentation was updated for single sign-on configuration. Visit [Custom mapping](https://docs.snyk.io/platform-administration/implementation-and-setup/enterprise-setup/single-sign-on-sso-for-authentication-to-snyk/custom-mapping) for more details.
* Export API added a prevention events dataset, with new columns and filters documented for exporting prevention data. Visit [Export API specifications, columns, and filters](https://docs.snyk.io/developer-tools/snyk-api/using-specific-snyk-apis/export-api-specifications-columns-and-filters) for more details.
* Snowflake data share added prevention events to the data-share data dictionary. Visit [Data share data dictionary](https://docs.snyk.io/manage-risk/analytics/reports-tab/reporting-and-bi-integrations-snowflake-data-share/data-share-data-dictionary) for more details.
* Prevention reports documentation was published in Early Access under the Analytics Reports tab. Visit [Prevention reports](https://docs.snyk.io/manage-risk/analytics/reports-tab/prevention-reports) for more details.
* Agent Fix guidance was updated on the page for fixing code vulnerabilities automatically. Visit [Fix code vulnerabilities automatically](https://docs.snyk.io/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically) for more details.
* Repo Content Sync documentation was updated for Project repositories. Visit [Snyk Repo Content Sync](https://docs.snyk.io/scan-with-snyk/project-repositories/snyk-repo-content-sync) for more details.
* Bitbucket for Snyk Essentials group-level integration documentation was updated. Visit [Bitbucket for Snyk Essentials](https://docs.snyk.io/developer-tools/scm-integrations/group-level-integrations/bitbucket-for-snyk-essentials) for more details.
* Snyk Agent Red Teaming references were removed across the docs as the feature was retired.

## May 2026

### Snyk Analytics

* The [Pull request checks usage and performance report](https://docs.snyk.io/manage-risk/analytics/reports-tab/prevention-reports#pull-request-checks-usage-and-performance-report) is now in GA for all plans, and PR check data is now available through the [Export API](https://docs.snyk.io/snyk-api/reference/export).
* The [Zero-Day report](https://docs.snyk.io/manage-risk/analytics/reports-tab/remediation-reports#zero-day-report) now documents the Active security incident assessment banner, which surfaces assets needing triage, assets cleared, and the affected open source packages during a high-severity zero-day event.

### Snyk CLI

* The latest Snyk CLI version is [v1.1304.0](https://github.com/snyk/cli/releases/tag/v1.1304.0).
* Added a new page for [CLI support for uv](https://docs.snyk.io/supported-languages/supported-languages-list/python/cli-support-for-uv), documenting Early Access support for the uv Python package manager across snyk test, snyk monitor, and snyk sbom, and extending coverage to Snyk IDE extensions, the Snyk MCP server, and Snyk GitHub Actions.
* The [snyk sbom](https://docs.snyk.io/developer-tools/snyk-cli/commands/sbom) command page now documents the --allow-incomplete-sbom flag, which generates an SBOM even when individual Projects fail to resolve.
* The [environment variables page](https://docs.snyk.io/developer-tools/snyk-cli/configure-the-snyk-cli/environment-variables-for-snyk-cli) has been updated to include SNYK\_REQUEST\_CONCURRENCY, which controls parallel dependency requests in [container monitor](https://docs.snyk.io/developer-tools/snyk-cli/commands/container-monitor).

### Evo by Snyk

* The [aibom test](https://docs.snyk.io/developer-tools/snyk-cli/commands/aibom-test) command now validates a generated AI-BOM against your tenant's Evo policies in a single step.
* redteam now documents the new exhaustive and eager scan modes, improved JSON output, and the vulnerability summary that appears in Snyk Agent Red Teaming results.

#### Other updates

* The [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) section has been updated with new coverage for .NET: TLS protocol misconfiguration ([CWE-326](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules)) across common .NET HTTP and network stacks, and broader insecure cipher detection ([CWE-327](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules)) for C# and VB, including third-party support through BouncyCastle.
* [Snyk Container](https://docs.snyk.io/scan-with-snyk/snyk-container) now supports extended Java runtime binary scanning in container test and container monitor.
* Added documentation for automatic closure of obsolete Fix PRs, now in Early Access through Snyk Preview. Snyk closes Fix PRs when the targeted vulnerabilities are no longer present in your Project, whether resolved by a manual fix, a removed dependency, or a transitive update. Snyk closes up to five PRs per Project each day. See [Snyk pull or merge requests](https://docs.snyk.io/scan-with-snyk/pull-requests/snyk-pull-or-merge-requests).
* The [snyk\_package\_health\_check](https://docs.snyk.io/integrations/snyk-studio-agentic-integrations/getting-started-with-snyk-studio#configure-the-snyk-mcp-profile) directive is now in General Availability and is enabled by default in the Full MCP profile. The docs now reflect supported ecosystems: npm, PyPI, Maven, NuGet, and Go.
* Snyk API & Web documentation now covers native GraphQL scanning, including schema ingestion through a URL, file upload, or introspection endpoint, and new GraphQL-specific authentication options.
* Snyk API & Web compliance reporting now supports the OWASP Top 10:2025 standard, in addition to OWASP Top 10:2021.

## April 2026

### Snyk CLI

* The [Install the Snyk CLI](/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli) page and sub-pages have been updated to reflect configuration best practice, including easily copied code snippets.
* The [Authenticate to use the Snyk CLI](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli) page has been updated to reflect best practice, including easily copied code snippets.

### Snyk supported languages

* [CLI support for uv](/supported-languages/supported-languages-list/python/support-for-uv) is now in Early Access.
* Snyk now supports [interfile analysis for Ruby](/supported-languages/supported-languages-list/ruby#ruby-for-snyk-code).

### Other updates

* The `snyk_package_health_check` directive is now available for the Full profile on the [Directives](/agent-security/agentic-security-with-snyk-studio/directives#secure-at-inception-package-health-check-experimental) page.
* CISA KEV has been added to the list of filters available in [Issue vulnerability details](/scan-fix-and-prevent/prevent/analytics/reports-tab/issue-columns-dictionary#issue-vulnerability-details).
* The [PR Checks Report](/scan-fix-and-prevent/prevent/analytics/reports-tab/prevention-reports#pull-request-checks-usage-and-performance-report) is now General Available, with updates to Prevention Reports, Export API, and Snowflake Data Share.
* The [Pull Request experience](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience#pull-request-experience-feature-requirements) documentation has been updated to reflect that if you are using inline comments or Agent Fix, you must now specify a dedicated GitHub account by providing a GitHub Personal Access Token (PAT) in your integration settings.
* The [Enterprise implementation guide](/implementation-guides/enterprise-implementation-guide) now has embedded video tutorials to guide you in your Enterprise setup as a new user of Snyk.
* The [High availability mode](/platform-administration/snyk-broker/high-availability-mode) from Snyk Broker is now enabled by default.
* The [Container registry sync](/scan-fix-and-prevent/scan-with-snyk/snyk-container/use-snyk-container/sync-your-container-registry) from Snyk Container is now Generally Available.
* The [Container registry import policy](/developer-tools/snyk-api/reference/containerregistryimportpolicy) API was enhanced by refactoring schema names, adding test components, and full CRUD operations.

## March 2026

### Evo by Snyk

* Added the [`aibom test`](/developer-tools/snyk-cli/snyk-cli/commands/aibom-test) command under [Snyk CLI Help](/developer-tools/snyk-cli/snyk-cli/commands#snyk-aibom-test).
* Updated `redteam` with additional options, and also added Snyk Agent Red Teaming.

### Snyk Analytics

* The [Analytics Overview](/scan-fix-and-prevent/prevent/analytics/overview-tab) tab now includes the **Projects Monitored** widget.
* The [Snyk Pull request checks usage & performance report](/scan-fix-and-prevent/prevent/analytics/reports-tab/prevention-reports#pull-request-checks-usage-and-performance-report) is now in **General Availability** for Enterprise plan users.
* Added the **Assessing active security incidents** option to the [Zero-Day report](/scan-fix-and-prevent/prevent/analytics/reports-tab/remediation-reports#zero-day-report).

### Snyk CLI

* The latest Snyk CLI version is [1.1303.2](https://github.com/snyk/cli/releases/tag/v1.1303.2).
* The [environment variables page](/developer-tools/snyk-cli/snyk-cli/configure-the-snyk-cli/environment-variables-for-snyk-cli#configure-max-network-attempts) has been updated to include `SNYK_MAX_ATTEMPTS` .

### Other updates

* The [Open Source license compliance](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/open-source-license-compliance#license-updates) page has been updated to clarify that the Snyk database of supported licenses is regularly updated to match new releases of the SPDX License List.
* The `package-health-check` directive [sample script links](/agent-security/agentic-security-with-snyk-studio/directives#secure-at-inception-package-health-check-experimental) now point to the improved recipes repository in GitHub. Use the [skills](https://github.com/snyk/studio-recipes/tree/main/command_directives/synchronous_remediation/skills/secure-dependency-health-check) script or the [hook](https://github.com/snyk/studio-recipes/tree/main/guardrail_directives/package_enforcement/cursor/hooks) script.
* For Snyk Container, the [Configure repository monitoring](/scan-fix-and-prevent/fix/configure-repository-monitoring) feature is now in Early Access.
* [Snyk 2.0](/snyk-2.0-platform-improvements) introduces UI enhancements to the platform navigation and is available in Early Access. This is being rolled out gradually, so not all users see the new navigation at the same time. If you are an existing user, you can switch between the new and classic navigation at any time using the toggle in your user profile menu. What is different:
  * **Global scope selector:** the top bar serves as the primary tool to navigate between different levels of your account. Use the scope selector to switch between Tenant, Groups, and Organizations. When you select a scope, the side menu automatically displays the relevant tools and data for that area.
  * **Analytics** becomes the centralized location for all reporting, including overview reports, dependencies, and license information.
  * **Settings** becomes the unified area for managing members, billing, integrations, and account preferences. When you use the scope selector to switch between Groups and Organizations, all relevant settings for that area are displayed under **Settings**.
  * **The Organization Dashboard** has been replaced by the scope selector and the **Analytics** overview page (accessible only to Tenant users, at Tenant-level).
* The [License Policies](/scan-fix-and-prevent/prevent/policies/license-policies) page has been updated to reflect that newly supported licenses now have a default **Severity** of **None** and only appear in results if you explicitly configure this behavior.
* The [Enterprise implementation guide](/implementation-guides/enterprise-implementation-guide) has been updated to reflect the actual journey you would take as a new user onboarding with Snyk on the Enterprise plan. This includes adding guidance on how to create your Organization Template, configure all available features, and includes key decision callouts to help guide you when making essential decisions in this process.

## February 2026

### Snyk CLI

* [Container SBOM](/developer-tools/snyk-cli/snyk-cli/commands/container-sbom) has been updated with additional options.
* The Snyk CLI latest release version is [v1.1303.0](https://github.com/snyk/cli/releases/tag/v1.1303.1).

### Snyk Open Source

* [Breakability risk levels](/scan-fix-and-prevent/fix/snyk-pull-or-merge-requests/breakability-risk-levels) is now in Early Access.
* Improved .NET scanning is now a General Availability feature. The [.NET (C# and VB.NET](/supported-languages/supported-languages-list/.net) section has been updated to reflect this change.

### Snyk supported languages

* [Python](/supported-languages/supported-languages-list/python) has been updated to include support for Python version 3.12 for Snyk Code.
* Snyk Code now supports C# 14 and .NET 10, Kotlin and Java (including Spring WebFlux and JAX-RS), JavaScript and TypeScript (including Sequelize), Go (including Fiber), and Swift (including grpc-swift).
* Ruby 4.0 is supported in Snyk Code, starting with core parser improvements and stronger handling of Ruby modules.

### Snyk Studio

* A [`snyk_package_health_check` directive](/agent-security/agentic-security-with-snyk-studio/directives#secure-at-inception-package-health-check-experimental) has been added to assist you in evaluating open-source packages for security vulnerabilities, maintenance health, community engagement, and popularity. Snyk has provided a secure dependency health check skill with a sample script and an enforce security scan on new packages hook with a sample script to integrate the `snyk_package_health_check` into your workflow.
* Additional guidance on [available MCP profile types](/agent-security/agentic-security-with-snyk-studio/getting-started-with-snyk-studio#configure-the-snyk-mcp-profile) and their applicable tools, with configuration instructions, has been added.

### Other updates

* Updated documentation references and rule mappings from OWASP Top 10 (2021) to the OWASP Top 10 (2025) revision. This keeps security-category labels and cross-references aligned with the OWASP taxonomy.
* [Broker Contexts](/platform-administration/snyk-broker/universal-broker/broker-context) was released for Universal Broker, including how contexts help segment and route Broker connections across environments and Organizations. This improves guidance for running multiple Broker deployments with clearer isolation.

## January 2026

### Snyk Code

* The [Snyk Code Security policies](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code#manage-ignores-at-the-group-level-through-snyk-code-security-policies) documentation has been updated to clarify that Snyk Code Security policies are different to Snyk Security Policies.
* The [Enable Snyk Agent Fix](/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically#enable-snyk-agent-fix) section has been enhanced with more details and clear configuration steps.

### Snyk CLI

* [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) command is now in Early Access.
* The latest [Snyk CLI version](/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli) available is v1.1302.1.
* The [debugging mode of the Snyk CLI](/developer-tools/snyk-cli/snyk-cli/debugging-the-snyk-cli) has been enhanced with error catalog codes and exit codes.

### Snyk IDE

* You can now use the Issue View Options in [Eclipse](/developer-tools/integrations/snyk-ide-plugins-and-extensions/eclipse-plugin/use-the-snyk-plugin-to-secure-your-eclipse-projects#issue-view-options), [JetBrains](/developer-tools/integrations/snyk-ide-plugins-and-extensions/jetbrains-plugin/configuration-for-the-snyk-jetbrains-plugin-and-ide-proxy#general-settings), and [Visual Studio Code](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-code-extension/visual-studio-code-extension-configuration-environment-variables-and-proxy#scan-configuration) to filter issues by their Code Consistent Ignores status.
* The Risk Score Threshold option has been added to the [Visual Studio Code](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-code-extension/visual-studio-code-extension-configuration-environment-variables-and-proxy#scan-configuration) extension to allow you to filter Open Source issues by their risk score.

### Snyk Studio

* The [Agentic security with Snyk Studio](/agent-security) documentation has been restructured to accurately reflect the workflow you would go through when using Snyk Studio for the first time, and using the available [Quickstart guides](/agent-security/agentic-security-with-snyk-studio/quickstart-guides).
* The [Snyk Studio Adoption](/agent-security/agentic-security-with-snyk-studio/usage-analytics) report is now available under [Redesigned analytics](/scan-fix-and-prevent/prevent/analytics/overview-tab#snyk-studio-adoption).
* The [supported tools list](/agent-security#mcp-server-supported-tools) was updated to clarify that Snyk supports `snyk_send_feedback`.

### Snyk supported languages

* [PHP](/supported-languages/supported-languages-list/php) has been updated to include support for PHP version 8.5.
* [JavaScript](/supported-languages/supported-languages-list/javascript) was updated with support for Yarn 4.
* [Ruby](/supported-languages/supported-languages-list/ruby) was updated with support for Ruby 4.
* [Python](/supported-languages/supported-languages-list/python) has been updated to remove the limitation note for Projects with downloaded dependencies.
* [Go](/supported-languages/supported-languages-list/go) has been updated to include support for the Go standard library, for Go with Open Source.
* Several supported language pages and their rules have been updated with Code analysis support in Early Access: [Rust](/supported-languages/supported-languages-list/rust), [Swift and Objective-C](/supported-languages/supported-languages-list/swift-and-objective-c), [Dart and Flutter](/supported-languages/supported-languages-list/dart-and-flutter), [Groovy](/supported-languages/supported-languages-list/groovy), [Rust rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules), [Objective-C rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/objective-c-rules), [Dart and Flutter rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/dart-and-flutter-rules), and [Groovy rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/groovy-rules).

### Other updates

* [Container monitor](/developer-tools/snyk-cli/snyk-cli/commands/container-monitor) has been updated to include a new CLI option `--prune-repeated-subdependencies` to prune depgraphs for large container scans.
* The [redesigned Snyk Analytics experience](/scan-fix-and-prevent/prevent/analytics/overview-tab) is now in General Availability.
* The [Bitbucket Cloud documentation](/developer-tools/integrations/scm-integrations/organization-level-integrations/bitbucket-cloud) has been updated to make it clear that scopeless API tokens are not supported for this integration.

## 2025

<details>

<summary>December - January 2025 Documentation updates</summary>

### December 2025

#### \*Snyk API

* The API docs navigation was enhanced with additional package-related reference pages (including `ContainerRegistryImagePolicy`).

#### Snyk Integrations

* The [Partner integrations](/developer-tools/integrations/partner-integrations) page has been updated, including additional coverage for Coding Assistants and how they can use Snyk Studio (MCP) in agentic workflows.
* [JavaScript](/supported-languages/supported-languages-list/javascript) navigation has been enhanced with better redirect and routing features.

#### Snyk Studio

* The [Snyk Studio - Agentic integrations](/agent-security) documentation has been updated to provide a clearer explanation of MCP usage and the available Snyk Studio tools.
* The [Quickstart guides for Snyk Studio](/agent-security/agentic-security-with-snyk-studio/quickstart-guides) were updated with new and refreshed setup guidance, including [Cursor](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/cursor-guide) and [Windsurf](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/windsurf-guide).

#### Other updates

* GitHub Cloud App and GitHub Server App have been added to the list of [supported SCMs for Dockerfile analysis](/scan-fix-and-prevent/scan-with-snyk/snyk-container/scan-your-dockerfile#supported-scms-for-dockerfile-analysis).
* The `snyk-scm-contributors-count` docs were updated with prerequisites and setup notes. See [snyk-scm-contributors-count](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-scm-contributors-count).
* The Declining Balance documentation from the [Snyk Declining Balance of Hours Service Description](/snyk-data-and-governance/snyk-terms-of-support-and-services-glossary/declining-balance) page was updated with service description and expiration details.
* The IaC issue-reporting walkthrough from the 'Getting started with Snyk IaC' page was updated to remove outdated screenshots and copy.
* PR template variables were updated on the [Variables list and description](/scan-fix-and-prevent/fix/snyk-pull-or-merge-requests/customize-pr-templates/variables-list-and-description) page with a new container base image `short name` values for cleaner PR titles and messages.

### November 2025

#### Snyk Container

* The list of [operated distribution systems supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) has been updated with support for Chisel.

#### Snyk CLI

* The latest [Snyk CLI version](/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli) available is v1.1301.0.
* The [CLI help](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/reachability-analysis#using-reachability-analysis-with-snyk-cli) has been updated with commands for reachability analysis.

#### Snyk IDE

* The Automated Org Selection feature uses repository context to choose an Organization. Manual configuration overrides this automated selection. If the selection fails, Snyk defaults to your preferred Organization setting. The feature is available for the [Eclipse plugin](/developer-tools/integrations/snyk-ide-plugins-and-extensions/eclipse-plugin), the [JetBrains plugin](/developer-tools/integrations/snyk-ide-plugins-and-extensions/jetbrains-plugin/configuration-for-the-snyk-jetbrains-plugin-and-ide-proxy), the [Visual Studio extension](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-extension), and the [Visual Studio Code extension](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-code-extension/visual-studio-code-extension-configuration-environment-variables-and-proxy).

#### Snyk integrations

* The Amazon Q guide for Snyk Studio now includes [updated instructions](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/amazon-q-guide#install-the-snyk-mcp-server-in-the-amazon-q-ide-extension) for configuring the Snyk MCP Server in VS Code and JetBrains.

#### Other updates

* [Reachabilty analysis](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/reachability-analysis) has been updated with instructions on how it works and how to use it in both the Snyk Web UI and the Snyk CLI and clear support for specific languages and package managers.
* The [Pre-defined roles](/platform-administration/user-management/pre-defined-roles#role-types) documentation has been updated to communicate that the Organization Admin role and associated permissions supersede any Group Member role restrictions.
* The [severity condition](/scan-fix-and-prevent/prevent/policies/security-policies/security-policies-conditions) is now available in Group-level policies. Use this feature to create more granular policies for Snyk Code and Snyk Open Source findings, for example, ignoring a finding or changing its severity.

### October 2025

#### Snyk API

* A new [API migration guide](/developer-tools/snyk-api/api-end-of-life-eol-process-and-migration-guides/guides-to-migration/v1-reporting-apis-to-export-api-migration-guide) is available to help you migrate from the v1 Reporting API to the REST Exporting API.
* The Export API has been improved with the option to [limit the link expiration](/developer-tools/snyk-api/using-specific-snyk-apis/export-api-specifications-columns-and-filters#data-retention).

#### Snyk Broker

* The [Universal Broker](/developer-tools/snyk-api/reference/universal-broker) release status has transitioned to Generally Available.
* The page [Upgrade an Organization from Classic Broker to Universal Broker](/platform-administration/snyk-broker/universal-broker/upgrade-an-organization-integration-from-classic-broker-to-universal-broker#migrating-multiple-organizations) has been updated with steps to migrate multiple Organizations at a time.

#### Snyk CLI

* Snyk CLI now supports uploading files and folders for Snyk Code scanning. The command [`code-test`](/developer-tools/snyk-cli/snyk-cli/commands/code-test) has been updated with options reflecting these capabilities.
* The latest [Snyk CLI version](/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli) available is v1.1300.2.

#### Snyk integrations

* The list of Snyk MCP quick guides now includes [Devin guide](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/devin-guide), [Factory guide](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/factory-guide), [Factory terminal guide](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/factory-terminal-ide-guide).
* The Snyk MCP Server has been rebranded as [Snyk Studio](/agent-security).
* [SCM integration support for Python](/supported-languages/supported-languages-list/python/scm-integrations-and-python) has been updated with support for Python 3.14.

#### Other updates

* The [Operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container#minimus) have been updated to include include support for Minimus, Ubuntu 25.10 - Questing Quokka, and Ubuntu 25.04 - Plucky Puffin.
* For [Ruby](/supported-languages/supported-languages-list/ruby), versions 2.3.X are no longer supported. The Ruby-specific versions have been updated to include more version patches.
* PR Check report was added as Early Access to the available reports to identify Snyk PR check locations, increase adoption, and pinpoint common failure impacts on developer workflows.
* You can now label your assets with metadata on repository assets and build artifacts, helping tag, manage security, and group items by features. An asset label differs from an asset tag, which enables key-value tags for structured metadata, allowing for granular filtering, policy creation, and improved system alignment.
* [JavaScript for open source](/supported-languages/supported-languages-list/javascript#javascript-for-snyk-open-source) has been updated to include full support for pnpm Projects.

### September 2025

#### Snyk Container

* The instructions for [installing the Snyk Controller on Amazon Elastic Kubernetes Service (Amazon AKS)](/scan-fix-and-prevent/scan-with-snyk/snyk-container/kubernetes-integration/install-the-snyk-controller/install-the-snyk-controller-on-amazon-elastic-kubernetes-service-amazon-eks#create-an-eks-node-role-for-your-node-group-and-add-the-trust-relationship-for-the-iam-role) have been updated with details for configuring trust relationships for the IAM role.
* The list of [operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) has been updated to include SUSE Linux Enterprise Server 15.7 and Rocky Linux 10.

#### Snyk integrations

* The SCM integration for Bitbucket Data Center/Server now supports the Required Builds feature for granular control over pull requests. To learn more, visit [Required Builds](/developer-tools/integrations/scm-integrations/organization-level-integrations/bitbucket-data-center-server#required-builds).
* [GitLab](/scan-fix-and-prevent/prevent/pull-request-checks/analyze-pr-checks-results#gitlab) is supported for PR check results. This feature blocks merge requests with security issues when the "Pipelines must succeed" setting is enabled.
* The Snyk MCP quick guides list has been enriched with the following guides: [Claude Code](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/claude-code-guide), [Continue](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/continue-guide), [JetBrains AI Assistant](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/jetbrains-ai-assistant), and [JetBrains Junie](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/jetbrains-junie)

#### Other updates

* For Java and Kotlin, the list of [supported Gradle versions](/supported-languages/supported-languages-list/java-and-kotlin#supported-package-managers-and-package-registries) now includes Gradle 9.
* For [Ruby](/supported-languages/supported-languages-list/ruby), an end-of-support notice has been added to say that starting Oct 1, 2025, Fix PRs are no longer supported for Projects using Ruby versions 3.1.x and lower. The table of supported Ruby versions has also been updated.
* For JavaScript, [support for pnpm Projects](/supported-languages/supported-languages-list/javascript#support-for-pnpm) has been added.
* `Raise Support Community Cases` and `View Support Community Cases` Tenant-level permissions have been added. To learn more about which Tenant roles these permissions apply to, visit Pre-defined roles, [Tenant-level permissions](/platform-administration/user-management/pre-defined-roles#tenant-level-permissions).
* The [Analytics](/scan-fix-and-prevent/prevent/analytics) menu now updates its data daily instead of hourly.
* Learn how to resolve duplicated and unenriched assets discovered outside Group and Organization-level SCM integrations.
* You can now [exclude specific values](/scan-fix-and-prevent/prevent/analytics/reports-tab#exclude-filters) when you filter your reports.

### August 2025

#### Snyk API

* The [Export API](/developer-tools/snyk-api/reference/export) has been enhanced with the project\_target\_file field.
* A new dataset for usage events has been added to the [Export API.](/developer-tools/snyk-api/reference/export)

#### Snyk CLI

* [Experimental builds](/developer-tools/snyk-cli/snyk-cli/releases-and-channels-for-the-snyk-cli#experimental-builds) information is now available for the CLI releases and channels.
* The [AI-BOM](/developer-tools/snyk-cli/snyk-cli/commands/aibom) Snyk CLI command is now available with any stable CLI release.
* A new Snyk CLI analytics page is now available, providing information about [Essential Operational Analytics](/developer-tools/snyk-cli/snyk-cli/snyk-cli-analytics#essential-operational-analytics) and [Optional Usage Analytics](/developer-tools/snyk-cli/snyk-cli/snyk-cli-analytics#optional-usage-analytics).

#### Snyk integrations

* You can now add the Snyk MCP server to [Goose CLI](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/goose-cli-guide) to secure code generated with agentic workflows through an LLM.
* You can now integrate Akamai with the Snyk API & Web to discover and scan your API. See the [API Security](/developer-tools/integrations/partner-integrations#api-security) section under the Partner integrations page for more details.
* The [Jira Cloud documentation](/developer-tools/integrations/jira-and-slack-integrations/snyk-security-in-jira-cloud-integration) has been updated for parity with the current version.

#### Other updates

* A new [Risk exposure report](/scan-fix-and-prevent/prevent/analytics/reports-tab/exposure-and-coverage-reports#risk-exposure-report) has been released, providing you with a single, consolidated view of your security risks.
* The rollout to General Availability has started for the [Pull Request Experience](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience).
* The [Operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) now include Debian 14 - Forky.
* Snyk now supports [Ruby versions](/supported-languages/supported-languages-list/ruby#technical-specifications) 3.3 \[3.3.9] and 3.4 \[3.4.5]. If the Ruby version is not specified in the Gemfile, it defaults to version 3.1.

### July 2025

#### Snyk API

* The [Export API](/developer-tools/snyk-api/reference/export) is now available as GA.
* The Assets API is now available as Early Access.

#### Snyk CLI

* MCP updates:
  * [Updated the list of supported Snyk security tools into an AI system](/agent-security#mcp-server-supported-tools).
  * Updated release status from experimental to [Early access](/snyk-release-process#early-access-features) and removed the experimental flag.
  * Added [Cursor](/agent-security/agentic-security-with-snyk-studio/quickstart-guides/cursor-guide) as a new supported agentic IDE for MCP.
* PAT updates:
  * Added PAT support for [Snyk CLI](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli).
  * Added PAT support for Snyk CI/CD integrations ([CircleCI](/developer-tools/integrations/snyk-ci-cd-integrations/circleci-integration-using-a-snyk-orb), [Jenkins](/developer-tools/integrations/snyk-ci-cd-integrations/jenkins-plugin-integration-with-snyk), [Maven](/developer-tools/integrations/snyk-ci-cd-integrations/maven-plugin-integration-with-snyk)).

#### Snyk Code

* Support for Python, JavaScript, and Typescript now includes more frameworks.

#### Snyk Container

[Operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) have been updated to include: SUSE Linux Enterprise (SLE) 15.3+, Red Hat Enterprise Linux 10, and Oracle Linux 10.

#### Snyk IDE

* Added PAT support for all [Snyk IDE](/developer-tools/integrations/snyk-ide-plugins-and-extensions) plugins and extensions.
* Added an [IDE Plugin Compatibility Matrix](/developer-tools/integrations/snyk-ide-plugins-and-extensions/compatibility-matrix) for all supported versions.

#### Snyk integrations

* [Snyk Agent Fix in the PR](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience#snyk-agent-fix-in-the-pr) has added support for Bitbucket integrations, still in Early Access.
* The [minimum version](/scan-fix-and-prevent/prevent/pull-request-checks/configure-pull-request-checks) of Bitbucket Server and Bitbucket Data Center required to use the integrations with PR checks has been updated to 7.4 and 8 respectively.

#### Snyk Open Source

[Scan open-source libraries and licenses](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses), [Snyk License Compliance Management](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/snyk-license-compliance-management), and [Fix your vulnerabilities](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/manage-vulnerabilities/fix-your-vulnerabilities) have been updated with the new **Issues** tab layout.

#### Other updates

* A new architecture for user documentation on developer tools is now available. This update groups the main developer tools into a single section and distinctly separates them from the integrations documentation.
* [Analytics](/scan-fix-and-prevent/prevent/analytics/overview-tab) has a fresh new look.
* Added [Snyk Assist](/developer-education-with-snyk-learn/snyk-learn/snyk-assist) documentation.
* The [Developer IDE and CLI usage report](/scan-fix-and-prevent/prevent/analytics/reports-tab/prevention-reports#developer-ide-and-cli-usage-report) has been improved with MCP-related data to provide better visibility into MCP usage.
* [Okta custom mapping documentation](/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk/custom-mapping/examples-setting-up-custom-mapping-for-idps/example-setting-up-custom-mapping-for-okta#construct-a-value-expression-that-creates-a-roles-array-to-be-sent-to-snyk) has been updated to clarify handling of the `Arrays.flatten(appuser.snyk_orgs)` value during setup.

### June 2025

#### Snyk Broker

* Updated the Snyk Broker documentation to include distinct steps for setting up the [Container Registry Agent with Docker](/platform-administration/snyk-broker/snyk-broker-container-registry-agent#configuring-and-running-the-container-registry-agent), whether using the Classic or Universal Broker.
* Updated the [Using the API to set up Universal Broker](/platform-administration/snyk-broker/universal-broker/using-the-api-to-set-up-universal-broker) documentation with a Prerequisites section and clarified that the Snyk Broker App ID differs for each [region](/snyk-data-and-governance/regional-hosting-and-data-residency#broker-client-urls).
* Snyk Learn courses have been integrated into the [Universal Broker](/platform-administration/snyk-broker/universal-broker) pages.

#### Other updates

* [Usage settings](/platform-administration/snyk-hierarchy/usage-settings) have been updated with the new **Billing and Usage** dashboard, available with the new Snyk Platform Access plan.
* [Snyk Platform Access credits](/snyk-data-and-governance/snyk-platform-access-credits) have been added with brief information on the new Snyk Platform Access plan.
* The troubleshooting sections for all [Snyk IDE plugins](/developer-tools/integrations/snyk-ide-plugins-and-extensions) have been updated to include clear steps for working with the Logs details, which are available across all plugins.
* A new feature, the [Snyk Agent Fix in the PR](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience#snyk-agent-fix-in-the-pr), has been released, enabling the user to interact with inline comments by requesting an initial fix or a different suggestion, or by applying a specific fix by using the `@snyk /apply #` command.
* [Consistent Ignores](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code) for Snyk Code now fully supports CLI Upload.
* The page on Docker Desktop Extension integration has been removed due to the end of support.

### May 2025

#### Snyk CLI

* The `--platform` option was added to the [`container sbom`](/developer-tools/snyk-cli/snyk-cli/commands/container-sbom) command.
* The MCP information was expanded to [Developer guardrails for agentic workflows](/agent-security).

#### IDE plugins and extensions

* Information was added to the [JetBrains plugin troubleshooting](/developer-tools/integrations/snyk-ide-plugins-and-extensions/jetbrains-plugin/troubleshooting-for-the-jetbrains-plugin).
* Region information was updated on all [IDE pages](/developer-tools/integrations/snyk-ide-plugins-and-extensions).

#### Snyk Code

* Legacy ignores can be converted using [bulk ignore conversion](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code/convert-project-scoped-ignores-to-asset-scoped-ignores#bulk-ignore-conversion).
* DeepCode AI Fix has a new name: [Snyk Agent Fix](/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically).

#### Snyk Container

[Configure the integration with Docker Hub](/scan-fix-and-prevent/scan-with-snyk/snyk-container/container-registry-integrations/integrate-with-docker-hub/configure-the-integration-with-docker-hub) has been updated to state that Snyk does not support Organization Access Tokens (OAT).

#### Snyk Integrations

The [Bitbucket Cloud App](/developer-tools/integrations/scm-integrations/organization-level-integrations/bitbucket-cloud-app) and [Jira App](/developer-tools/integrations/jira-and-slack-integrations/snyk-security-in-jira-cloud-integration) integrations are now available in the `SNYK-US-02` environment.

#### Other updates

* For [SCM integrations with Python](/supported-languages/supported-languages-list/python/scm-integrations-and-python), the list of dependencies that are not supported has been updated to include `pip` for Python 2.7 and 3.7.
* [Python dependency filtering results](/supported-languages/supported-languages-list/python/scm-integrations-and-python) have been updated to clarify the conditions in which certain packages and configurations are skipped by SCM scans.
* The list of supported package managers has been updated to include `conan`. See [C/C++](/supported-languages/supported-languages-list/c-c++), [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test), [Test an SBOM document for vulnerabilities](/developer-tools/snyk-api/using-specific-snyk-apis/sbom-apis/rest-api-endpoint-test-an-sbom-document-for-vulnerabilities).
* [Instructions for upgrading an Organization integration from Classic Broker to Universal Broker](/platform-administration/snyk-broker/universal-broker/upgrade-an-organization-integration-from-classic-broker-to-universal-broker) were clarified.

### April 2025

#### Snyk API

* Several APIs have been updated; see the [Changelog](/developer-tools/snyk-api/changelog).
* The navigation in the API section now reflects the use of Authentication and the Changelog for both the V1 and REST APIs.
* The [Authentication for API](/developer-tools/snyk-api/authentication-for-api) page has been updated with region information and clarity on using the bearer token.
* The [API endpoints index and tips](/developer-tools/snyk-api/api-endpoints-index-and-tips) page now has a note about how to find your `org_id`.

#### Snyk Essentials

* [The Inventory Overview tab](/scan-fix-and-prevent/fix/assets-inventory-layouts) is now available to provide insights and prescriptive guidance to improve your application security.
* [The Visibility column](/scan-fix-and-prevent/fix/assets-inventory-components#visibility) has been added to show the visibility status of your repositories.

#### Snyk Broker

Additional updates have been made to the [Universal Broker](/developer-tools/snyk-api/reference/universal-broker) documentation to clarify the instructions and add details about the use of the APIs.

#### Snyk CLI

Information has been added about Snyk support for the Model Context Protocol (MCP) through the [`snyk mcp` experimental CLI command](/agent-security/agentic-security-with-snyk-studio/usage-analytics).

#### Snyk Code

* [Consistent Ignores ](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/ignore-issues/consistent-ignores-for-snyk-code)is now available in Early Access. Your development teams can create ignores that are consistently respected regardless of how and where the test is run and what branch is being tested.
* Snyk Code supports gRPC libraries.

#### Snyk Container

* [Using Custom Base Image Recommendation](/scan-fix-and-prevent/scan-with-snyk/snyk-container/use-snyk-container/use-custom-base-image-recommendations) has been updated with clarifications on how Snyk recommends images.
* The list of [Operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) has been updated to include Alpine Linux 3.21, Ubuntu 25.04 - Plucky Puffin, and Ubuntu 24.10 - Oracular Oriole.
* The section describing the automated integration process for Amazon Elastic Container Registry (ECR) has been removed, as Snyk no longer supports this method.

#### Snyk Integrations

* For the [Jira integration](/developer-tools/integrations/jira-and-slack-integrations/jira-integration#prerequisites-for-jira-integration-with-snyk), Snyk now supports Jira versions 5 to 10.
* For [SCM integrations with Gradle](/supported-languages/supported-languages-list/java-and-kotlin/git-repositories-with-maven-and-gradle), Snyk now supports `allprojects` and `subprojects` blocks, as well as Spring Boot plugins BOMs.

#### Other updates

* DAST scanning is now available with [Snyk API & Web](/scan-fix-and-prevent#select-scanning-methods), enabling users to discover and test the security of their APIs and web apps, including AI-generated ones.
* PR Checks is now available with a General Availability release status.

### March 2025

#### Snyk Broker

* The Snyk Broker section has been divided into [Universal Broker](/platform-administration/snyk-broker/universal-broker) and [Classic Broker](/platform-administration/snyk-broker/classic-broker) documentation and the [main page](/platform-administration/snyk-broker/snyk-broker) has been updated.
* The Classic Broker installation instructions now include the command to set the `BROKER_SERVER_URL` for [Docker](/platform-administration/snyk-broker/classic-broker/install-and-configure-snyk-broker/install-and-configure-broker-using-docker) and the `brokerServerUrl` for [Helm](/platform-administration/snyk-broker/classic-broker/install-and-configure-snyk-broker/install-and-configure-broker-using-helm).

#### Snyk API

* The [V1 API overview](/developer-tools/snyk-api/v1-api) and [reference](/developer-tools/snyk-api/reference) are now on the user docs site only. Additional details from Apiary have been added to the V1 reference on the user docs site. The API reference has been removed from the V1 API Apiary site.
* A section has been added for [pages that explain how to use specific APIs in depth](/developer-tools/snyk-api/using-specific-snyk-apis).

#### Snyk CLI, CI/CD, IDE

* [Advanced use of Snyk Container CLI](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-container/advanced-use-of-snyk-container-cli) now includes support for scanning Kaniko image archives.
* The [support policy for the CI/CD plugins](/developer-tools/integrations/snyk-ci-cd-integrations#support-policy) was updated to align with the CLI support policy.
* The Net new issues feature was added to the IDE documentation for [Eclipse](/developer-tools/integrations/snyk-ide-plugins-and-extensions/eclipse-plugin), [JetBrains](/developer-tools/integrations/snyk-ide-plugins-and-extensions/jetbrains-plugin/run-an-analysis-with-the-jetbrains-plugin#net-new-issues-versus-all-issues), [Visual Studio](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-extension/view-analysis-results-from-visual-studio-extension#net-new-issues-versus-all-issues), and [Visual Studio Code](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-code-extension/view-analysis-results-from-visual-studio-code-extension#net-new-issues-versus-all-issues), and [troubleshooting information](/developer-tools/integrations/snyk-ide-plugins-and-extensions/troubleshooting-ides/net-new-issues-delta-scan-troubleshooting) was added.

#### Snyk Code

* The Generated Pull Requests report is now available in Early Access. This report provides an overview of how Fix, Backlog, and Upgrade PRs are used and highlights the efficiency of PR merges.
* [The Pull Request Experience](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience) now supports GitLab and Azure Repos SCM integrations, with a few [limitations](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience#inline-comments).
* New Snyk Code filters and columns were added to [Snyk Reports](/scan-fix-and-prevent/prevent/analytics/reports-tab/issue-columns-dictionary#issue-characteristics) and [Snowflake Data Share](/scan-fix-and-prevent/prevent/analytics/reports-tab/reporting-and-bi-integrations-snowflake-data-share/data-share-data-dictionary): File Path, Code Region, and Asset Finding ID.
* Snyk Code now supports [Rust](/supported-languages/supported-languages-list/rust) and [Groovy](/supported-languages/supported-languages-list/groovy) available in Early Access and accessible from Snyk Preview.

#### Snyk Essentials

* A new feature is now available in Snyk Essentials, introducing a new type of [asset tag](/scan-fix-and-prevent/prevent/policies/assets-policies#asset-tagging) known as GitHub custom properties.
* [Asset tags](/scan-fix-and-prevent/fix/assets-inventory-components#tags) have been redefined and are now clearly separated into system tags and user-defined tags.

#### Snyk Integrations

* The [GitHub Server App](/developer-tools/integrations/scm-integrations/organization-level-integrations/github-server-app) has moved into General Availability.
* The Jira integration documentation has been updated to state that Snyk supports version 5 to version 9.

#### Other updates

* The PCI-DSS v4.0.1 report is now available in Early Access. This report leverages Snyk scan results to assess, prove, and improve readiness for PCI-DSS AppSec compliance regarding SCA and SAST vulnerabilities.
* The [Repositories Tested in CI/CD report](/scan-fix-and-prevent/prevent/analytics/reports-tab/prevention-reports#repositories-tested-in-ci-cd-report) is available in Early Access. This report tracks Snyk CI/CD testing to prevent vulnerable production deployments.
* [Severity levels](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/severity-levels#why-are-there-multiple-cvss-scores-for-the-same-vulnerability) now provide more details about the CVSS v4.0.

### February 2025

#### Snyk Essentials

* The Integrations UI at the Group level has been enhanced to improve readability and actionability and provide inline instructions and inline profile helpers.
* Group-level [Integrations documentation](/developer-tools/integrations/integrate-with-snyk#integrations-syncing-time) has been updated with new, more accurate sync times.
* The [asset filter](/scan-fix-and-prevent/prevent/policies/assets-policies/create-policies) documentation has been consolidated into one section, and it now links to all relevant areas, such as Inventory and Asset Policy filters.

#### Other updates

* A new [Automated Provisioning guide](/implementation-guides/auto-provisioning-guide) has been created for **Pilot** and **Enterprise** **users**, detailing the steps of the auto-provisioning process for new and existing user accounts.
* [Snyk Code PR Checks](/scan-fix-and-prevent/prevent/pull-request-checks/configure-pull-request-checks#configure-for-code-analysis-click-to-expand) are in General Availability.

</details>

## 2024

<details>

<summary>December - January 2024 Documentation updates</summary>

#### December 2024 and January 2025

**Snyk Container**

* Page "Integrate with Docker Desktop Extension" has been updated to include an end-of-support notice. Effective June 20, 2025, the integration with Docker Desktop will no longer receive updates or technical support.

**Snyk CLI and IDEs**

* [Eclipse IDE](/developer-tools/integrations/snyk-ide-plugins-and-extensions/eclipse-plugin) major update
* [Visual Studio IDE](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-extension) major update
* Region configuration update for [IDEs](/developer-tools/integrations/snyk-ide-plugins-and-extensions)
* [Snyk images EOL policy updated](/developer-tools/integrations/snyk-ci-cd-integrations/snyk-images-and-eol-image-policy)
* [`snyk container test`](/developer-tools/snyk-cli/snyk-cli/commands/container-test) and [`snyk container monitor`](/developer-tools/snyk-cli/snyk-cli/commands/container-monitor) option `--exclude-node-modules` added

**Other updates**

* [Snyk Admin](https://docs.snyk.io/platform-administration/) pages have been updated to reflect the addition of [Tenants](/platform-administration/snyk-hierarchy/tenant) in the Snyk hierarchy, including a new infographic to illustrate the Tenant position in the [hierarchy](/platform-administration/snyk-hierarchy/groups-and-organizations#the-snyk-hierarchy).

#### November 2024

**Snyk Container**

* The list of [operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container) has been updated to include Ubuntu 24.10 - Oracular Oriole and Ubuntu 24.04 - Noble Numbat 04.
* [How Snyk Container works](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works) has been updated with details on the logic Snyk applies when providing public base image recommendations.

**Other updates**

* The Pull Request Checks section has been updated to include the new [Pull Request Experience](/scan-fix-and-prevent/prevent/pull-request-checks/pull-request-experience) for PR Checks.
* The [Supported languages](/supported-languages/supported-languages-package-managers-and-frameworks) page has been reorganized to provide detailed information about language availability for each Snyk product. Additionally, it provides a list of package managers, frameworks, and features for each supported language.
* A service account using OAuth 2.0 can now be [created through the Snyk Web UI](/platform-administration/service-accounts/service-accounts-using-oauth-2.0#create-oauth-service-accounts-through-the-ui).
* The [API index](/developer-tools/snyk-api/api-endpoints-index-and-tips) now includes entries for each endpoint mentioned in the Snyk user docs.
* The [Developer IDE and CLI usage report](/scan-fix-and-prevent/prevent/analytics/reports-tab/prevention-reports#developer-ide-and-cli-usage-report) has been enhanced with additional functionalities: **Developer email address** and **PDF export**.
* The [Vulnerabilities Detail report](/scan-fix-and-prevent/prevent/analytics/reports-tab/remediation-reports#vulnerabilities-detail-report) has been enhanced with additional functionalities, such as **Target indication** and **Column picker**.

#### October 2024

**Snyk API**

* [Asset inventory components](/scan-fix-and-prevent/fix/assets-inventory-components#clusters) has been updated to include details on clusters.

**Snyk CLI and IDEs**

* The [CLI authentication page](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli) has been updated for the OAuth 2.0 protocol.
* The page [Debugging the Snyk CLI](/developer-tools/snyk-cli/snyk-cli/debugging-the-snyk-cli) has been added.
* [CLI standalone executables](/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli#direct-binary-download) have been updated to include Alpine Arm64.
* IDE [Eclipse plugin](/developer-tools/integrations/snyk-ide-plugins-and-extensions/eclipse-plugin) and [JetBrains plugin](/developer-tools/integrations/snyk-ide-plugins-and-extensions/jetbrains-plugin) documentation pages have been updated.
* Authentication information has been updated for all [IDEs](/developer-tools/integrations/snyk-ide-plugins-and-extensions).

**Snyk Integrations**

* [Snowflake Data Share](/scan-fix-and-prevent/prevent/analytics/reports-tab/reporting-and-bi-integrations-snowflake-data-share) is now in [GA](/snyk-release-process).
* [Snyk SCM integrations](/developer-tools/integrations/scm-integrations/organization-level-integrations) has been updated with additional notices relating to repository retrieval and permission or scope modifications after initial configuration.
* GitHub Cloud App has been added to feature support notices for Fix, Backlog, and Upgrade PRs.
* Snyk SCM integrations has been updated to include a table detailing the [permissions and scopes](/developer-tools/integrations/scm-integrations/user-permissions-and-access-scopes#github-cloud-app-permission-requirements) required for the GitHub Cloud App.

**Other updates**

* [Getting started](/getting-started-guides/getting-started) has been updated to centralize content related to everything you need to know before using Snyk.
* Scanning methods have been added for the [Dart and Flutter](/supported-languages/supported-languages-list/dart-and-flutter) languages.

#### September 2024

**Snyk API**

* A prerequisites section has been added to the Group level of [GitHub integration](/developer-tools/integrations/scm-integrations/organization-level-integrations/github-enterprise#prerequisites), and more details about the [Pull personal repositories](/developer-tools/integrations/scm-integrations/group-level-integrations/github-for-snyk-essentials) option have been added to the same documentation page.
* The [Set up Insights](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/set-up-insights) section was updated to emphasize the risk factors availability for each integration option.
* The Snyk Runtime Sensor has been updated to reflect the importance of adopting it to achieve the most effective integration and to access its continuously expanded set of features.

**Snyk Broker**

The Universal Broker feature is now available in Early Access. The Universal Broker separates deployment and container concerns from connection concerns. It allows for a smaller or a single deployment to support numerous connections of varied types.

**Snyk CLI**

* The [CLI commands and options summary](/developer-tools/snyk-cli/snyk-cli/cli-commands-and-options-summary) was updated.
* [Authentication](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli) has been updated.
* Configuration has been updated: Environment variables for Snyk CLI, [`snyk config`](/developer-tools/snyk-cli/snyk-cli/commands/config) help, [`snyk config environment`](/developer-tools/snyk-cli/snyk-cli/commands/config-environment) help.

**Snyk Integrations**

The Snowflake Data Share section has been updated to include a [Data Share Dictionary](/scan-fix-and-prevent/prevent/analytics/reports-tab/reporting-and-bi-integrations-snowflake-data-share/data-share-data-dictionary), designed to help you navigate and build your dataset.

**Other updates**

* The updated [Regional hosting and data residency](/snyk-data-and-governance/regional-hosting-and-data-residency) page was published.
* [Glossary](/glossary) terms were updated for SCA, SAST, DAST, and IAST as well as Software Composition Analysis.
* [Early Access](/snyk-release-process#early-access) release status notices were updated.

#### August 2024

**Snyk API**

* Links in the API reference docs have been updated.
* The [API endpoints index and notes](/developer-tools/snyk-api/api-endpoints-index-and-tips) have been updated.

**Snyk CLI**

* [`snyk auth`](/developer-tools/snyk-cli/snyk-cli/commands/auth) command help updated to reflect OAuth default.
* [CLI authentication](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli) instructions updated for OAuth default and improved flow.
* [`snyk config environment`](/developer-tools/snyk-cli/snyk-cli/commands/config-environment) command help has been added.
* CLI [support for pnpm added](/supported-languages/supported-languages-list/javascript#support-for-pnpm).

**Snyk IDE**

* [CLI authentication](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli) instructions updated for IDE.
* IDE authentication instructions updated: [Eclipse](/developer-tools/integrations/snyk-ide-plugins-and-extensions/eclipse-plugin/authentication-for-the-eclipse-plugin), [Jetbrains](/developer-tools/integrations/snyk-ide-plugins-and-extensions/jetbrains-plugin/authentication-for-the-jetbrains-plugins), [VS extension](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-extension/authentication-for-visual-studio-extension), [VS Code extension](/developer-tools/integrations/snyk-ide-plugins-and-extensions/visual-studio-code-extension/authentication-for-visual-studio-code-extension)

**Snyk Integrations**

* Git repository cloning has been renamed [Workspaces for SCM integrations](/developer-tools/integrations/scm-integrations/workspaces) to better reflect its functionality. Additional detail on [enablement](/developer-tools/integrations/scm-integrations/workspaces#manage-workspaces) has been added.
* The [relationship](/developer-tools/integrations/scm-integrations/organization-level-integrations/github-cloud-app#how-to-set-up-the-github-cloud-app) between GitHub organizations and Snyk Organizations when integrating with the GitHub Cloud App has been clarified.

#### July 2024

**Snyk API**

* The API documentation now provides the API Reference and explanatory documentation in the [API section](/developer-tools/snyk-api/snyk-api).
* The [API End of Life (EOL) process and migration guides](/developer-tools/snyk-api/api-end-of-life-eol-process-and-migration-guides) are now published and updated to support the process, which began in July.
* [Asset inventory filtering](/scan-fix-and-prevent/fix/assets-inventory-components#asset-tabs) describes the new, simplified view that provides an improved experience of filtering the assets.
* The [Asset inventory layouts](/scan-fix-and-prevent/fix/assets-inventory-layouts) have been renamed to better reflect their functionality.
* Four new SCM integrations are now available for Snyk:
  * [Atlassian Compass](/developer-tools/integrations/scm-integrations/application-context-for-scm-integrations#atlassian-compass)
  * [Harness](/developer-tools/integrations/scm-integrations/application-context-for-scm-integrations#harness)
  * [OpsLevel](/developer-tools/integrations/scm-integrations/application-context-for-scm-integrations#opslevel)
  * [Datadog Service Catalog](/developer-tools/integrations/scm-integrations/application-context-for-scm-integrations#datadog-service-catalog)

**Snyk Integrations**

* A comparison of the GitHub and GitHub Enterprise integrations functions now resides on the [SCM, IDE, and CI/CD integrations](/developer-tools/integrations/scm-integrations#github-vs-github-enterprise) page.
* Steps for [migrating from the GitHub integration to the GitHub Enterprise integration](/developer-tools/integrations/scm-integrations/organization-level-integrations/github#migrate-to-the-github-enterprise-integration) now reside on the GitHub integration page.
* The [Snyk SCM Integrations](/developer-tools/integrations/scm-integrations/organization-level-integrations) page now contains information critical to using these integrations successfully in your SDLC. This includes:
  * [Git repository cloning](/developer-tools/integrations/scm-integrations/workspaces) details
  * [Deployment recommendations](/developer-tools/integrations/scm-integrations/deployment-recommendations) for Enterprise customers
  * [User permissions and access scope requirements](/developer-tools/integrations/scm-integrations/user-permissions-and-access-scopes) for each SCM integration
  * Instructions on how to generate [integrated SCM tokens for Snyk Broker](/developer-tools/integrations/scm-integrations/scm-integrations-and-snyk-broker#integrated-scm-tokens-for-classic-broker)

**Other updates**

* **Snyk Reports:** The [issue column dictionary](/scan-fix-and-prevent/prevent/analytics/reports-tab/issue-columns-dictionary#issue-vulnerability-details) includes new filters and columns for Jira (JIRA ISSUES LIST, LATEST JIRA ISSUE) and EPSS (EPSS SCORE, EPSS PERCENTILE). This allows you to manage your work with Jira and to include EPSS in your prioritization steps.
* **Snyk Security:** Snyk has improved the prioritization workflow and risk assessment by adopting [CVSS V4.0](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/severity-levels#severity-levels-and-cvss) as the default evaluation for new vulnerabilities.
* **Fix code vulnerabilities automatically:** [DeepCode AI Fix](/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically#snyk-agent-fix-language-support) is now available in AWS Environments and JetBrains IDEs. If you use AWS multi-tenant environments, turn on the Snyk Preview [Snyk Code Fix Suggestions](/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically#enable-snyk-agent-fix) and retest with Snyk in your IDE.

</details>


# Snyk 2.0 platform improvements

Snyk 2.0 platform improvements rolling out through 2026 to address navigation, asset visibility, and issue triage

## What is Snyk 2.0?

Snyk 2.0 is a series of platform improvements rolling out gradually from April 2026 throughout the year to address navigation complexity, asset visibility, and triage inefficiency. As Snyk completes each component, users will gradually see Snyk platform interface updates. During the transition period, users can toggle between the new and classic interfaces.

| Improvement      | Description                                                                                                                                                      | Availability              |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------- |
| Navigation       | <p>A unified menu with a new scope selector.</p><p>Context-aware shortcuts reduce common tasks to two or three clicks.</p>                                       | April 2026 (Early Access) |
| Dark mode        | Full dark mode across the platform.                                                                                                                              | In development            |
| Asset management | View all repositories, containers, configurations, and AI models in a single inventory.                                                                          | In development            |
| Issue triage     | <p>Snyk prioritizes issues based on exploitability, reachability, and business impact.</p><p>Use bulk actions to fix similar issues across Snyk Projects.</p>    | In development            |
| Day2Operations   | Snyk 2.0 rduces operational friction between finding a vulnerability and acting on it, through grouped navigation, issue deduplication, and bulk triage actions. | In development            |

## What is Snyk 2.0 trying to solve?

<table><thead><tr><th>Feature area</th><th>Current use</th><th width="213.23046875">Snyk 2.0 solution</th><th>Status</th></tr></thead><tbody><tr><td>Navigation</td><td><ul><li>High friction</li><li>Six to eight clicks to find specific issues using deep breadcrumb paths.</li></ul></td><td><ul><li>Unified menu with a new scope selector.</li><li>Context-aware shortcuts.</li></ul><p><br></p></td><td>April 2026 (Early Access)</td></tr><tr><td>Asset visibility</td><td><ul><li>Separate views for Code, containers, and infrastructure</li><li>Users must check multiple pages to see which applications are affected by a new vulnerability.</li></ul></td><td><ul><li>Unified inventory for all repositories, configurations, and AI models.</li><li>Ability to tag assets by team, environment, and deployment status.</li></ul></td><td>In development</td></tr><tr><td>Issue triage</td><td>Users are experiencing alert overload</td><td><ul><li>Issue deduplications across product lines and scan surfaces</li><li>Bulk actions to fix similar problems across Snyk Projects</li></ul></td><td>In development</td></tr><tr><td>Policy and settings</td><td>Complex and scattered configurations across interfaces</td><td>An intuitive, unified view of the platform's settings</td><td>In development</td></tr><tr><td>Interface</td><td>Light-only UI causing eye strain during long sessions.</td><td>Support for dark mode with the ability to sync automatically with system preferences.</td><td>In development</td></tr></tbody></table>

## What do you need to do?

Updates apply automatically. You can toggle between the new and classic interfaces during the rollout.

To join the Early Access program, contact your Snyk account team. Provide feedback using the in-app form or email <snyk2.0@snyk.io>.

## How will this impact your workflow?

* **Developers**: Apply bulk actions to fix similar issues across multiple repositories. Enable dark mode to match your development environment.
* **Security teams**: View all assets and associated risks in a unified inventory. Faster mean-time-to-fix using prioritization and bulk actions. Manage policies more easily using the visual builder.
* **Administrators**: A simpler setup for roles and permissions using templates. Validate policies in real time before you commit changes. This means better visibility into team activity and easier integration management.

## Migration and support

Snyk releases updates gradually. You can toggle between interfaces during the transition period. These updates do not affect existing integrations and workflows. Snyk provides in-app help.

For dedicated support, use <snyk2.0@snyk.io>.

## Get help

* **Report issues**: Click the in-app feedback button or email support with "Snyk 2.0" in the subject line.
* **Ask questions**: Visit the Snyk Community forum or contact support.

## FAQs

**Can I opt out of the new interface?** Yes. You can switch back to the classic interface during the transition period.

**Does this change my pricing?** No. Your current plan includes all improvements.

**What if I find a bug?** Report bugs using the in-app feedback button or email <snyk2.0@snyk.io>. You can switch back to the classic interface while Snyk resolves the issue.


# Supported languages, package managers, and frameworks

Language, package manager, and framework support across Snyk Open Source and Snyk Code, with pointers to Snyk Container coverage

## Overview

Snyk offers support for various languages, customized depending on the Snyk product you are using. These pages focus on Snyk Open Source and Snyk Code.

For information about language support for Snyk Container, see [Supported workloads, container registries, languages, and operating systems](/scan-fix-and-prevent/scan-with-snyk/snyk-container/kubernetes-integration/overview-of-kubernetes-integration/supported-workloads-container-registries-languages-and-operating-systems) and [Operating system distributions supported by Snyk Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/operating-system-distributions-supported-by-snyk-container).

For IaC language support, see [Supported IaC languages, cloud providers, and cloud resources](/scan-fix-and-prevent/scan-with-snyk/snyk-iac/supported-iac-languages-cloud-providers-and-cloud-resources).

{% hint style="info" %}
Check the language availability before you import, test, or monitor it as an application using the Snyk products.
{% endhint %}

## Supported languages

The following table lists supported languages and the availability of support for using each language with SCM integrations and Snyk CLI, IDE, and CI/CD. Navigate to each language page for more details.

<table><thead><tr><th width="270">Language</th><th width="225">Snyk Open Source</th><th width="210">Snyk Code</th><th data-hidden>SCM support</th><th data-hidden>Snyk CLI, IDE, CI/CD</th></tr></thead><tbody><tr><td><a href="/pages/yPuOT73KgI3Wvfg3Ppyi">Apex</a></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/itqKYuBlOragPKxpslFw">C/C++</a></td><td>✔️</td><td>✔️</td><td>For Snyk Code</td><td>✔️</td></tr><tr><td><a href="/pages/STwpLMW8fsZlkuYyqqKG">COBOL</a></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td>✔️</td><td></td><td></td></tr><tr><td><a href="/pages/POJpt0vOkLeIi3MMbVL3">Dart and Flutter</a></td><td>✔️</td><td>✔️</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td></tr><tr><td><a href="/pages/Dav2o2av6Hw1GIOFSdig">Elixir</a></td><td>✔️</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td>✔️</td></tr><tr><td><a href="/pages/v8aNIJo4foPeFM41om4o">Go</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/apN9AnyjjHonGxaGpokp">Groovy</a></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td>✔️</td><td></td><td></td></tr><tr><td><a href="/pages/Qv1khHxFkO3W9L3cYmnr">Java and Kotlin</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/PjUo5YObkY3WeUVHBU3U">JavaScript</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/j2aThH3QSsiNgsGMGjc8">.NET (C# and VB.NET)</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/jkYkunQ9VqsTa8gQaaMt">PHP</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/x8YK94WGZOMp0xoNY47G">Python</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/SUsLNWOiXYhYWUZoH1XJ">Ruby</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/b5GaZ6tnmLM1ekd0CT5X">Rust</a></td><td>Limited support</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2716">✖️</span></td></tr><tr><td><a href="/pages/5IpbQEsZ3X1T1k5L7wXP">Scala</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/QNitFC0FrdIpKLLWPqs1">Swift and Objective-C</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr><tr><td><a href="/pages/z2azE2xFNDgPtKaCbd7t">TypeScript</a></td><td>✔️</td><td>✔️</td><td>✔️</td><td>✔️</td></tr></tbody></table>

{% hint style="info" %}
Interfile analysis in Snyk Code is available for all supported languages.

For Snyk Open Source, only official releases are tracked. Commits, including into the default branch, are not identified unless included in an official release or tag.

For Projects with a package manager, an official release of the package manager is required.

For Go and Unmanaged scans (C/C++), an official release or tag on the GitHub repository is required.
{% endhint %}


# Technical specifications and guidance

Technical requirements for Snyk Code and Snyk Open Source, including file encoding and how Snyk builds the dependency tree

## Unicode character encoding

Both Snyk Code and Snyk Open Source accept source code files in UTF-8 encoding. Consider converting source files to this encoding type before importing them into Snyk.

## Snyk Open Source

Snyk analyzes and builds the dependency tree depending on the language and package manager for the Project, as well as the location of the Project.

### How Snyk for Open Source and licensing works

{% hint style="info" %}
Before testing your Open Source Project for vulnerabilities, with limited exceptions, you must build your Project. For details, see [Open Source Projects that must be built before testing with the Snyk CLI](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-open-source/open-source-projects-that-must-be-built-before-testing-with-the-snyk-cli).
{% endhint %}

Snyk builds a dependency graph and (dependency tree) and then uses the [vulnerability database](https://snyk.io/vuln) to find vulnerabilities in any of the packages anywhere in that tree.

### Snyk policies in Open Source

For information on managing dependencies and vulnerabilities from your developer workflows through the use of policies, see:

* [Defining a secure open-source policy](https://snyk.io/series/open-source-security/open-source-policy/)
* [Use Snyk security policies to prioritize fixes more efficiently](https://snyk.io/blog/snyk-security-policies/)

### Open Source license compliance

To check compliance for open source licenses, see [Snyk License Compliance Management](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/snyk-license-compliance-management).

## Snyk Code

### File size limit for Snyk Code analysis

Snyk Code automatically excludes the following files from analysis:

* On the Web UI - files that are larger than 1MB.
* On the CLI and IDE - files that are larger than 1MB.
* Minified JS files with 3 or fewer lines.

### Filename length limitation

The analysis is available only for files with names shorter than or equal to 255 characters. If the filename exceeds this limit, you receive an error. To ensure that all files are being analyzed, Snyk recommends shortening long filenames.

### Framework support

To support a specific framework, Snyk Code must both support the relevant language and be trained on Projects using the framework. The found patterns are then annotated by the security team and extended by curated content.

Most frameworks are partially supported out of the box, as Snyk Code needs only to parse the code to analyze it. In some cases, frameworks may require specific rules, or require specific program analysis engine updates, or both.

If you notice any gaps in support for a specific framework, [contact Snyk Support](https://support.snyk.io).

Snyk categorizes framework support into two levels: Comprehensive and Partial.

Comprehensive support includes:

* Sources and sinks: All relevant sources and sinks are identified.
* Data flow testing: Extensive testing provides thorough data flow coverage.
* Engine support: The Snyk Code engine is fully optimized for this framework.
* Limitations: No known limitations; report any false negatives to [Snyk Support](https://support.snyk.io).

Partial support includes:

* Sources and sinks: Coverage may be limited, with some missing elements.
* Data flow testing: Limited testing has been conducted.
* Engine support: Compatibility is restricted, which may impact analysis accuracy.
* Limitations: Potential for false negatives in taint analysis or source/sink identification.

Snyk continuously expands its framework coverage and improves analysis accuracy.

### How Snyk Code analysis works

Snyk scans your codebase following this sequence:

1. The source code is analyzed to generate an event graph. The event graph is similar to a code map, helping Snyk understand how different parts of the code are related. There are two node types, each node in the graph representing something that happens in the code. Some represent parts of the code, and others represent how the code is used.
2. Rules are run against the event graph to find matches. The rules act as a checklist of known vulnerabilities that Snyk looks for in the event graph.
3. If a match is found, Snyk looks for a vulnerability in the event graph, identifying where problems might be hiding in the code.

For more information, see [Snyk Code AI Engine](/scan-fix-and-prevent/scan-with-snyk/snyk-code#ai-engine). For more information about Snyk Code language support, see [Supported languages, package managers, and frameworks](/supported-languages/supported-languages-package-managers-and-frameworks).

## Language support and CLI, CI/CD, and SCM integrations

Snyk supports a variety of programming languages, enabling seamless integration into your development workflow through CLI commands, CI/CD pipelines, and SCM integrations.

You can use these tools to automatically check your code for security issues as you develop your software. This ensures that strong security practices are part of your development process.

Navigate to the following pages for more details:

* CLI for [Snyk Open Source](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-open-source) and [Snyk Code](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-code)
* CI/CD for [Snyk Open Source](/developer-tools/integrations/snyk-ci-cd-integrations/snyk-ci-cd-integration-deployment-and-strategies/snyk-open-source-specific-ci-cd-strategies) and [Snyk Code](/developer-tools/integrations/snyk-ci-cd-integrations/use-snyk-code-in-the-ci-cd-pipeline)
* [SCM integrations](/developer-tools/integrations/scm-integrations/organization-level-integrations) for Snyk Open Source and Snyk Code


# Supported languages list

Index of the programming languages Snyk supports, with per-language product coverage and integration details


# Apex

Snyk support for Apex with Snyk Code, including supported file formats, interfile analysis, and SCM, CLI, and IDE features

{% hint style="info" %}
Apex is supported only for Snyk Code.
{% endhint %}

## Supported file formats

Apex Standard Library is fully supported. Snyk supports the following file formats for Snyk Code: `.cls`, `.trigger`, `.tgr`

## Available features

For Apex, Snyk supports the following features:

* Support for Interfile analysis
* Reports
* Interfile analysis
* SCM import
* CLI and IDE: test or monitor your app. For more information, see [Snyk CLI for Snyk Code](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-code).

{% hint style="info" %}
The **Snyk fix PR** feature is not available for Apex. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}


# Bazel

Snyk support for Bazel with Snyk Open Source, including testing Bazel v7 Projects through the Dep Graph API

## Applicability

{% hint style="info" %}
Snyk supports Bazel only for Snyk Open Source.

Snyk for Bazel provides support for using the [Bazel build and test tool](https://docs.bazel.build/versions/master/bazel-overview.html) with Snyk Open Source. The instructions in this documentation apply to Bazel v 7 only.
{% endhint %}

Snyk supports testing Projects whose dependencies are managed by Bazel. Snyk recommends testing and monitoring using the Dep Graph API.

Unlike npm, Bazel does not rely on dependency manifest files or lock files. Instead, you manage build configurations in [BUILD](https://docs.bazel.build/versions/master/build-ref.html#BUILD_files) files using [Starlark](https://docs.bazel.build/versions/master/skylark/language.html), a domain-specific language based on Python 3.

You manually specify all dependencies (package name, location, and version), including transitive dependencies. Bazel fetches these dependencies during builds.

Bazel has limited native integration with package registries, such as npmjs.org or Maven Central. You can add Bazel rules to help install dependencies from external registries.

Because Bazel dependencies are specified as code in BUILD files using Starlark, Snyk cannot easily discover the dependencies from a Project.

## Dep Graph API

To secure Bazel Projects, you must use the Snyk Dep Graph API. This API accepts a generic dependency graph and returns a report containing any relevant vulnerabilities for those dependencies.

### Requirements and considerations

The Dep Graph API requires specific permissions. If you do not have access, contact Snyk Support.

You can test Bazel dependencies across any supported ecosystem, except C++, which is not supported by these endpoints.

Use the Snyk Dep Graph API endpoints [Test Dep Graph](/developer-tools/snyk-api/reference/test-v1) and [Monitor Dep Graph](/developer-tools/snyk-api/reference/monitor-v1) to test and monitor dependencies managed by Bazel. The monitor capability allows you to submit a tree for Snyk to monitor for vulnerabilities.

### Test and monitor dependencies

To integrate Snyk into your Bazel workflow, follow these steps to manually generate and submit a dependency graph to the Snyk API:

1. Create a [Dep Graph JSON object](https://github.com/snyk/dep-graph) listing all the dependency packages and versions for each type of dependency (for example, Maven or CocoaPods).
2. Send the Dep Graph JSON object as a POST request to the Test Dep Graph endpoint, along with your [auth token](/developer-tools/snyk-api/authentication-for-api), as part of a Bazel test rule.
3. Check the API response for pass or fail status and any resulting vulnerabilities.

For example:

```bash
curl -X POST 'https://api.snyk.io/v1/test/dep-graph' \
  -H 'Authorization: token {{your token}}' \
  -H 'Content-Type: application/json; charset=utf-8' \
  -d @dep-graph.json
```

### Dep Graph JSON syntax

The Test Dep Graph API accepts a Snyk Dep Graph JSON object. This object describes the root application and the graph of direct and transitive dependencies.

The [schema](https://github.com/snyk/dep-graph#depgraphdata) for this format is:

{% code overflow="wrap" fullWidth="false" %}

```json
export interface DepGraphData {
  schemaVersion: string;
  pkgManager: {
    name: string;
    version?: string;
    repositories?: Array<{
      alias: string;
    }>;
  };
  pkgs: Array<{
    id: string;
    info: {
      name: string;
      version?: string;
    };
  }>;
  graph: {
    rootNodeId: string;
    nodes: Array<{
      nodeId: string;
      pkgId: string;
      info?: {
        versionProvenance?: {
          type: string;
          location: string;
          property?: {
            name: string;
          };
        },
        labels?: {
          [key: string]: string | undefined;
        };
      };
      deps: Array<{
        nodeId: string;
      }>;
    }>;
  };
}
```

{% endcode %}

Specific components in the Dep Graph object include:

* `schemaVersion` - the version of the Dep Graph schema. Set this to `1.2.0`.
* `pkgManager.name` - can be one of `deb`, `gomodules`, `gradle`, `maven`, `npm`, `nuget`, `paket`, `pip`, `rpm`, `rubygems`, or `cocoapods`.
* `pkgs` - an array of objects containing `id`, `name` and `version` of all packages in the Dep Graph. The `id` must be in the form `name@version`. List each of your dependencies in this array, including an item representing the Project itself.
* `graph.nodes` - an array of objects describing the relationships between entries in `pkgs`. This is typically the Project node with all other packages defined as a flat array of direct dependencies in `deps.`
* `graph.rootNodeId` - specifies the `id` of the entry in `graph.nodes` to use as the root node of the graph. Set this to the `nodeId` of the Project node.

### Dep Graph Test API response

The Test Dep Graph API returns a JSON object describing any issues (vulnerabilities and licenses) found in the Dep Graph dependencies.

An example response with a single vulnerability:

{% code overflow="wrap" %}

```json
{
    "ok": false,
    "packageManager": "maven",
    "issuesData": {
        "SNYK-JAVA-CHQOSLOGBACK-30208": {
            "CVSSv3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "alternativeIds": [],
            "creationTime": "2017-03-19T14:58:38Z",
            "credit": [
                "Unknown"
            ],
            "cvssScore": 9.8,
            "description": "## Overview\n[ch.qos.logback:logback-core](https://mvnrepository.com/artifact/ch.qos.logback/logback-core) is a logback-core module.\n\nAffected versions of this package are vulnerable to Arbitrary Code Execution. A configuration can be ...",
            "disclosureTime": "2017-03-13T06:59:00Z",
            "exploit": "Not Defined",
            "fixedIn": [
                "1.1.11"
            ],
            "functions": [],
            "id": "SNYK-JAVA-CHQOSLOGBACK-30208",
            "identifiers": {
                "CVE": [
                    "CVE-2017-5929"
                ],
                "CWE": [
                    "CWE-502"
                ]
            },
            "language": "java",
            "mavenModuleName": {
                "artifactId": "logback-core",
                "groupId": "ch.qos.logback"
            },
            "modificationTime": "2020-06-12T14:36:56.271247Z",
            "moduleName": "ch.qos.logback:logback-core",
            "packageManager": "maven",
            "packageName": "ch.qos.logback:logback-core",
            "patches": [],
            "proprietary": false,
            "publicationTime": "2017-03-21T15:30:44Z",
            "references": [
                {
                    "title": "GitHub Commit #1",
                    "url": "https://github.com/qos-ch/logback/commit/f46044b805bca91efe5fd6afe52257cd02f775f8"
                },
                {
                    "title": "GitHub Commit #2",
                    "url": "https://github.com/qos-ch/logback/commit/979b042cb1f0b4c1e5869ccc8912e68c39f769f9"
                },
                {
                    "title": "Logback News",
                    "url": "https://logback.qos.ch/news.html"
                },
                {
                    "title": "NVD",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5929"
                },
                {
                    "title": "NVD",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5929/"
                }
            ],
            "semver": {
                "vulnerable": [
                    "[, 1.1.11)"
                ]
            },
            "severity": "high",
            "title": "Arbitrary Code Execution"
        }
    },
    "issues": [
        {
            "pkgName": "ch.qos.logback:logback-core",
            "pkgVersion": "1.0.13",
            "issueId": "SNYK-JAVA-CHQOSLOGBACK-30208",
            "fixInfo": {}
        }
    ],
    "org": {
        "id": "3e5fe3fe-9181-4f0f-a231-39764485e73f",
        "name": "stephen.elson-xnf"
    }
}
```

{% endcode %}

Specific components in the response object include:

* `ok` - Boolean value summarizing whether Snyk found any vulnerabilities in the supplied dependencies. You can use this for a quick pass or fail test.
* `issuesData` - a hash of each unique vulnerability found. Each vulnerability contains useful properties, such as `title`, `description`, `identifiers`, `publicationTime`, `severity`, and so on.
* `issues` - an array of mappings from vulnerabilities in `issuesData` to package. This mapping shortens the response length because a vulnerability can apply to multiple packages.

### Example of dependency mapping for a Bazel Project

For a Bazel Project with a single dependency on a Maven package, you can specify the dependency as follows:

```python
maven_jar(
    name = "logback-core",
    artifact = "ch.qos.logback:logback-core:1.0.13",
    sha1 = "dc6e6ce937347bd4d990fc89f4ceb469db53e45e",
)
```

Use the provided template to construct the following Dep Graph JSON object:

```json
{
  "depGraph": {
    "schemaVersion": "1.2.0",
    "pkgManager": {
      "name": "maven"
    },
    "pkgs": [
      {
        "id": "app@1.0.0",
        "info": {
          "name": "app",
          "version": "1.0.0"
        }
      },
      {
        "id": "ch.qos.logback:logback-core@1.0.13",
        "info": {
          "name": "ch.qos.logback:logback-core",
          "version": "1.0.13"
        }
      }
    ],
    "graph": {
      "rootNodeId": "root-node",
      "nodes": [
        {
          "nodeId": "root-node",
          "pkgId": "app@1.0.0",
          "deps": [
            {
              "nodeId": "ch.qos.logback:logback-core@1.0.13"
            }
          ]
        },
        {
          "nodeId": "ch.qos.logback:logback-core@1.0.13",
          "pkgId": "ch.qos.logback:logback-core@1.0.13",
          "deps": []
        }
      ]
    }
  }
}
```

This package (`ch.qos.logback:logback-core@1.0.13`) contains a vulnerability described in detail in the resulting JSON response object.


# C/C++

Snyk support for C and C++ with Snyk Code and Snyk Open Source, including CLI and IDE testing and supported frameworks and libraries

{% hint style="info" %}
C/C++ is supported for Snyk Code and Snyk Open Source.
{% endhint %}

Available integrations:

* CLI and IDE: test or monitor your app

## Supported frameworks and libraries

For C/C++, the following frameworks and libraries are supported:

{% columns %}
{% column %}

* argparse parser
* Asio Library
* Boost Library
* Botan LIbrary
* C Standard Library
* C++ Standard Library
* Curl library
* fstream framework
* grpc-cpp library
* HTTPlib framework
* JsonCpp library
* liboai framework
* libpq library
* libpqxx framework
* libsodium library
* LibTomCrypt framework
* libxml2 framework
  {% endcolumn %}

{% column %}

* MySQL framework
* OpenSSL framework
* POSIX LIbrary
* pugixml library
* SQLite library
* WinHTTP framework
* Xerces libraries
  {% endcolumn %}
  {% endcolumns %}

## Supported package managers

For Conan, Snyk supports [conan.io](https://conan.io/center) as a package registry.

## C/C++ for Snyk Code

For an overview of the supported security rules, visit [C/C++ rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/c-c++-rules).

For C/C++ for Snyk Code, the embedded operating system is Linux. Support for Windows is limited.

### Supported file formats

For C/C++ with Snyk Code, Snyk supports the following file formats: `.c`, `.cc`, `.cpp`, `.cxx`, `.h`, `.hpp`, `.hxx`.

### Available features

* SCM import
* Support for interfile analysis

If you use macros, it is possible that your results include false positives and false negatives.

For C/C++ Projects:

* Snyk does not require compilation or a build to perform analysis.
* Snyk Code analyzes the source code directly.
* If you have precompile components, ensure the source code is available during the scan.

When using the IDE, you do not need additional options. The Snyk plugin displays results in the IDE views.

## C/C++ for Snyk Open Source

### Available features

* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:generic` or `pkg:conan` PURLs through [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command.

{% hint style="info" %}
The **Snyk FixPR** feature is not available for C/C++. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}

### Dependency management and license compliance

To check compliance for open source licenses, visit [Snyk License Compliance Management.](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/snyk-license-compliance-management)

For information about managing dependencies and licenses from your developer workflows through policy, visit the following resources:

* [Defining a secure open source policy](https://snyk.io/series/open-source-security/open-source-policy/)
* [Use Snyk security policies to prioritize fixes more efficiently](https://snyk.io/blog/snyk-security-policies/)

To scan for C/C++ Open Source dependencies using the IDE, add the `--unmanaged` option to your IDE settings:

1. Navigate to **Additional Parameters** in the IDE settings.
2. Enter `--unmanaged`.
3. Click **Scan for dependencies**.

### Troubleshooting

Your Snyk Open Source code is not sent to Snyk severs. Snyk converts the files to a list of hashes before sending them for scanning.

Snyk matches your code against a database of official open-source releases. If a scan returns no results, check these common causes:

* **Unpacked source code:** The source code of the scanned dependencies must be unpacked in the scanned directory. If you use a package manager like Conan, the Conan cache often contains the source code along with dependencies from other Snyk Projects. Snyk recommends scanning package manager dependencies in a clean environment, for example, during a build.
* **Unofficial releases:** The dependency source code is not from an official release of the open-source software (OSS) component. Snyk does not store unofficial releases in the database.
* **Extensive modifications:** If you modify the OSS source code extensively, Snyk cannot detect it. If you modify most files in a small component, Snyk cannot match them to the Snyk database. Common modifications include whitespace formatting and adding license or copyright headers.
* **Incomplete source code:** If you include only a small percentage of the component files, Snyk cannot match them to the Snyk database.
* **Symlink issues:** Snyk does not follow symlinks when collecting files for hashing. If you unzip a Linux source package in Windows, Windows replaces in-package symlinks with copies of linked files. This makes the Windows representation different from the original source. If the difference is too large, Snyk cannot detect the component.
* **New components:** The OSS component source code is too new. Snyk refreshes the database twice a month, but processing the latest releases takes time.

If none of the above apply, contact Snyk Support.

## CLI support for C/C++

To explore C/C++ vulnerabilities, you can search the [Snyk Vulnerability Database](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/manage-vulnerabilities/snyk-vulnerability-database). Snyk tests your code against this database. Snyk updates the database periodically with the latest source code from online sources.

For codebase scanning, Snyk analyzes your source code without requiring a build. To test your code, open the source code directory in the terminal and run the following command:

```bash
snyk code test
```

Use the `snyk-to-html` plugin to generate reports. To access results programmatically, export them to JSON or SARIF using the `--json` or `--sarif` options. For more information, visit [Exporting the test results to a JSON or SARIF file](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-code/view-snyk-code-cli-results#export-test-results).

For advanced filtering options, see[ snyk-filter](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter).

To scan an Open Source Project, Snyk requires the dependencies to be available as source code in the scanned directory. If the dependencies reside in a different location, you must scan that location.

For Open Source Projects, use the `--unmanaged` option to analyze for license compliance and known security issues:

```bash
snyk test --unmanaged
```

When you run the `snyk test --unmanaged` command, Snyk performs the following steps:

1. Converts all files from your current directory into a list of hashes.
2. Sends hashes to the Snyk scan server to compute the dependencies list.
3. Queries the database to find a list of potentially matching dependencies.
4. Links the dependencies to known vulnerabilities.
5. Displays the results.

To monitor and share reports, run the following command:

```bash
snyk monitor --unmanaged --org=*org-id*
```

Find your org-id under **Organization settings** in the Snyk web UI. Although the Organization ID is optional, Snyk recommends using it. You can use the `snyk-to-html` plugin to generate reports.

For individual scans, use the CLI or IDE and run `snyk monitor --unmanaged` to upload results. This displays license and policy information.

To prevent noise from individual scans, Snyk recommends that you:

* Send results to your personal folder.
* Disable scheduled scanning in **Project settings**.

For automated scans in a CI/CD pipeline, run `snyk monitor --unmanaged` and send results to your chosen Organization. This displays license and policy information.

### Scanning license policies

You can create a license policy for open-source applications to specify unapproved licenses. When Snyk detects an unapproved license, it sends an alert containing the license name and the license policy text.

Administrators associate license policy text with the license issue. This text provides custom instructions on how to resolve the issue or explains why the license violates the policy.

### Display dependencies

To display dependencies in your codebase and their origin, use the `--print-deps` option.

In C/C++, this flag also identifies the confidence level of a match. A confidence level below 90% indicates the file is likely modified and not the original source. Investigate these files to confirm their origin.

```bash
$ snyk test --unmanaged --print-deps

Testing /Users/user/src/foo...


Dependencies:

  https://curl.se|curl@7.29.0
  purl: pkg:generic/curl@7.29.0?download_url=https:%2F%2Fcurl.se%2Fdownload%2Farcheology%2Fcurl-7.29.0.tar.gz
  confidence: 1.000

  https://github.com|nih-at/libzip@1.8.0
  purl: pkg:generic/libzip@1.8.0?download_url=https:%2F%2Fgithub.com%2Fnih-at%2Flibzip%2Farchive%2Fv1.8.0.tar.gz
  confidence: 1.000

  https://github.com|madler/zlib@1.2.11
  purl: pkg:generic/zlib@1.2.11?download_url=https:%2F%2Fzlib.net%2Ffossils%2Fzlib-1.2.11.tar.gz
  confidence: 1.000
```

Use the `--print-dep-paths` option to see which files contribute to each dependency.

```bash
$ snyk test --unmanaged --print-dep-paths

Testing /Users/user/src/foo...


Dependencies:

  https://curl.se|curl@7.29.0
  purl: pkg:generic/curl@7.29.0?download_url=https:%2F%2Fcurl.se%2Fdownload%2Farcheology%2Fcurl-7.29.0.tar.gz
  confidence: 1.000
  matching files:
    - curl-7.29.0/Android.mk
    - curl-7.29.0/CHANGES
    - curl-7.29.0/CMake/CMakeConfigurableFile.in
    ... and 1766 more files

  https://github.com|nih-at/libzip@1.8.0
  purl: pkg:generic/libzip@1.8.0?download_url=https:%2F%2Fgithub.com%2Fnih-at%2Flibzip%2Farchive%2Fv1.8.0.tar.gz
  confidence: 1.000
  matching files:
    - libzip-1.8.0/API-CHANGES.md
    - libzip-1.8.0/AUTHORS
    - libzip-1.8.0/CMakeLists.txt
    ... and 780 more files

  https://github.com|madler/zlib@1.2.11
  purl: pkg:generic/zlib@1.2.11?download_url=https:%2F%2Fzlib.net%2Ffossils%2Fzlib-1.2.11.tar.gz
  confidence: 1.000
  matching files:
    - zlib-1.2.11/CMakeLists.txt
    - zlib-1.2.11/ChangeLog
    - zlib-1.2.11/FAQ
    ... and 249 more files
```

The output shows the confidence level for the identified dependency and its version. Use the `--print-deps` or `--print-dep-paths` option to view this information.

### Confidence level

The confidence level indicates how accurately Snyk identifies a dependency. This value ranges from 0 to 1. A higher number indicates greater accuracy. A confidence level of 1 means all files in the source tree fully match the expected files in the Snyk database.

```
curl|https://github.com/curl/curl/releases/download/curl-7_58_0/curl-7.58.0.tar.xz@7.58.0 confidence: 0.993
```

Snyk uses file signatures to find the closest match to an open-source library. If you modify the source code of a dependency, the identification accuracy decreases.

### Source code dependency location

The CLI requires the full dependency source code in the scanned directory to find dependencies.

Keep a large percentage of files in their original, unchanged form to ensure Snyk accurately identifies dependencies and reports the correct vulnerabilities. Modifying the source code reduces the confidence of the scanning engine and produces less accurate results. Modified source code causes Snyk to miss dependencies or identify them incorrectly as a different version or package.

The following example shows a typical package with listed dependencies:

```
c-example
├── deps
│   ├── curl-7.58.0
│   │   ├── include
│   │   │   ├── Makefile.am
│   │   │   ├── Makefile.in
│   │   │   ├── README
│   │   │   └── curl
│   │   ├── install-sh
│   │   ├── lib
│   │   │   ├── asyn.h
│   │   │   ├── base64.c
│   │   │   ├── checksrc.pl
│   │   │   ├── config-amigaos.h
│   │   │   ├── conncache.c
│   │   │   ├── conncache.h
│   │   ├── src
│   │   │   ├── tool_binmode.c
│   │   │   ├── tool_binmode.h
│   │   │   ├── tool_bname.c
│   │   │   ├── tool_xattr.c
...
```

### Scanning archives

By default, Snyk does not scan archives. However, the CLI can recursively extract archives to analyze the internal source code.

To enable archive extraction, specify the extraction depth using the `--max-depth` option.

Snyk supports the following archive formats:

* Zip-like archives
* Tar archives
* Tar with gzip compression algorithm

### Support for releases

Snyk tracks only official releases. Snyk does not identify commits, including commits to the default branch, unless they are part of an official release or tag.

For Projects with a package manager, this means a release to the package manager. For Go and unmanaged scans (C/C++), this requires an official release or tag on the GitHub repository.

### Data collection during a scan

When you scan C++ Projects, Snyk collects and stores the following data for troubleshooting:

* Hashes of the scanned files: Snyk converts all files to a list of irreversible hashes.
* Relative paths to scanned files: Snyk includes the paths to files relative to the scanned directory for better identification and matching.

Example:

```
./project-name/vendor/bzip2-1.0.6/blocksort.c
```

### JSON output

To generate machine-readable JSON output, use the `--json` option:

```
$ snyk test --unmanaged --json
[
  {
    "issues": [
      {
        "pkgName": "curl|https://github.com/curl/curl/releases/download/curl-7_58_0/curl-7.58.0.tar.xz",
        "pkgVersion": "7.58.0",
        "issueId": "CVE-2019-5481",
        "fixInfo": {
          "isPatchable": false,
          "isPinnable": false
        }
      }
    ],
    "issuesData": {
      "CVE-2019-5481": {
        "severity": "high",
        "CVSSv3": "",
        "originalSeverity": "high",
        "severityWithCritical": "high",
        "type": "vuln",
        "alternativeIds": [
          ""
        ],
        "creationTime": "2019-09-16T19:15:00.000Z",
        "disclosureTime": "2019-09-16T19:15:00.000Z",
        "modificationTime": "2020-10-20T22:15:00.000Z",
        "publicationTime": "2019-09-16T19:15:00.000Z",
        "credit": [
          ""
        ],
        "id": "CVE-2019-5481",
        "packageManager": "cpp",
        "packageName": "curl|https://github.com/curl/curl/releases/download/curl-7_58_0/curl-7.58.0.tar.xz",
        "language": "cpp",
        "fixedIn": [
          ""
        ],
        "patches": [],
        "exploit": "No Data",
        "functions": [
          ""
        ],
        "semver": {
          "vulnerable": [
            "7.58.0"
          ],
          "vulnerableHashes": [
            ""
          ],
          "vulnerableByDistro": {}
        },
        "references": [
          {
            "title": "https://curl.haxx.se/docs/CVE-2019-5481.html",
            "url": "https://curl.haxx.se/docs/CVE-2019-5481.html"
          },
        ],
        "internal": {},
        "identifiers": {
          "CVE": [
            "CVE-2019-5481"
          ],
          "CWE": [],
          "ALTERNATIVE": [
            ""
          ]
        },
        "title": "CVE-2019-5481",
        "description": "",
        "license": "",
        "proprietary": true,
        "nearestFixedInVersion": ""
      }
    },
    "fileSignaturesDetails": {
      "https://curl.se|curl@7.58.0": {
        "artifact": "curl",
        "version": "7.58.0",
        "author": "curl",
        "path": "curl-7.58.0",
        "id": "59d80da8ba341aaff828662700000000",
        "url": "https://curl.se/download/curl-7.58.0.tar.gz",
        "purl": "pkg:generic/curl@7.58.0?download_url=https:%2F%2Fcurl.se%2Fdownload%2Fcurl-7.58.0.tar.gz",
        "score": 1,
        "confidence": 1,
        "filePaths": [
          "deps/curl-7.58.0/CHANGES",
          "c-example/deps/curl-7.58.0/CMake/CMakeConfigurableFile.in",
          "c-example/deps/curl-7.58.0/CMake/CurlSymbolHiding.cmake"
        ],
        "confidence": 1
      }
    }
  }
]
```

### CLI options

You can use the following command-line options with the `snyk test --unmanaged` and `snyk monitor --unmanaged` commands:

* `--org=ORG_ID`
* `--json`
* `--json-file-output=OUTPUT_FILE_PATH` (`snyk test` only)
* `--remote-repo-url=URL`
* `--severity-threshold=low|medium|high|critical>` (`snyk test` only)
* `--max-depth`
* `--print-dep-paths`
* `--target-reference=TARGET_REFERENCE` (`snyk monitor` only)
* `--project-name=c-project` (`snyk monitor` only)

For more information about command-line options, visit [Options for scanning with `snyk test --unmanaged`](/developer-tools/snyk-cli/snyk-cli/commands/test#unmanaged) or [`snyk monitor --unmanaged`](/developer-tools/snyk-cli/snyk-cli/commands/monitor#unmanaged).

To import the test results (issues and dependencies) in the Snyk CLI, run the `snyk monitor --unmanaged` command:

```
$ snyk monitor --unmanaged
Monitoring /c-example (c-example)...

Explore this snapshot at https://app.snyk.io/org/example-org/project/8ac0e233-d0f9-403e-b422-5970e7a37443/history/5de4616d-3967-485f-bf21-bbbe91068029

Notifications about newly disclosed issues related to these dependencies will be emailed to you.
```

Snyk creates a snapshot of dependencies and vulnerabilities and imports them into the Snyk web UI. You can review the issues and view them in your reports.

Importing a Snyk Project with unmanaged dependencies creates a new Snyk Project on the **Projects** page:

<figure><img src="/files/ykGqDeVPFZBOqdJPdK9p" alt="Project with unmanaged dependencies"><figcaption><p>Project with unmanaged dependencies</p></figcaption></figure>

Use Snyk test APIs if you develop advanced dependency management strategies instead of using standard package managers.

For C++, if you know the open-source packages and versions included in the application but lack the source code, use the [List issues for a package](/developer-tools/snyk-api/reference/issues#orgs-org_id-packages-purl-issues) endpoint to analyze the application.


# COBOL

Snyk support for COBOL with Snyk Code, available in Early Access on Enterprise plans, including CICS frameworks and supported dialects

{% hint style="info" %}
COBOL is supported only for Snyk Code.
{% endhint %}

## COBOL for Snyk Code

{% hint style="info" %}
Code analysis support for COBOL is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

For an overview of the supported security rules, visit [COBOL rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules).

### Supported frameworks and libraries

For COBOL with Snyk Code, Snyk supports the CICS frameworks and libraries.

### Supported dialects and formats

* IBM Enterprise COBOL for z/OS (v4.2+)
* Micro Focus COBOL
* GNU COBOL
* OpenCOBOL
* ACUCOBOL-GT
* Fujitsu COBOL2000
* RM/COBOL

### Supported file formats

The following file formats are supported: `.cbl`, `.ccp`, `.cob`, `.cpy`.

### Available features

* Reports


# Dart and Flutter

Snyk support for Dart and Flutter with Snyk Code and Snyk Open Source, including Early Access code analysis on Enterprise plans

{% hint style="info" %}
Dart and Flutter is supported for Snyk Code and Snyk Open Source.
{% endhint %}

## Dart and Flutter for Snyk Code

{% hint style="info" %}
Code analysis support for Dart is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

For an overview of the supported security rules, visit [Dart and Flutter rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/dart-and-flutter-rules).

### Supported frameworks and libraries

For Dart and Flutter with Snyk Code, Snyk supports the following frameworks and libraries:

{% columns %}
{% column %}

* crypto
* encrypt
* uuid
* basic\_utils
* pointycastle
* cryptography
* sqflite
* sqlite3
* drift
* realm
* http
* dio
* cupertino\_http
* web\_socket\_channel
* web
  {% endcolumn %}

{% column %}

* cronet\_http
* flutter\_inappwebview
* webview\_flutter
* twilio\_flutter
* dart\_eval
* google\_sign\_in
* flutter\_facebook\_auth
* sign\_in\_with\_apple
* flutter\_appauth
* openid\_client
* firebase\_auth
* amplify\_flutter
* flutter\_stripe
* nfc\_manager
* mobile\_scanner
* flutter
  {% endcolumn %}
  {% endcolumns %}

### Supported file formats

The following file formats are supported: `.dart`

### Available features

* Reports
* Interfile analysis

## Dart and Flutter for Snyk Open Source

### Available features

* Test your app's SBOM and packages using `pkg:pub` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command
* Test & monitor your Flutter apps native platform dependencies using [`snyk test`](/developer-tools/snyk-cli/snyk-cli/commands/test) and [`snyk monitor`](/developer-tools/snyk-cli/snyk-cli/commands/monitor) commands

### Testing a Dart applications pub dependency tree

Activate the pub [`sbom`](https://pub.dev/packages/sbom) package & create a minimal `sbom.yaml` file in the root folder of the repository:

```
dart pub global activate sbom
cat << EOF > sbom.yaml
type: spdx
spdx:
  SPDXFormat: 'tagvalue'
EOF
```

Use the dart `sbom` command to create a SBOM file & test it using the [`sbom test`](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) command:

```
dart pub global run sbom
snyk sbom test --experimental --file sbom-pub.json
```

### Testing platform dependencies (iOS, macOS, Android) in Flutter apps

Flutter applications rely on native platform dependencies to handle lower-level tasks, such as analytics, hardware access, or integrating existing functionality. These dependencies can be added through pub packages to extend functionality or integrated directly into build systems like Gradle or Cocoapods.

Snyk’s regular open-source support can scan these packages; however, a complete app build is necessary to make them available in the repository and accessible to CLI tools.

You can start by building the application for all relevant platforms. This ensures that `pub` fetches all required packages, and the Flutter build system establishes the necessary links for the native build systems.

```
flutter build apk --debug
flutter build ios --debug --no-codesign
flutter build macos --debug
```

Next, run the `snyk monitor` command to scan for native dependencies:

```
snyk monitor --all-projects --exclude=example,.symlinks
```

The `--exclude` parameter removes duplicates and ignores example applications, which are part of the plugin source code but not included in regular application builds.

You are now able to view in the Snyk Web UI all native dependencies, including those introduced by third-party plugins.

<figure><img src="/files/od8YrLCb8177xCjFDhic" alt=""><figcaption><p>Snyk Project page showing dependencies in Flutter apps</p></figcaption></figure>


# Elixir

Snyk support for Elixir with Snyk Open Source, including CLI and IDE testing, the Mix and Hex package managers, and SBOM testing

{% hint style="info" %}
Elixir is supported only for Snyk Open Source.
{% endhint %}

Available integrations: CLI and IDE: test or monitor your app

## Technical specifications

* Supported package manager: [Mix](https://hexdocs.pm/mix/Mix.html) or [Hex](https://hex.pm/)
* Supported package registry: [hex.pm](https://hex.pm/)

## Available features

For Elixir, the following features are available:

* Reports
* Test your app's SBOM and packages using `pkg:hex` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command

{% hint style="info" %}
The **Snyk Fix PR** feature is not available for Elixir. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}

## CLI support for Elixir

{% hint style="info" %}
To scan your dependencies, you must first install Elixir and Mix. For details, [see the Elixir installation instructions](https://elixir-lang.org/install.html).
{% endhint %}

Snyk offers security scanning to test your Elixir Projects for vulnerabilities using the [CLI](/developer-tools/snyk-cli/snyk-cli).

Mix is a build tool that compiles, tests, and creates Elixir projects. Mix manages dependencies by integrating with the Hex package manager.

Snyk builds a dependency tree for your Project by analyzing your `mix.exs` and `mix.lock` files. The `mix.lock` file must be present and in sync with the `mix.exs` file. After Snyk builds the tree, Snyk uses the [vulnerability database](https://snyk.io/vuln) to find vulnerabilities in the packages anywhere in the dependency tree.

#### **Project naming**

Projects in the Snyk UI are named according to the `app` keyword from the `project/0` function exported by `Mix.Project` in the main `mix.exs` file.

To override the name, use the `--project-name` CLI option.

#### **Mix umbrella projects**

If you test a Mix umbrella project, Snyk detects that it is an umbrella project and includes all the child apps automatically.

Along with the main `mix.exs`, each app `mix.exs` appears as a separate Project in the Snyk UI, named according to the path to the app.

Snyk fully supports all `:hex` packages listed in the Mix project, including all their transitive dependencies and any vulnerabilities.

Hex support includes both Elixir and Erlang packages.

Snyk also has limited support for `:path`, `:git` and `:github` dependencies, but not their transitive dependencies or vulnerabilities.

* `:path` dependencies appear in the dependency tree by name
* `:git` and `:github` dependencies appear in the dependency tree by repository URL and version (either `:branch`, `:tag` or `:ref`, as defined in the `mix.exs` file)

{% hint style="info" %}
When using `asdf`, ensure you set a version by running the `asdf global elixir <version of your choice>`.
{% endhint %}


# Go

Snyk support for Go with Snyk Open Source and Snyk Code, including SCM import, CLI and IDE testing, and supported frameworks

## Applicability and integration

{% hint style="info" %}
Snyk for Go is supported for Snyk Open Source and Snyk Code.
{% endhint %}

Available integrations:

* SCM import
* CLI and IDE: test or monitor your app

## Technical specifications

### Supported frameworks and libraries

* Azure/azure-sdk-for-go/sdk/ai/azopenai
* gage-technologies/mistral-go
* Gin
* google/generative-ai-go/genai
* GORM library
* grpc-go
* labstack/echo
* lib/pq
* sashabaranov/go-openai
* spf13/pflag
* sqlx

### Supported package managers

For Go, Snyk supports [Go Modules](https://go.dev/ref/mod) and [dep](https://github.com/golang/dep) as package managers.

## Go for Snyk Code

For an overview of the supported security rules, visit [Go rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/go-rules).

For Go with Snyk Code, Snyk supports:

* Go Standard Library comprehensive as a library
* .`go` as a file format

Available features:

* Reports
* Interfile analysis

## Go for Snyk Open Source

### Available features

Available features for Go Projects with dependencies managed by Go Modules and dep:

* PR checks
* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:golang` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) command.

{% hint style="info" %}
If the **Snyk Fix PR** feature is enabled, this means that you will be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}

Snyk supports all versions of Go, including the latest stable version listed on the Go [All releases](https://go.dev/dl/) page.

Snyk tracks only official releases. Snyk does not identify commits, including those in the default branch, unless they are included in an official release or tag. For Projects with a package manager, Snyk requires a release to the package manager. For Go and unamanaged scans (C/C++), Snyk requires an official release or tag in the GitHub repository.

{% hint style="warning" %}
Since January 1, 2023, Snyk has not supported govendor Projects. As a general security best practice, Snyk recommends using tools that are consistently maintained and up-to-date.

Since Snyk no longer supports scanning of govendor Projects, a warning is issued and no results are provided.
{% endhint %}

### Support for Go Modules

{% hint style="info" %}
**Feature availability**\
Some features may not be available, depending on your plan. For more information, visit [Plans and pricing.](https://snyk.io/plans/)
{% endhint %}

#### CLI support for Go Modules

Snyk scans Go Modules Projects in the CLI at the package level rather than the module level, as Snyk has full access to your local source code.

Packages from the [Go standard library](https://pkg.go.dev/std) are supported and included in the dependency tree.

Packages under `golang.org/x/` that are [part of the Go Project](https://pkg.go.dev/golang.org/x) but outside the main Go tree are also supported.

To build the dependency tree for all third party packages, Snyk uses

* The `go list -json -deps ./...` command and the dependencies found in `Imports` .
* The `toolchain` directive in the `go.mod` file
* The `go version` command to determine the Golang version to apply to standard libraries.

{% hint style="info" %}
`TestImports` and `XTestImports` are not supported.
{% endhint %}

When you test Go Modules Projects using the CLI, Snyk does not require that their dependencies are installed, but you must have a `go.mod` file at the root of your Project. `go list` uses this and your Project source code to build a complete dependency tree.

Different versions of Go generate different results for the `go list -json -deps` command. This can affect the dependency tree and the vulnerabilities that the Snyk CLI finds.

#### SCM integrations for Go Modules

The source code management (SCM) integration resolves dependencies using one of two scopes, depending on your configuration:

* Standard SCM scan (default): resolves dependencies at the module level. Snyk parses the `go.mod` file using the `go mod graph` command, which maps the entire dependency tree regardless of whether the application code imports specific packages.
* Full source code analysis scan: resolves dependencies at the package level. When you enable this feature, Snyk clones the repository and runs the `go list -json -deps ./...` command. This forces the SCM integration to analyze active package imports and generate a dependency tree that aligns with the package-level baseline.

Because the default SCM integration evaluates the entire module graph using the `go mod graph` command, it reports a higher number of dependencies and vulnerabilities than the package-level baseline. This introduces vulnerabilities from unused or unimported packages within a module, resulting in findings that do not affect the compiled binary.

Enabling full source code analysis aligns the SCM integration with CLI resolution and eliminates findings from unimported code.

#### Enable full source code analysis

To build the most accurate dependency tree for Go modules Projects imported from SCM integrations, Snyk must access all files in your repository.

This allows Snyk to see the import statements in your `.go` source files and determine which specific packages your application uses. Without this access, Snyk includes all packages from the modules listed in your `go.mod` file.

To enable full source code analysis, adjust your settings as follows:

1. Log in to your account and select your Organization.
2. Navigate to **Settings** > **Snyk Open Source**.
3. Select **Edit settings** for **Go**.
4. Toggle **Enable full source code analysis** on or off.

<figure><img src="/files/q54H2IwwH0xuQK9tDp72" alt=""><figcaption><p>Enable full source code analysis</p></figcaption></figure>

For more details on levels of access to your repository required by different Snyk features, see [How Snyk handles your data](/snyk-data-and-governance/how-snyk-handles-your-data).

**Private modules**

Snyk supports Go modules Projects that rely on modules from private SCM repositories if those repositories are in the same SCM organization as the main Project repository.

Private module support for different SCMs varies based on whether you enable or disable full source code analysis.

| Full source code analysis enabled                                                                                                      | Full source code analysis disabled                                         |
| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- |
| <ul><li>Azure Repos</li><li>Bitbucket Cloud</li><li>Bitbucket Server</li><li>GitHub</li><li>GitLab</li><li>GitHub Enterprise</li></ul> | <ul><li>Bitbucket Cloud</li><li>GitHub</li><li>GitHub Enterprise</li></ul> |

**Private and Brokered package sources**

To give Snyk access to privately hosted Go modules, configure your private module sources in **Settings > Open Source > Go**. Configure them under one of the following:

* Brokered package sources: for Universal Broker connections that have been enabled for Open Source.
* Private package registries: for direct access.

#### Source requirements and routing

Snyk handles configuration requirements differently based on the source type and how Snyk accesses it.

For package registries or proxies (Artifactory, Nexus), Snyk always requires an explicit registry URL for both brokered and non-brokered setups. Snyk appends the URL to the `GOPROXY` chain so Go can resolve and fetch packages from your private registry. For example: `https://artifactory.example.com/artifactory/api/go/team-go`

For source control private dependencies, (GitHub and GitHub Enterprise, Bitbucket, GitLab, Azure Repos):

* Snyk only requires an explicit URL if you use a brokered connection. For non-brokered setups, Snyk relies natively on your existing SCM Organization permissions, and you do not need to configure a URL here.
* When you provide a URL for a brokered SCM, Snyk adds the host to `GONOSUMDB` so Go correctly tunnels traffic and skips the public checksum database. For example: `https://github.snyk-customer.com/owner/internal-shared-lib`

#### Configuration rules

The **Registry type** or **Source type** dropdowns only display options that have an active integration configured in your Organization and valid Universal Broker connections to SCM and package registries. The SCM integration must have permission to access the repositories containing the private Go modules.

Do not include credentials or authentication tokens within the URLs. You must configure credentials directly on the underlying SCM integration or the Universal Broker Client.

You can also view and configure these settings programmatically using the Snyk API, for both [brokered](https://apidocs.snyk.io/?version=2026-03-25#get-/orgs/-org_id-/settings/opensource/-ecosystem-/broker) and [direct](https://apidocs.snyk.io/?version=2026-03-25#get-/orgs/-org_id-/settings/opensource/-ecosystem-/private-registries) connections.

### Support for dep

#### CLI support for dep

To build the dependency tree, Snyk analyzes your `Gopkg.lock` files.

When you test dep Projects using the CLI, Snyk requires installation of dependencies. Run `dep ensure` to achieve this.

#### SCM integrations for dep

To build the dependency tree, Snyk analyzes the `Gopkg.lock` files in your SCM repository.


# Groovy

Snyk support for Groovy with Snyk Code, available in Early Access on Enterprise plans, including supported frameworks and libraries

## Groovy for Snyk Code

{% hint style="info" %}
Code analysis support for Groovy is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

For an overview of the supported security rules, visit [Groovy rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/groovy-rules).

### Supported frameworks and libraries

For Groovy, Snyk supports the following frameworks and libraries:

* Apache Camel
* groovy-cli-picollo
* Groovy standard library
* groovy-cli-commons
* Grails
* GDK
* Micronaut
* Play
* Spring

### Supported file extensions

For Groovy, Snyk supports the following file extensions:

* .groovy
* .grt
* .gtpl
* .gvy

### Available features

* Support for Interfile analysis
* Reports


# Java and Kotlin

Snyk support for Java and Kotlin with Snyk Code and Snyk Open Source, including SCM import, CLI and IDE testing, and Maven and Gradle

## Applicability and integration

{% hint style="info" %}
Java and Kotlin are supported for Snyk Code and Snyk Open Source.
{% endhint %}

Available integrations:

* SCM import
* CLI and IDE: test or monitor your app

{% hint style="info" %}
**Release status**

Improved Gradle SCM scanning is in Early Access. For more information, see [SCM integrations with Maven and Gradle](/supported-languages/supported-languages-list/java-and-kotlin/git-repositories-with-maven-and-gradle).
{% endhint %}

## Technical specifications

Snyk supports Java analysis for Java versions up to SE 21 and is designed to process code from newer Java versions where feasible.

### Supported frameworks and libraries

For Java and Kotlin, the following frameworks and libraries are supported:

{% columns %}
{% column %}

* Amazon AWS SDK
* Android Standard Library
* Apache Camel
* Apache Commons
* Apache Tomcat
* Apache XML
* apache.mahou
* bouncycastle
* com.azure.ai.openai
* com.google.ai.client.generativeai
* com.google.cloud.vertexai.generativeai
* com.google.re2j
* com.google.gwt
* Dropwizard
* elasticsearch
* FasterXML Jackson
* Google Guava
* grpc-java
* hibernate
* http4k
* io.jsonwebtoken
* Jakarta EE
* Jakarta XML Services
* Java EE
* Java Servlet
* Java Servlet (javax)
* Java Server Pages
* Java Standard Edition
* javalin
* Jax-RS
* jooq
  {% endcolumn %}

{% column %}

* Kyro
* Micronaut
* mongo-java-driver
* Netty
* okhttp3
* org.apache.hc.client5
* org.apache.http.client
* org.apache.sling
* org.apache.tools.zip
* org.codehaus.plexus
* org.dom4j.io
* Playframework
* rxhttp
* Seam logger
* SnakeYaml
* Spongycastle
* Spring AI
* Spring boot
* Spring Web, MVC and JDBC
* Spring WebFlux
* Struts
* Vaadin
* XStream

Kotlin only:

* Android Standard Library
* com.aallam.openai
* com.expediagroup.graphql.server
* Javalin
* Ktor
* Kotlin Standard Library
* khttp
  {% endcolumn %}
  {% endcolumns %}

### Supported package managers and package registries <a href="#supported-package-managers-and-package-registries" id="supported-package-managers-and-package-registries"></a>

* Supported package managers: [Maven](https://maven.apache.org) and [Gradle](https://gradle.org), with the following supported versions:
  * Maven: `3.*` , `4.*`. For more information, see the [Snyk Maven plugin readme](https://github.com/snyk/snyk-mvn-plugin#support).
  * Gradle: `4.*`, `5.*`, `6.*`, `7.*`, `8.*`, `9*`. For more information, see the [Snyk Gradle plugin readme](https://github.com/snyk/snyk-gradle-plugin#support).
* Supported package registry: [maven.org](https://maven.org/) (Maven Central Repository)

## Java and Kotlin for Snyk Code

For an overview of the supported security rules, visit [Java rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules) and [Kotlin rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/kotlin-rules).

For Java and Kotlin with Snyk Code, the following file formats are supported:

* For Java: `.java`, `.jsp`, `.jspx`
* For Kotlin: `.kt`

Available features:

* Reports
* Interfile analysis - Kotlin is fully supported
* Interfile analysis - Android is partially supported

## Java and Kotlin for Snyk Open Source

For Java and Kotlin with Snyk Open Source, the following file formats are supported:

* For Maven: `pom.xml`
* For Gradle: `build.gradle`, `build.gradle.kts`

Available features:

* Reports
* License scanning
* Fix PRs (for Gradle only Fix advice is available)
* Test your app's SBOM and packages using `pkg:maven` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command

## Validating, monitoring, alerting, and gating for Java and Kotlin

For SCM integrations, Snyk allows you to [run PR Checks](/scan-fix-and-prevent/prevent/pull-request-checks) to validate submitted changes to code and open source packages before merging. Snyk can also retest and alert on the default branch on a scheduled basis. You can see the results on the **Projects** page.

For CI/CD integrations, Snyk can passively monitor and provide a QA gate by failing build checks during testing for policy violations.

Snyk provides flexible capabilities, including:

* [Gradle Plugins](https://snyk.io/blog/gradle-plugin-by-snyk-gradle-dependencies-scanning/) (Community project)
* [Maven Plugins](https://snyk.io/blog/snyk-maven-plugin-integrated-security-vulnerability-scanning-for-developers/)
* Dedicated plugins for Jenkins, Circle CI, and others (see relevant marketplaces)
* Using [Github Actions](https://snyk.io/blog/building-a-secure-pipeline-with-github-actions/)
* The Snyk CLI can be used in most CI/CD systems (see [examples](https://github.com/snyk-labs/snyk-cicd-integration-examples))
  * Fail the build based on criteria using options or the [snyk-filter](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter) tool
  * There are [containerized](https://hub.docker.com/r/snyk/snyk) versions available
* With Partner Platforms: Azure, Bitbucket, and AWS have built-in pipes/components for use with Snyk. For Java, Snyk suggests using the SCM integration with Bitbucket Cloud or using the CLI instead of the prepackaged Bitbucket Pipe.

Snyk can monitor container images and their open source or Linux-based packages being used in production using Kubernetes integration, to notify customers of known vulnerabilities for applications in production. This feature is available for Enterprise plans only.

Where a production integration does not exist, use the [snyk monitor](/developer-tools/snyk-cli/snyk-cli/commands/monitor) CLI command to take a snapshot and monitor what is being pushed to production (available for all plans).

## Java support for BOM

Maven supports [bill of materials (BOM) POM files](https://maven.apache.org/guides/introduction/introduction-to-dependency-mechanism.html#bill-of-materials-bom-poms) to centralize dependency versions known to work together.

A BOM file includes:

* a `pom` packaging type: `<packaging>pom</packaging>`.
* a `dependencyManagement` section.

Third-party Projects can provide BOM files to simplify dependency management. Here are some common examples:

* [spring-data-bom](https://github.com/spring-projects/spring-data-bom) - The Spring team provides a BOM for their Spring Data Project.
* [jackson-bom](https://github.com/FasterXML/jackson-bom) - The Jackson Project provides a BOM for Jackson dependencies.

Example of a BOM file:

{% code title="Example 1 - BOM file" %}

```xml
<project ...>
    <modelVersion>4.0.0</modelVersion>
    <groupId>snyk</groupId>
    <artifactId>snyk-bom</artifactId>
    <version>1.0</version>
    <packaging>pom</packaging>
    <name>Snyk Bill Of Materials</name>
    
    <dependencyManagement>
        <dependencies>
            <dependency>
                <groupId>log4j</groupId>
                <artifactId>log4j</artifactId>
                <version>1.2.12</version>
            </dependency>
            <dependency>
                <groupId>commons-logging</groupId>
                <artifactId>commons-logging</artifactId>
                <version>1.1.1</version>
            </dependency>
        </dependencies>
    </dependencyManagement>
</project>
```

{% endcode %}

The `dependencyManagement` section contains dependency elements. Each dependency is a lookup reference for Maven to determine the version to select for transitive (and direct) dependencies.

Defining a dependency in the `dependencyManagement` section is used only for lookup reference, it does not add it to the dependency tree of the Project.

You can run `mvn dependency:tree` on the previous BOM example to show that Maven does not treat the contents as dependencies of the file itself.

This BOM can be imported into a Project POM as a parent. You do not need to specify the `log4j` version, as it inherits it from the BOM:

{% code title="Example 2 - Project POM" %}

```xml
<project ...>
    <modelVersion>4.0.0</modelVersion>
    <parent>
        <groupId>snyk</groupId>
        <artifactId>snyk-bom</artifactId>
        <version>1.0</version>
    </parent>
    
    <groupId>snyk</groupId>
    <artifactId>snyk-project</artifactId>
    <version>1.0.0-SNAPSHOT</version>
    <packaging>jar</packaging>
    <name>Snyk Project</name>
    <dependencies>
        <dependency>
            <groupId>log4j</groupId>
            <artifactId>log4j</artifactId>
        </dependency>
     </dependencies>
</project>
```

{% endcode %}

Snyk applies the versions in the BOM `dependencyManagement` lookup to any dependencies declared in Project POMs that import it as a `parent`.

When Snyk scans the BOM files, the `dependencyManagement` contents are not considered dependencies of that file. These are only lookups.

For the previous examples, Snyk analyzes and treats the files as follows:

* BOM file - Snyk does not create a Snyk Project for this file because it has no dependencies.
* Project POM - Snyk creates a Project with a single dependency, `log4j,` with `v1.2.12`. Snyk applies the rules from the parent BOM to identify the correct version for `log4j`. The dependency `commons-logging` is not included, as it is not directly declared in the Project POM.

{% hint style="info" %}
This example uses `log4j 1.x` to demonstrate BOM version inheritance. log4j 1.x is end-of-life and has known vulnerabilities, so Snyk does not recommend using it.
{% endhint %}

{% hint style="info" %}
If a BOM has direct dependencies outside `dependencyManagement`, then Snyk creates a Project for that BOM.
{% endhint %}

Snyk also offers fix advice, including recommendations to upgrade vulnerable packages through the [Fix PR feature](/scan-fix-and-prevent/fix/pull-requests#snyk-fix-prs).

Fix PRs can only be created for dependencies whose versions are managed in the POM file where the issue is reported.

If the version or dependency is managed in a parent BOM, then even though Snyk sees that it could fix the vulnerable path by changing the version, it cannot apply the fix.

See additional resources for Java developers on security topics and best practices:

* [Snyk Blog](https://snyk.io/blog/)
* [Securing your modern software supply chain](https://snyk.io/blog/software-supply-chain-security/)
* [Snyk for secure Java development](https://snyk.io/blog/snyk-for-secure-java-development/)
* [Advanced IntelliJ debugger features](https://snyk.io/blog/advanced-intellij-debugger-features/)
* [Spring4shell: the zero day RCE Spring Framework explained](https://snyk.io/blog/spring4shell-zero-day-rce-spring-framework-explained/)
* [Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17.1](https://snyk.io/blog/log4j-rce-log4shell-vulnerability-cve-2021-44228/)
* [Best practices for managing Java dependencies](https://snyk.io/blog/best-practices-for-managing-java-dependencies/)
* [Exploring the Spring security authorization bypass (CVE-2022-31692)](https://snyk.io/blog/spring-security-authorization-bypass-cve-2022-31692/)


# CLI support for Java and Kotlin

How to test Maven and Gradle Projects for Java and Kotlin with the Snyk CLI, including supported manifest files

To test Maven and Gradle Projects, use the `snyk test` command as follows:

* Snyk CLI with Gradle: to build the dependency graph, Snyk integrates with Gradle and inspects the dependencies reported by the tool. The following manifest files are supported: `build.gradle` (Groovy DSL) and `build.gradle.kts` (Kotlin DSL).
* Snyk CLI with Maven: to build the dependency tree, Snyk integrates with Maven and inspects the dependencies reported by the tool. The following manifest files are supported: `pom.xml`.

| Package manager-environment | Test help                                                                                                                                                                                                                                                                                                                                                                                                                                 | Monitor help                                                                                                                                                                                                                                                                                                                                                                                                                               |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Maven                       | <p><code>--maven-aggregate-project</code><br><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#options-for-maven-projects">Options for Maven Projects</a>.<br><br>Example for aggregate projects:<br><code>snyk test --maven-aggregate-project</code></p><p>Ensure you execute the options in the same directory as the root pom.xml file.</p>                                                                             | <p><code>--maven-aggregate-project</code><br><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN#options-for-maven-projects">Options for Maven Projects</a>.<br><br>Example for aggregate projects:<br><code>snyk monitor --maven-aggregate-project</code></p><p>Ensure you execute the options in the same directory as the root pom.xml file.</p>                                                                           |
| Gradle                      | <p><code>--init-script=\<FILE></code> - Used for projects with a Gradle initialization script.</p><p><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#options-for-gradle-projects">Options for Gradle Projects</a>.</p>                                                                                                                                                                                                   | <p><code>--init-script=\<FILE></code> - Used for projects with a Gradle initialization script.<br><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN#options-for-gradle-projects">Options for Gradle Projects</a>.</p>                                                                                                                                                                                                       |
| Build tools                 | <p><code>snyk test -- \[\<context-specific\_options>]</code></p><p>See <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#options-for-build-tools">Options for build tools</a>.</p>                                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Unmanaged JAR files         | <p><code>--scan-unmanaged</code> - Tests unmanaged files<br></p><p><code>--scan-unmanaged --file=\<JAR\_FILE\_NAME></code> - Tests individual JAR, WAR, and AAR files<br></p><p><code>--scan-all-unmanaged</code> - Auto-detects Maven, JAR, WAR, and AAR files recursively from the current folder.<br>See <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#scan-all-unmanaged">Options for unmanaged JAR files</a>.</p> | <p><code>--scan-unmanaged</code> - Tests unmanagedfiles<br></p><p><code>--scan-unmanaged --file=\<JAR\_FILE\_NAME></code> - Testsindividual JAR, WAR, and AAR files<br></p><p><code>--scan-all-unmanaged</code> - Auto-detects Maven, JAR, WAR, and AAR files recursively from the current folder.</p><p>See <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN#scan-all-unmanaged">Options for unmanaged JAR files</a>.</p> |

## CLI help for Maven Projects

A Maven aggregate Project is one that uses modules and inheritance. When scanning these types of Projects, Snyk performs a compile to ensure all modules are fixable by the Maven reactor.

To scan aggregate Projects, use the `--maven-aggregate-project` option:

```
snyk test --maven-aggregate-project
```

To scan non-aggregate Projects, use the `--all-projects` option:

```
snyk test --all-projects
```

You can use the same options with `snyk monitor`.

The following example outlines how Maven-specific options are used with the Snyk CLI.

1. Test a specific Maven profile called “prod”.

```
snyk test -- -prod
```

2. Add a system property from your pom.xml file, for example, the package version that appears in your pom.xml:

```
${pkg_version}
```

3. Define the system property:

```
snyk test -- -Dpkg_version=1.4
```

## CLI help for Gradle Projects

Gradle build can consist of several sub-projects, where each sub-project has its own build.gradle, while the root Project is the only one that also includes a `settings.gradle` file. Sub-projects depend on the root ProjectProjects but can be configured otherwise.

By default, Snyk CLI scans only the current Project, the Project in the root of the current folder, or the Project that is specified by `--file=path/to/build.gradle`).

To scan all Projects at once (recommended), use the `--all-sub-projects` option:

```
snyk test --all-sub-projects
```

Each of the individual sub-projects appears as a separate Snyk Project in the eb UI.

To scan a specific Project (for example, "myapp"), use the following command:

```
snyk test --sub-project=myapp
```

### Gradle configurations

Gradle dependencies are declared for a particular scope. Each scope is represented by Gradle with the help of [Configurations](https://docs.gradle.org/current/userguide/declaring_dependencies.html#sec:what-are-dependency-configurations). For example:

* `implementation`: configuration for dependencies required at compile time and runtime, but not exposed to consumers.
* `api`: configuration for dependencies required at compile time and runtime, and exposed to consumers.
* `compileOnly`: configuration for dependencies required only at compile time.
* `runtimeOnly`: configuration for dependencies required only at runtime.
* `compileClasspath`: configuration for dependencies required at compile time.

In most cases, Snyk includes all the dependencies in the `compileClasspath` configuration, but this can vary in some circumstances.

To test a specific configuration:

* Use the `--configuration-matching` option with a Java regular expression (case-insensitive) as its parameter. The CLI identifies all resolvable configurations that match the regex and aggregates their dependencies into a single scan result. If you require separate reports for different configurations (for example, compile vs. runtime), run the command separately for each.
* If the different sub-projects include different configurations, scan each sub-project separately.

Examples of how you can use the `--configuration-matching` option:

* `--configuration-matching=compile` to match `compile`, `testCompile`, `compileOnly`, and so on.
* `--configuration-matching=^compile$` to match only `compile`.
* `--configuration-matching='^(debug|release)compile$'` to match `debugCompile` and `releaseCompile`.
* `--configuration-matching='^(?!test).*$'` to match all configurations except those starting with "test" (for example, excludes `testCompileClasspath`, `testRuntimeClasspath`). This is recommended for with large dependency graphs that hit max path limits, as excluding test configurations reduces the graph size while still covering production dependencies.

### Android build variants

Android Gradle supports creating different versions of your app by configuring [build variants.](https://developer.android.com/studio/build/build-variants)

Because the Snyk default behavior is to merge all available configurations, the iterated variants cause a clash of configurations that can't be merged.

In these situations, the Snyk scan fails with an error from Gradle which may contain one of the following messages:

* Cannot choose between the following configurations of `project :mymodulewithvariants`
* Cannot choose between the following variants of `project :mymodulewithvariants`
* Could not select value from candidates

To avoid such conflicts:

* Use a specific configuration(s): if you know of a build configuration that has all the required attributes and the configuration is identical across all sub-projects included in the test, specify that configuration.\
  For example:

  ```
  --configuration-matching=prodReleaseRuntimeClasspath
  ```
* Explicitly specify the dependency configuration: modify intra-project dependencies in your build.gradle file(s) to use a specific configuration

  ```
    dependencies {
        implementation project(path: ':mymodulewithvariants', configuration: 'default')
    }
  ```
* Suggest configuration attributes: if you receive an error when running the command, the error can indicate which attribute values are available, while the error details from Gradle also indicate which dependency variants match which attributes. Using these details, add the attribute filter option.\
  For example:

  ```
  snyk test --configuration-attributes=buildtype:release,usage:java-runtime,mode:demo
  ```

  matches the variants using `com.android.build.api.attributes.BuildTypeAttr=release` and `org.gradle.usage=java-runtime`

### Daemon

By default, Snyk passes `gradle build --no-daemon` in the background when running `snyk test` and `snyk monitor` on Windows.

If you see `snyk test` or `snyk monitor` fail on other operating systems because of daemon-related issues, try adding the `--no-daemon` flag to the Snyk command or set `GRADLE_OPTS: '-Dorg.gradle.daemon=false'`.

For tips on disabling the daemon, the [Gradle documentation](https://docs.gradle.org/current/userguide/gradle_daemon.html#sec:disabling_the_daemon).

### Lockfiles

If your Gradle Project uses a single `gradle.lockfile` or multiple `*.lockfile` per configuration, the following issue can appear:

{% code overflow="wrap" %}

```
Gradle Error (short): > Could not resolve all dependencies for configuration ':compileOnly'. > Locking strict mode: Configuration ':compileOnly' is locked but does not have lock state.
```

{% endcode %}

The **compileOnly** configuration has been deprecated, and even if your Project successfully generates a lockfile, the `compileOnly` state is not included because this configuration cannot be resolved.

Only resolvable configurations compute a dependency graph. To solve this issue, Snyk suggests you update your `build.gradle` containing `dependencyLocking` logic with the following instruction:

```
compileOnly {resolutionStrategy.deactivateDependencyLocking() }
```

This ignores the `compileOnly` and saves only the necessary information to analyze your Project.

If you have trouble testing your Gradle Projects with Snyk, contact Snyk support and provide the following details:

* `build.gradle`
* `settings.gradle` (especially if Snyk did not pick up a version of a package)
* The output from the following commands:
  * `$ snyk test -d`
  * `$ gradle dependencies -q`

## Workaround for `ant` and `ivy`

[Apache Ant](https://ant.apache.org/) is a Java build system focused solely on executing build tasks defined in XML. [Apache Ivy](https://ant.apache.org/ivy/) extends Ant by adding dependency management, handling library retrieval and transitive dependencies, which Ant alone does not manage.

Ivy dependencies are configured in an XML file, for example `ivy.xml`:

```xml
<ivy-module version="2.0">
    <info organisation="com.example" module="my-project" revision="1.0"/>

    <dependencies>
        <dependency org="junit" name="junit" rev="4.12" conf="default"/>
    </dependencies>
</ivy-module>
```

Such a dependency file is typically evaluated using an `ant` task defined in `build.xml`:

```xml
<target name="resolve-dependencies" depends="init">
    <ivy:retrieve pattern="${lib.dir}/[artifact]-[revision].[ext]"/>
</target>
```

Using the command `ant resolve-dependencies`, dependencies will be downloaded from Maven Central, just like regular Maven dependencies.

To let Snyk know about the dependency tree, you must first convert to the Maven POM format. Start by configuring a new `makepom` task in `build.xml`

```xml
<target name="makepom" depends="resolve-dependencies">
    <ivy:makepom ivyfile="${basedir}/ivy.xml" pomfile="${basedir}/pom.xml" conf="default,runtime">
        <mapping conf="default" scope="compile"/>
        <mapping conf="runtime" scope="runtime"/>
    </ivy:makepom>
</target>
```

With this, you can now run the following commands:

```
ant makepom
snyk test --file=pom.xml
```

The `pom.xml` file does not need to be checked in and can be deleted after a test is done using `snyk`. Additionally, the dependency tree can be monitored using:

```
snyk monitor --file=pom.xml
```

## Snyk CLI tips and tricks

the [CLI commands and options summary](/developer-tools/snyk-cli/snyk-cli/cli-commands-and-options-summary) and the [CLI cheat sheet](https://snyk.io/blog/snyk-cli-cheat-sheet/). Use the `--help` option in the CLI for details of Snyk CLI commands.

### Testing your own code

* Use the `snyk code test` command from the root of the project to perform source code analysis.
* Use `--scan-all-unmanaged --all-projects` to recursively find all jars under the present working directory.

### Testing Open Source libraries

#### Maven

The `snyk test` command tests the first manifest it can find, and scans that singular entry point. To scan all manifests, follow these instructions:

* To scan aggregate projects, use the `--maven-aggregate-project` option\
  (for example, `snyk test --maven-aggregate-project`)
* To scan for all projects use `--all-projects` option:\
  (that is, `snyk test --all-projects`)

Snyk scans active profiles activated by default.

* Any additional Maven arguments can be passed, a common one is a non-standard settings.xml location. For example, `snyk test -- -s path/to/settings.xml`
* To scan a specific configuration, test a specific Maven profile using `-P [name]`. For example, use `snyk test -- -P prod` to scan the `prod` configuration.

#### Gradle

By default, Snyk CLI scans only the current project (the project in the root of the current folder), or the project that is specified by `--file=path/to/build.gradle`.

`--all-projects` can be used across all package managers, which also includes the behaviors of `--all-sub-projects`, mentioned below.

* To scan all projects at once (recommended), use the `--all-sub-projects` option:\
  (that is, `snyk test --all-sub-projects`). Each of the individual sub-projects appears as a separate Snyk Project in the eb UI.
* To scan a specific project (for example, myapp), use `--sub-project=` (that is, `snyk test --sub-project=myapp`).

specific configurations, [Snyk for Java and Kotlin](/supported-languages/supported-languages-list/java-and-kotlin).

#### Unmanaged

For more details on unmanaged Jars, [Scan all unmanaged JAR files](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/scan-all-unmanaged-jar-files).

### Testing containers

Snyk automatically looks for application (such as open source, maven, and npm) vulnerabilities as part of a container scan. Snyk recommends integrating via CLI or Registry earlier in the pipeline and use this as an additional signal or insight into what is in production. [Snyk CLI for container security](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-container).

To test Infrastructure as Code, [Infrastructure as Code security](https://snyk.io/product/infrastructure-as-code-security/).

To fix vulnerabilities, [Fixing vulnerabilities on Maven projects](https://snyk.io/blog/fixing-vulnerabilities-in-maven-projects/).

### Options and plugins

To help generate reports locally or at build time, [snyk-to-html plugin](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-to-html).

See `--json` and `--sarif` options for generating output that can be programmatically accessed.

For advanced filtering options, [snyk-filter](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter).


# SCM integrations with Maven and Gradle

How Snyk scans Maven and Gradle applications through SCM integrations, including dependency trees and supported scopes

## Available SCM integrations

### Maven

When scanning Maven applications, Snyk creates a Project per `pom.xml` file. The Project includes all direct and indirect dependencies associated with that file.

The Project includes only the production dependencies in the `compile`, `provided`, and `runtime` scopes.

For Maven, Snyk can generate a dependency tree from POM through the SCM integration or the CLI:

* Locally and using CI/CD: Snyk interacts with the package manager to produce a list of dependencies.
* SCM integration: Snyk approximates the build as if it were built at that time.

{% hint style="info" %}
Developer dependencies (`scope=test`) are ignored as they are not pushed to production and are generally considered noise. You can enable them in CLI by adding `--dev`.

Because Maven resolves dependencies in the order it encounters them in the POM file, it is important that dev dependencies are listed last in the POM file. Not doing so can lead to dev dependencies being reported by Snyk.
{% endhint %}

### Gradle

For Gradle, Snyk interacts with the package manager to produce a list of dependencies. Typically Gradle executes code and other actions during the build process that impacts the installed dependencies, so Snyk recommends using the CLI if a gradle.lockfile is not present.

For Gradle, after you select a Project for import, Snyk builds the dependency tree based on the `build.gradle` file and (optional) `gradle.lockfile`.

Only production dependencies in the `api`, `compile`, `classpath`, `implementation`, `runtime` and `runtimeOnly` configurations are included.

If possible, enable [Gradle lockfiles](https://docs.gradle.org/current/userguide/dependency_locking.html) in your application. When present, Snyk can more accurately resolve the final version of dependencies used in the Project.

For Kotlin, the following manifest files are supported:

* build.gradle (Groovy DSL) for both SCM and CLI
* build.gradle.kts (Kotlin DSL) for CLI only

## **Maven and Gradle Projects using gradle.lockfile**

If you are using Maven or Gradle with a gradle.lockfile, the Git code repository integration is an efficient way to use Snyk and get visibility or you can use CLI/IDE or CI/CD integrations to test, gate, and, or monitor.

Typically you can instrument testing as part of a build system or adopt a lockfile as part of their process.

* It is quite common for large organizations to monitor applications via Git integration, to begin with, daily monitoring, turning on PR checks for only key applications at the start.
* As developers become familiar with Snyk capabilities, they widen the scope of applications with PR checks for gating.
* Use CI/CD to passively monitor and then turn on gating by using the [snyk \[product\] test and monitor commands](/developer-tools/integrations/snyk-ci-cd-integrations/snyk-ci-cd-integration-deployment-and-strategies/snyk-test-and-snyk-monitor-in-ci-cd-integration).

## Gradle Projects without a lock file

If you're using Gradle without a Gradle.lockfile, it is possible that the full dependency tree is not apparent or artifacts are pulled in from external resources. Snyk recommends to:

* Use the CLI/IDE workflow for local scans
* Use CI/CD to passively monitor and then turn on gating by using the [`snyk [product] test` and `monitor` commands](/developer-tools/integrations/snyk-ci-cd-integrations/snyk-ci-cd-integration-deployment-and-strategies/snyk-test-and-snyk-monitor-in-ci-cd-integration).
* Start with turning on gating and failing the build on one Project, so developers get familiar with the process and then use passive monitoring for the remainder of the portfolio.

## Improved Gradle SCM scanning

{% hint style="info" %}
**Release status**

Improved Gradle SCM scanning is in Early Access. You can enable the feature by using [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

### Supported Gradle features

* [Groovy](https://docs.gradle.org/current/userguide/groovy_build_script_primer.html) and [Kotlin](https://docs.gradle.org/current/userguide/kotlin_dsl.html) DSLs - `build.gradle(.kts)` and `settings.gradle(.kts)`
* [Built-in](https://docs.gradle.org/current/userguide/declaring_repositories.html#sec:declaring_public_repository) and [custom](https://docs.gradle.org/current/userguide/declaring_repositories.html#sec:declaring_custom_repository) package repositories, for example, Artifactory, Nexus
* Built-in objects [`ext`](https://docs.gradle.org/current/dsl/org.gradle.api.plugins.ExtraPropertiesExtension.html), [`project`](https://docs.gradle.org/current/dsl/org.gradle.api.Project.html), `rootProject`, and [`settings`](https://docs.gradle.org/current/dsl/org.gradle.api.initialization.Settings.html)
* Local and global variables, maps, and string interpolation
* `allprojects` and `subprojects` blocks
* Custom files referenced using `apply from`
* [Type-safe project accessors](https://docs.gradle.org/current/userguide/declaring_dependencies_basics.html#sec:type-safe-project-accessors)
* Gradle [lockfiles](https://docs.gradle.org/current/userguide/dependency_locking.html)
* [Gradle properties and system properties](https://docs.gradle.org/current/userguide/build_environment.html#sec:gradle_system_properties) - `gradle.properties`
* [Dependency exclusions](https://docs.gradle.org/current/userguide/dependency_downgrade_and_exclude.html#sec:excluding-transitive-deps)
* Version catalogs declared in [Gradle](https://docs.gradle.org/current/userguide/platforms.html#sub:version-catalog-declaration) and [TOML](https://docs.gradle.org/current/userguide/platforms.html#sub::toml-dependencies-format) files - `gradle/libs.versions.toml`
* [Multi-project builds](https://docs.gradle.org/current/userguide/declaring_dependencies_between_subprojects.html), project names, project references
* [Spring's `mavenBom`](https://docs.spring.io/dependency-management-plugin/docs/current/reference/html/#dependency-management-configuration-bom-import)
* [Spring Boot plugin BOMs](https://docs.spring.io/spring-boot/gradle-plugin/managing-dependencies.html)
* Maven BOMs as [`platform`](https://docs.gradle.org/current/userguide/platforms.html#sub:using-platform-to-control-transitive-deps) dependencies

The following Gradle features are not supported:

* Custom configuration in [buildSrc](https://docs.gradle.org/current/userguide/organizing_gradle_projects.html#sec:build_sources) directories
* Dependencies introduced via [plugins](https://docs.gradle.org/current/userguide/plugins.html).

### Enable improved Gradle SCM scanning

{% hint style="warning" %}
Improved Gradle SCM scanning supports importing a maximum limit of 5,000 `build.gradle(.kts)` files per SCM repository. Attempts to import repos with more than 5,000 Gradle build files will fail.
{% endhint %}

To enable this feature, follow these steps for your Snyk Organization:

1. Configure [package repository integrations](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations) (if you use Artifactory or Nexus, see [below](#package-repository-integrations)).
2. Enable [Workspaces for SCM integrations](/developer-tools/integrations/scm-integrations/workspaces).
3. Enable **Improved Gradle scanning** in Snyk Preview.

After Improved Gradle SCM scanning is enabled:

* The SCM repositories that have been previously imported have existing Gradle Groovy DSL Projects automatically updated on the next manual or recurring test.
* Re-import the repository to start seeing results for Gradle Kotlin DSL Projects.

## Package repository integrations

If your application build uses private package repositories, you must configure the relevant Snyk integration to get the most accurate results.

To use package repository integrations with the Improved Gradle scanning feature, use the configuration instructions and settings for Maven. These will be detected and used in improved Gradle scans.

In the Java language settings, you can integrate Snyk with your private package repositories (for example, Artifactory or Nexus). This enables Snyk to build a complete dependency tree when scanning Maven or Gradle Projects that reference private packages.

## Package registry integrations (Artifactory/Nexus) - Maven

{% hint style="info" %}
Artifactory and Nexus package registry integrations are available only with Snyk Enterprise plans.
{% endhint %}

Snyk Open Source uses Artifactory or Nexus to resolve transitive dependencies through private packages.

Snyk can be connected to a publicly available instance using username and password or a private server on your network using the Snyk Broker.

Snyk Open Source provides integrations with Artifactory and Nexus, both as local gatekeepers and interacting with the registry for security testing. See [Nexus Repository Manager setup](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/nexus-repository-manager-connection-setup) and [Artifactory Registry setup](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/artifactory-package-repository-connection-setup).

{% hint style="info" %}
For users who do not have a Snyk Enterprise integration with Artifactory or Nexus, Snyk recommends using the CLI, as it works with the dependencies that your build system makes available locally.
{% endhint %}

For more information on package registry integrations, including Maven, see the following external resources:

* Package registry integrations: [Nexus Repository Manager setup](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/nexus-repository-manager-connection-setup) and [Artifactory Registry setup](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/artifactory-package-repository-connection-setup)
* [Artifactory Registry for Maven](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/artifactory-package-repository-connection-setup/artifactory-registry-for-maven)
* [Nexus Registry for Maven](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/nexus-repository-manager-connection-setup/nexus-repository-manager-for-maven)
* Nexus Container Registry: [Container security with Nexus integration](/scan-fix-and-prevent/scan-with-snyk/snyk-container/container-registry-integrations/integrate-with-nexus-container-registry)
* Gatekeeper plugins: Artifactory Gatekeeper plugin

## Configure language settings for Snyk for Java

You can configure language settings for your open source libraries and licensing at the Organization level. The configuration settings apply to all Projects in that Organization. To configure:

1. In the Snyk Web UI, navigate to **Settings** > **Snyk Open Source** > **Languages** > **Java.**
2. Click **Edit settings.**
3. Configure the settings for **Maven**.
4. Click **Update Settings** to save changes.

## **APIs**

Customers develop advanced dependency management strategies and can choose not to use the standard and frequently used package managers.

For on-time testing using the Snyk API, you can use the [Test](/developer-tools/snyk-api/reference/test-v1) endpoints. Examples include [Test for issues in a (Maven) public package by group id, artifact id and version](/developer-tools/snyk-api/reference/test-v1#test-maven-groupid-artifactid-version) and [List issues for a package](/developer-tools/snyk-api/reference/issues#orgs-org_id-packages-purl-issues).


# JavaScript

Snyk support for JavaScript with Snyk Code and Snyk Open Source, including supported frameworks, libraries, and package managers

{% hint style="info" %}
JavaScript is supported for Snyk Code and Snyk Open Source.
{% endhint %}

## JavaScript for Snyk Code

For an overview of the supported security rules, visit [JavaScript and TypeScript rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/javascript-and-typescript-rules).

### Supported frameworks and libraries

The following frameworks and libraries are supported:

{% columns %}
{% column %}

* @Google Drive/generative-ai
* @anthropic-ai/sdk
* @huggingface/inference
* @mistralai/mistralai
* axios
* Angular
* apollo-server
* bcrypt-nodejs
* cross-spawn
* crypto-js
* date-fns
* dayjs
* dompurify
* electron
* ejs
* execa
* express
* express-mongo-sanitize
* express-graphql
* express-jwt
* fastMCP
* fs
* fs-extra
* fs-plus
* graceful-fs
* graphql-js
* grpc-js
* hapi.js
* jQuery
* js-yaml
* jzip
* koa
* koa-graphql
* libxml
* libxmljs
* lodash
* luxon
* minimongo
  {% endcolumn %}

{% column %}

* minimist
* modelcontextprotocol/typescript-sdk
* mongodb
* Mongoose
* mercurius
* Nestjs
* Node Crypto
* node-buffer
* node-cmd
* Node Crypto
* node-dir
* node-forge
* node-pty
* node-serialize
* octokit
* openai
* pg
* pg-promise
* React - Partial
* request-promise
* restler
* rimraf
* sanitize-html
* shelljs
* Stanford JS Crypto
* superagent
* tar-stream
* TSOA
* unirest
* unzip
* underscore
* url
* vm
* webstomp-client
* WebCryptoAPI
* xpath
* yargs
  {% endcolumn %}
  {% endcolumns %}

### Supported file formats

The following file formats are supported: `.ejs`, `.es`, `.es6`, `.htm`, `.html`, `.js`, `.jsx`, `.ts`, `.cts`, `.mts`, `.tsx`, `.vue`, `.mjs`, `.cjs`, `.erb` .

### Available features

* Reports
* Interfile analysis

## JavaScript for Snyk Open Source

### Supported package managers and package registries

Snyk supports the following package managers and versions:

* npm: `npm 5`, `npm 6`, `npm 7`, `npm 8`, `npm 9`, `npm 10+`

  Supported Lockfile versions: `Lockfile v1`, `Lockfile v2`, `Lockfile v3`
* pnpm: `pnpm 7`, `pnpm 8`, `pnpm 9`, `pnpm 10`
* Yarn: `Yarn 1`, `Yarn 2`, `Yarn 3`, `Yarn 4`

Snyk's default package registry is [npmjs.org](https://www.npmjs.org/). Private package registries are supported. For more information, visit [Package repository integrations.](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations)

### Available integrations

* SCM import
* CLI and IDE: test or monitor your app

### Supported file formats

The following file formats are supported:

* For npm: `package.json` and `package-lock.json`
* For pnpm: `pnpm-lock.yaml`
* For yarn: `yarn.lock`

Lerna is partially supported.

### Available features

* Automatic and manual Fix PRs (for npm, pnpm, and Yarn)
* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:npm` PURLs, using [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) command.

### Language and package manager considerations

{% hint style="info" %}
Only official releases are tracked. Commits, including into the default branch, are not identified unless included in an official release or tag.

In the case of JavaScript packages this means a release to the npmjs.org package registry.
{% endhint %}

#### devDependencies analysis

`devDependencies` analysis is disabled by default as these are not typically elevated to production, often seen as “noise” by both security and development. To enable testing on dev-dependencies:

* Use the `--dev` parameter for CLI and CI/CD integrations.
* For SCM integrations, set using **Settings** > **Languages** in the relevant configuration item.

#### optionalDependencies analysis

optionalDependencies are included by default for CLI and CI/CD, as well as SCM integrations.

#### Unmanaged JavaScript

If you are on the Enterprise plan and thus have access to the Snyk API, can use the API to get a full list of dependencies and their transitive dependencies.

To test for vulnerabilities, you can use the following API endpoints:

* [Test for issues in a public package by name and version](/developer-tools/snyk-api/reference/test-v1#test-npm-packagename-version)
* [Test Dep Graph](/developer-tools/snyk-api/reference/test-v1#test-dep-graph)
* [List issues for a package](/developer-tools/snyk-api/reference/issues#orgs-org_id-packages-purl-issues)

#### Out of sync lockfiles

Control behavior when the lockfile and package file are in sync can be done using:

* CLI additional values: `--strict-out-of-sync`, `--fail-on`
* Web UI for SCM scans: **Settings** > **Language** > **JavaScript**

### Support for npm

For all supported lockfile versions, the following features are available:

* CLI support
* SCM support
* License scanning
* Automatic and Manual Fix PRs

Snyk can build a dependency tree with or without a lockfile. If a lockfile is present, Snyk uses it as follows:

* Locally and with CI/CD: if a lockfile is not present and the scan is performed with the CLI or an IDE, Snyk looks at `node_modules` to determine what is installed.
* With SCM integrations: if a lockfile is not present, Snyk approximates what the tree will look like at build time. This is highly valuable for getting insights into Projects in development or what the next build will look like when there is no lockfile present

As a user of npm, even though npm-audit is at hand anytime you are working with your dependencies, Snyk provides the following capabilities. These are designed for both individuals and companies:

* It helps secure not only open source, but also your first-party code. If you are using infrastructure as code and/or containers, Snyk also provides visibility and remediation advice.
* In the context of Open Source:
  * You receive all the benefits of the curation, updates, and additional value that the Snyk Security Team adds, such as Known Exploit and Trending on X.
  * You have Automated Remediation.
* Central reporting
* Git Code repository integration, but not just there, Snyk has integrations across your pipeline and visibility into production.
* Broad support across programming languages and package managers.
* Ignore capabilities.

#### Peer dependencies

In npm v7 and above, the behavior of peer dependencies changes if they are being installed by default. To match this in npm v7+ Projects, Snyk assumes peer dependencies are installed and scans them by default.

An npm v7+ Project ignores peer dependencies only if they are explicitly marked as optional in the `peerDependenciesMeta` object in the `package.json` as shown here for `cache-manager`:

```json
{
    ...
    "peerDependenciesMeta": {
        "cache-manager": {
            "optional": true
        }
    },
    ...
}
```

In npm v6 and below, peer dependencies are not scanned by default, as the package manager does not install them by default. To scan peer dependencies, ensure they are installed, and then run the CLI with the `--peer-dependencies` option.

#### Lockfile versions

Snyk uses the `package-lock.json` lockfile when present to generate a dependency tree for your Project. These lockfiles come in different versions.

Lockfile v1 was used in npm v5 and v6. Two new formats were introduced in npm v7 - lockfile v2 and lockfile v3. For more information, see [lockfileVersion](https://docs.npmjs.com/cli/v9/configuring-npm/package-lock-json#lockfileversion).

You can see which lockfile format you are using in the `package-lock.json`, as follows:

```json
{
    ...
    "lockfileVersion": 3,
    ...
}
```

If you want to force npm to create a specific lockfile version, use the npm `--lockfile-version` parameter.

```bash
npm install --lockfile-version=2
```

### Support for pnpm

For all supported pnpm versions, the following features are available:

* CLI support
* SCM support
* License scanning
* Fix PRs

For Snyk to detect a Project as using pnpm, the Project must include the relevant lockfile and configuration files:

* Standard pnpm Projects must contain both `package.json` and `pnpm-lock.yaml` in the same directory.
* pnpm workspaces must include `package.json`, `pnpm-lock.yaml`, and `pnpm-workspace.yaml` in the root directory. Additionally, each package within the workspace must have its own `package.json`.

If the mentioned pnpm lockfile is not present, Snyk treats the Project as an `npm` Project and scans it according to the details mentioned above, for `npm`.

#### Lockfile versions

Snyk uses the `pnpm-lock.yaml` lockfile to generate a dependency tree for your Project.

The supported lockfile versions are 5.4, 6.x and 9.x, as used by pnpm 7, 8, 9 and 10.

pnpm lockfiles do not include [bundledDependencies](https://docs.npmjs.com/cli/v10/configuring-npm/package-json#bundledependencies), so Snyk does not include them in scans.

### Support for Yarn

Snyk uses the Yarn lockfile (`yarn.lock`) to generate a representation of Project dependencies.

The files Snyk relies on to scan a Project may change on version upgrades of the package manager. Snyk lists only versions verified internally as supported.

If you are using a newer version of Yarn than is not listed on this page, it is possible that Snyk performs as expected because Yarn is using a lockfile version that is already supported. That version of Yarn has likely not been evaluated and, thus not added to this page.

For all supported Yarn versions, the following features are available:

* CLI support
* SCM support
* License scanning
* Automatic and Manual Fix PRs

{% hint style="info" %}
Because different versions of Yarn have different feature sets, there are differences in Snyk support in order to match how the package manager works.

Resolutions are supported in Yarn v2 and above. Yarn v1 resolutions are not supported.
{% endhint %}

`nohoist` is not supported for Yarn Workspaces.

If the mentioned yarn lockfile is not present, Snyk treats the Project as an `npm` Project and scans it according to the details mentioned above, for `npm`.

### Support for Lerna

Snyk does not fully support Lerna. If your Project is set up using Yarn Workspaces, you can scan the Project in the same way you scan any Yarn Workspaces Project.

If your Lerna Project is set up using Yarn Workspaces, you can run `snyk test` and `snyk monitor` as follows.

For each example package, you can use the following command:

<pre class="language-shellscript"><code class="lang-shellscript"><strong>snyk monitor --file=packages/example-package/package.json
</strong></code></pre>

Alternatively, you can specify a script to automate scanning of nested `package.json` files:

```shellscript
ls packages | xargs -I PKG_NAME snyk monitor --file=packages/PKG_NAME/package.json
```

### Scanning using npm, pnpm and Yarn

The following table lists the steps to start scanning your dependencies. It covers basic commands, such as `snyk test` and `snyk monitor`. For a full list of CLI commands, see the [CLI commands and options summary](/developer-tools/snyk-cli/snyk-cli/cli-commands-and-options-summary).

<table><thead><tr><th width="153.43489583333331">Package manager</th><th>Getting started</th><th>Description</th></tr></thead><tbody><tr><td>npm</td><td><ol><li>Install npm.</li><li>Ensure you are in a directory with npm Project files, that is, <code>package.json</code> and <code>package-lock.json</code>.</li><li>(Optional) Run <code>npm install</code>.</li><li>Run <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/xhRhnPsgJFdya4vzAjTH">Snyk commands</a>.</li><li>(Optional) Run command options for <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#options-for-npm-projects">snyk test</a> and <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN#options-for-npm-projects">snyk monitor</a>.</li></ol></td><td><p>Snyk analyzes your <code>package-lock.json</code> files to build a dependency tree.</p><p>If the <code>package-lock.json</code> is missing, Snyk analyzes your <code>node_modules</code> folder.</p><p>Alternatively, run <code>npm install</code> to generate the lockfile first.</p></td></tr><tr><td>pnpm</td><td><ol><li>Install pnpm.</li><li>Ensure that you are in a directory with pnpm Project files, that is, <code>package.json</code> or <code>pnpm</code>and <code>pnpm-lock.yaml</code>.</li><li>(Optional) Run <code>pnpm install</code>.</li><li>Run <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/xhRhnPsgJFdya4vzAjTH">Snyk commands</a>.</li><li>(Optional) Run command options for <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#options-for-npm-projects">snyk test</a> and <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN#options-for-npm-projects">snyk monitor</a>.</li></ol></td><td>Snyk analyzes your<code>pnpm-lock.yaml</code> files to build a dependency tree.<br><br>If the <code>pnpm-lock.yaml</code> is missing, Snyk analyzes your <code>node_modules</code> folder.<br><br>Alternatively, run <code>pnpm install</code> to generate the lockfile first.</td></tr><tr><td>Yarn</td><td><ol><li>Install Yarn.</li><li>Ensure you are in a directory with Yarn Project files, that is, <code>package.json</code> and <code>yarn.lock</code>.</li><li>(Optional) Run <code>yarn install</code></li><li>Run <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/xhRhnPsgJFdya4vzAjTH">Snyk commands</a>.</li><li>(Optional) Run command options for <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j#options-for-yarn-projects">snyk test</a> and <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN#options-for-yarn-projects">snyk monitor</a>.</li></ol></td><td><p>Snyk analyzes your <code>yarn.lock</code> files to build a dependency tree.</p><p>If the <code>yarn.lock</code> is missing, Snyk analyzes your <code>node_modules</code> folder.</p><p>Alternatively, run <code>yarn install</code> to generate the lockfile first.</p></td></tr></tbody></table>

### Support for monorepos and workspaces

Yarn, npm, and pnpm support workspaces, to help manage monorepos containing multiple sub-Projects.

#### SCM scanning considerations

Npm workspaces are not explicitly supported in Snyk SCM integrations scans. Root-level `package.json` manifest files with adjacent lockfiles are scanned as normal.

For nested manifest files with no lockfiles, Snyk approximates what the dependency tree looks like at build time without using the root lockfile.

Yarn workspaces Projects must have the `package.json` and `yarn.lock` files in the root directory.

Yarn 1.x workspaces fail to import using SCM and return an `Out of sync package.json and package-lock.json detected` error. This occurs with internal workspace packages when the `yarn.lock` file is at the repository root, but the `package.json` file is in a subdirectory.

As an SCM workaround, in the Snyk web UI, navigate to **Settings** > **Snyk Open Source** > **Languages** > **JavaScript** and clear the checkbox **Require package.json and package-lock.json/yarn.lock files to be in sync**.

As a workaround using the CLI, use the `--strict-out-of-sync=false` flag to allow testing without causing errors.

{% hint style="info" %}
Upgrading to Yarn 2+ does not resolve this issue for SCM scans. SCM workspace Projects require both the `package.json` and `yarn.lock` files to be in the root directory.
{% endhint %}

Pnpm workspaces must have the `package.json`, `pnpm-lock.yaml` and `pnpm-workspace.yaml` files in the root directory.

Pnpm [workspace protocol](https://pnpm.io/workspaces#workspace-protocol-workspace) is not supported for SCM scans.

Dependencies should be defined explicitly with specific versions, or versions using standard semver. (eg `"foo": "^1.1.0"` )

Dependencies that are defined using workspace protocol for the version (eg `"foo" : "workspace:*"` ) will be listed in SCM scans as undefined version.

For all workspaces, Fix PRs and Upgrade PRs do not support workspaces lockfile updates. PRs for these Projects will update the `package.json` only.

#### CLI scanning considerations

Workspaces are supported in the Snyk CLI for the following CLI options:

* `--all-projects`: Discovers and scan all Yarn, npm and pnpm workspaces Projects, along with Projects from other supported ecosystems. The root lock file is referenced when scanning the workspace Projects.
* `--detection-depth`: Specifies how many sub-directory levels to search.
* `--strict-out-of-sync=false`: Allows testing out-of-sync lockfiles for packages in a workspace. When this option is set to `false`, you can run Snyk tests with unsynchronized manifest and lock files without causing errors.
* `--policy-path`: Specifies the path to a policy used by Snyk during testing.

#### Examples of scanning workspaces with the CLI

To scan all workspaces Projects in the current directory and five sub-directories deep, plus any other Projects types detected, use the following command:

```bash
snyk test --all-projects --strict-out-of-sync=false --detection-depth=6 
```

Use a common `.snyk` policy file, if you maintain ignores and patches in one place to be applied for all detected workspaces by using the policy path. See [The .snyk file](/scan-fix-and-prevent/prevent/policies/the-.snyk-file).

```bash
snyk test --all-projects --strict-out-of-sync=false --policy-path=src/.snyk
```

#### Scanning npm workspaces

npm v7 introduced support for workspaces. To detect and scan all workspaces in your npm Project, use the CLI options described above.

#### Scanning pnpm workspaces

pnpm workspaces must have the `package.json`, `pnpm-lock.yaml` and `pnpm-workspace.yaml` files in the root directory. To detect and scan all workspaces in your pnpm Project, use the CLI options described above.

#### Scanning Yarn workspaces

{% hint style="info" %}
`nohoist` is not supported for Yarn Workspaces.
{% endhint %}

To detect and scan all workspaces in your Yarn Project, use the CLI options identified for monorepos and workspaces, as well as this Yarn-specific option.

`--yarn-workspaces` : Uses instead of `--all-projects` to detect and scan only Yarn workspaces Projects when a lockfile is present in the root. Other ecosystems will be ignored.

## Validating, monitoring, alerting, and gating for JavaScript

For SCM integrations with a Snyk Enterprise plan only, Snyk can monitor container images and their open source or Linux-based packages being used in production using Kubernetes integration to notify customers of known vulnerabilities for applications in production.

For all Snyk plans, where a production integration does not exist, use the [`snyk monitor`](/developer-tools/snyk-cli/snyk-cli/commands/monitor) CLI command to take a snapshot and monitor what is being pushed to production.


# CLI support for JavaScript

How to test JavaScript Projects with the Snyk CLI, including report generation, output formats, and dependency filtering

To help generate reports locally or at build time, see the [snyk-to-html plugin](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-to-html).

See `--json` and `--sarif` options for generating output that can be programmatically accessed.

For advanced filtering options, see[ snyk-filter](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter).

## Open Source libraries

The `snyk test` command tests the first manifest it can find and performs a test on that singular entry point. To have Snyk analyze all manifests in the directory, use the following options:

* `--all-projects`: This option detects and scans all Yarn and other Projects in this directory.
* `--yarn-workspaces`: For Yarn Workspaces use the `--all-projects` flag to test and monitor your packages with other package managers or Yarn workspaces or use `--yarn-workspaces` to specifically scan Yarn Workspaces Projects only.

{% hint style="info" %}
If you are using a package manager that requires options, it is suggested to target them individually with `--file=`
{% endhint %}

### Codebase

* Framework support - see [Supported languages, frameworks, and feature availability overview](/supported-languages/supported-languages-package-managers-and-frameworks).
* Use the `snyk code test` command from the root of the Project to perform source code analysis.

### Containers

* Snyk will automatically look for application (open source) vulnerabilities as part of a container scan. Consider having Snyk integrated through CLI earlier in the pipeline and utilize this for an additional signal of and insight into what is in production.
* If you ship your Node.JS application in a container, be aware that you might also be bundling insecure packages (Linux, open source), alongside your application in addition to what is brought in by the container base image. The Snyk Container CLI can help you identify a base image that minimizes the attack surface of your application.
* For more information on how you can filter to the layer you wish to work on, such as identifying a secure base image to build off of, the layers you are responsible for, or application (OS) vulnerabilities, see [Snyk CLI for container security](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-container)

### Infrastructure as Code

See [Infrastructure as Code security](https://snyk.io/product/infrastructure-as-code-security/).

## Resources

See the [CLI commands and options summary](/developer-tools/snyk-cli/snyk-cli/cli-commands-and-options-summary) and the [CLI cheat sheet](https://snyk.io/blog/snyk-cli-cheat-sheet/). Use the `--help` option in the CLI for details of Snyk CLI commands.


# SCM integrations for JavaScript

How to import and scan JavaScript repositories through Snyk SCM integrations, including Organization-level language settings

You can import JavaScript repositories from any SCM integration supported by Snyk. See [Organization level integrations](/developer-tools/integrations/scm-integrations/organization-level-integrations). After the import, Snyk analyzes your Projects based on their supported manifest files.

## Configure language settings for Snyk with JavaScript

You can configure language settings for open source and licensing at the Organization level. The configuration settings apply to all Projects in that Organization. To configure:

1. In the Snyk Web UI, navigate to **Settings** > **Snyk Open Source** > **Languages** > **JavaScript**.
2. Click **Edit settings.**
3. Configure the settings based on your package manager - npm, pnpm, or Yarn.
   * **Scan and fix dev dependencies**: if you check this option, Snyk reads the `devDependencies` property on the `package.json` and reports and fixes any vulnerabilities accordingly.
   * **Require package.json and package-lock.json/yarn.lock files to be in sync**: when this is checked if the `package.json` and `package-lock.json`/`yarn.lock/pnpm-lock.yaml` files are out-of-sync, Snyk fails the import.
   * **Exclude package-lock.json from being generated when fixing vulnerabilities**: if you are using private mirrors or registries, it is possible that a Snyk-generated lockfile is not appropriate for you because Snyk uses the npm registry to update the lockfile. Enterprise customers can use [package repository integrations](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations) to ensure lockfiles are updated correctly. Alternatively, this setting allows you to opt out of getting lockfiles generated for you in Snyk fix pull requests and merge requests.
4. Click **Update Settings** to save changes.

## Package registry integrations (Artifactory/Nexus)

{% hint style="info" %}
Artifactory, Nexus, npm Teams, and npm Enterprise Package Registry integrations are available only for Snyk Enterprise plans.
{% endhint %}

Snyk Open Source Gatekeeper plugins integrates with Artifactory to block builds from downloading packages with vulnerability and license issues.

Snyk Open Source can also integrate with Artifactory, Nexus, npm Teams, and npm Enterprise to assist in the security testing of your applications. Snyk uses this integration for dependency resolution, fix calculation, and re-locking lock files.

If your Projects reference private dependencies in these repositories but you are not a Snyk Enterprise user, you can use the Snyk CLI in a properly configured local environment (such as your build pipeline) so these dependencies can be resolved and included in the test.

For more information, see the following external resources:

* Package registry integrations: [npm Teams and npm Enterprise](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/npm-teams-and-npm-enterprise-integration), [Artifactory Registry setup](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/artifactory-package-repository-connection-setup) and [Nexus Repository Manager setup](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/nexus-repository-manager-connection-setup).
* Gatekeeper plugins: [Artifactory Gatekeeper plugin](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/manage-vulnerabilities/artifactory-gatekeeper-plugin)

## Fix PRs and npm save-prefix

When creating a fix for vulnerabilities using npm v7+ Projects, Snyk uses the default npm `save-prefix` rather than inferring it from your Project.

This means that if you have dependencies using a range format other than the caret range (`^`), it is possible that you see additional changes to the `version` fields in the `package-lock.json` file.

These changes do not affect day-to-day functionality, as the ranges will be read from the `package.json`.

## Fix PRs for Yarn zero-installs users

In Yarn v2, the [zero-installs](https://yarnpkg.com/features/zero-installs) feature was released, which allowed Yarn developers to work on a Project without having to run `yarn` to install dependencies on their machine.

Zero-installs achieved this by installing all the dependencies of a Project inside of the `.yarn/cache` directory and asking users to commit this to their version control system, allowing the next developer to pull any new dependencies directly from the repository.

{% hint style="info" %}
If you use the zero-installs feature, Snyk Fix PRs do not update the .yarn/cache directory. You must run `yarn` to update this directory.
{% endhint %}


# .NET (C# and VB.NET)

Snyk support for .NET with Snyk Code and Snyk Open Source, including C# and VB.NET frameworks, libraries, and versions

{% hint style="info" %}
.NET is supported for Snyk Code and Snyk Open Source.
{% endhint %}

## .NET for Snyk Code

{% hint style="info" %}
For .NET with Snyk Code, C# and VB.NET are supported.
{% endhint %}

### Supported frameworks and libraries

For .NET with Snyk Code, the following frameworks and libraries are supported:

* .NET 6.0 - 10.0
* .NET Core
* .NET Framework 4.6-4.8.x
* Anthropic.SDK
* ASP.NET 6.x (C# only)
* Azure.AI.OpenAI
* Dapper
* fastJSON
* Google\_GenerativeAI
* grpc-dotnet (C# only)
* Microsoft.CodeAnalysis.VisualBasic
* Mistral.SDK
* System.CodeDom.Compiler
* Windows Forms

### Supported file formats

* For C#, Snyk supports the `.aspx` & `.cs` file formats.
* For VB.NET, Snyk supports the `.vb` file format.

### Available features

* Reports
* Interfile analysis

## .NET for Snyk Open Source

{% hint style="info" %}
For .NET with Snyk Open Source, Snyk supports C# only.
{% endhint %}

### Supported versions

For .NET with Snyk Open Source, the following versions are supported:

* .NET versions 6, 7 - only the latest SDK version
* .NET versions 8, 9, and 10 - all SDK versions
* .NET Framework version 4 - using SDK-style projects
* All versions of .NET Standard

### Supported package managers and package registries

For .NET with Snyk Open Source, NuGet and Paket are supported as package managers and [nuget.org](https://www.nuget.org/) as a package registry.

### Supported file formats

* For NuGet: `project.assets.json`, `*.sln`, `packages.config,` `project.json`
* For Paket: `paket.dependencies` and `paket.lock`

### Available integrations

* SCM import (not available for Paket)
* CLI and IDE: test or monitor your app

### Available features

For .NET with Snyk Open Source, the following features are available:

* Fix PRs (only for NuGet)
* License scanning
* Reports
* (Only for Paket) Test your app's SBOM and packages using `pkg:nuget` PURLs, using the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) command.

{% hint style="warning" %}
Snyk does not support `PackageReference` entries without a version attribute. If your Project is missing this attribute, Snyk cannot open a pull request. Ensure you add versions to all `PackageReference` entries.
{% endhint %}

### Dependency analysis using the CLI

{% hint style="info" %}
Snyk does not support `package-lock.json`. Snyk uses the build system to determine which dependencies are installed.
{% endhint %}

For dependency analysis using the CLI, Snyk must accurately resolve dependencies to identify vulnerabilities in .NET applications. Snyk scans and fixes build and development dependencies in your `*.proj`, `packages.config`, and `project.json` files.

If you manage Project dependencies using `PackageReference`, Snyk scans the `obj/project.assets.json` file.

Snyk resolves runtime dependencies (or meta-packages) more accurately when the host machine uses a runtime SDK similar to the one used by the server running the application.

### Dependency analysis using SCM integrations

Snyk resolves dependencies to identify vulnerabilities in .NET applications. The .NET ecosystem includes multiple dependency levels, including those not visible to developers.

By default, Snyk excludes developer dependencies to reduce noise in scan results, since you rarely deploy them to production.

To include developer dependencies in NuGet SCM imports, navigate to **Settings** > **Languages** > **.NET**.

When scanning through an SCM integration, the methodology varies based on your Project format:

* Modern Projects (SDK-style): For modern `.csproj` formats, the scanner utilises the .NET SDK directly to resolve dependencies, resulting in higher accuracy. This also provides the capability of scanning any Project that can be successfully restored by the `dotnet` SDK itself including `Directory.Build.props` files, `global.json`, or Central Package Management (`Directory.Packages.props`).
* Legacy Projects (Non-SDK style): For Projects relying on `packages.config`, `project.json`, or XML-style `*.csproj` , `*.vbproj` or `*.fproj` files. The scanner uses static analysis to approximate the dependency graph based on standard NuGet algorithms.

To improve accuracy, migrate to the [Universal Broker](/platform-administration/snyk-broker/universal-broker) and [enable](/platform-administration/snyk-broker/universal-broker/basic-steps-to-install-and-configure-universal-broker#enabling-the-universal-broker-for-enhanced-sca-scanning) it for Open Source Scanning.

### .NET framework package pruning

For Snyk Projects targeting .NET 10.0 and later, the Snyk SCM and CLI scanners align with default Microsoft build behavior.

By default, Microsoft enables the `RestoreEnablePackagePruning` property for these frameworks. This setting prunes framework-provided package references during the restore operation.

Snyk respects your Project configuration. If you set `RestoreEnablePackagePruning` to `false` in your Project file or `Directory.Build.props`, Snyk does not prune these references during the scan.

For Projects targeting .NET 10.0 and later, Snyk SCM and CLI scanners align with the default Microsoft build behaviour.

By default, Microsoft enables the `RestoreEnablePackagePruning` property for these target frameworks. This setting prunes framework-provided package references during the restore operation.

The Improved .NET scanner respects your Project configuration. If you disable this feature by setting the `RestoreEnablePackagePruning` property to `false` either in your Project file or in a `Directory.Build.props` file, Snyk respects this setting and does not prune those references during the scan.


# CLI support for .NET

How to test .NET Projects with the Snyk CLI, including open source analysis with solution and project files and source code scanning

To analyze Open Source libraries, install your dependencies, then run `snyk test` using one of the following options:

* `--file=`: Targets a specific solution file (`.sln`) or Project file.
* `--all-projects`: Analyzes all Open Source Projects. Use this for Projects with multiple languages, package managers, or `.sln` files.

To perform source code analysis, run `snyk code test` from the root of the Project.

## NuGet

For NuGet-specific options, visit [Options for NuGet projects in the Test help](/developer-tools/snyk-cli/snyk-cli/commands/test#options-for-nuget-projects) and [Options for NuGet projects in the Monitor help](/developer-tools/snyk-cli/snyk-cli/commands/monitor#options-for-nuget-projects).

Snyk scans NuGet Projects using the `project.assets.json` file. Snyk supports the following Project files that resolve into `project.assets.json`:

* `*.csproj`
* `*.vbproj`
* `*.fsproj`

To scan a NuGet Project:

1. Run `dotnet restore`. This restores dependencies and creates the `obj/project.assets.json` file.
2. Run `snyk test`.

{% hint style="info" %}
You must run `dotnet restore` before `snyk test` to restore dependencies and ensure accurate scan results.
{% endhint %}

#### Support for project.json

Snyk supports `project.json` files, although Microsoft no longer recommends this format.

#### Support for packages.config

Snyk supports `packages.config` files. To scan these Projects:

1. Run `nuget install -OutputDirectory packages` to install dependencies into the `packages` folder.
2. Ensure the command created the `packages` directory.
3. Run `snyk test` as follows:
   1. Install the dependencies into the packages folder by running `nuget install -OutputDirectory packages`
   2. Ensure that the packages directory has been created by the previous command.
   3. Run `snyk test`.

## Paket

To use Paket with the Snyk CLI:

1. Ensure your project contains a `paket.lock` file and a `paket.dependencies` file.
2. Run `snyk test`.

## Options and plugins

* [snyk-to-html](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-to-html): Generates reports locally or at build time.
* `--json` and `--sarif`: Generates output for programmatic access.
* [snyk-filter](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter): Provides advanced filtering options.


# SCM integrations for .NET

How Snyk scans .NET repositories through SCM integrations, including NuGet support and Universal Broker requirements

{% hint style="info" %}
Snyk does not support Projects using Visual Studio Build Tools.

Snyk supports Windows-specific frameworks (WPF, WCF) only for .NET 10 and later.
{% endhint %}

Snyk supports NuGet as the only package manager for SCM integrations. For brokered SCMs and brokered private package repositories, Snyk supports only the Universal Broker.

Considerations:

* Snyk operates on a case-sensitive file system. Manifest definitions, such as `<ProjectReference>` strings, must match the case of the files and folders.
* `Directory.*.props`, `global.json`, and other .NET-specific manifest files must use the exact casing Microsoft describes.
* Snyk supports a subset of the major, minor, and patch versions supported by Microsoft.

Snyk uses the following files to create dependency trees:

* .NET Core: `*.proj` files
* .NET Framework: `*.proj` files and `packages.config`

## Import and scan .NET Projects

You can import .NET Projects from any supported SCM integration. Snyk analyzes your Projects using supported manifest files, builds a dependency tree, and displays the results in the Snyk Web UI.

To configure Snyk to scan build and development dependencies or skip them, navigate to the relevant Group and Organization **Settings** > **.NET**. To scan all development dependencies, ensure that the **Scan build dependencies** option is checked.

## Support manifest files

Snyk builds the dependency tree using the following manifest files:

* `*.csproj`
* `*.vbproj`
* `*.fsproj`
* `global.json`
* `Directory.Build.props`
* `Directory.Packages.props`

{% hint style="info" %}
A .NET Project can target different frameworks. Snyk creates a separate list of dependencies for each framework and displays each as a distinct Snyk Project. This isolates dependencies and simplifies remediation planning.
{% endhint %}

## Fix vulnerabilities in .NET Projects

If you manage Project dependencies with NuGet using `PackageReference` or `packages.config`, Snyk automatically updates the dependency version in your manifest file if a fix is available. You can then review and merge the fixes.


# Troubleshooting Snyk for .NET

How to resolve common Snyk problems for .NET, including static dependency resolution for legacy Project files and Legacy Broker setups

### .NET SDK resolution limitations

Snyk uses static analysis instead of the .NET SDK to resolve dependencies in the following scenarios:

* Legacy Project files: Projects use legacy non-SDK style Project files.
* Legacy Broker: Organizations use the Legacy Broker instead of the Universal Broker to connect to brokered private package repositories and SCMs.

To improve accuracy, migrate to the Universal Broker.

### Static analysis limitations

The following functionality is not supported when using static analysis:

* Private dependencies: Snyk cannot access private dependencies, including brokered and non-brokered. Transitive dependencies are not resolved.
* Build configuration: Snyk ignores `Directory.Build.props`, `Directory.Build.targets`, and `global.json` files.
* Runtime precision: Snyk cannot reliably identify the specific runtime, which may increase false positives

### Handle runtime false positives

Static analysis may flag vulnerabilities already patched in your environment because it may not detect your specific runtime patch version.

#### Vulnerabilities in SCM

If your application runs on a system updated with the latest Microsoft patches, a flagged vulnerability may not be relevant. You can ignore these vulnerabilities in the Snyk Web UI.

#### Vulnerabilities in CLI

If your production environment pulls the latest patches or you deploy a self-contained application, use the following configurations in your project file to improve accuracy:

* Latest SDK patch: If your application always runs on the latest SDK patch version in production, set `TargetLatestRuntimePatch` to `true` in the project file. Ensure you upgrade all environments to the latest runtime version.
* Self-contained applications: If you publish a self-contained app that includes the runtime, set `RuntimeFrameworkVersion` to the specific patch version in the project file. You can ignore vulnerabilities that are no longer relevant.


# PHP

Snyk support for PHP with Snyk Code and Snyk Open Source, including supported versions, frameworks, and interfile analysis

{% hint style="info" %}
PHP is supported for Snyk Code and Snyk Open Source.
{% endhint %}

## PHP for Snyk Code

Snyk Code has support for PHP versions 5.2 through 8.0 and is designed to process code from newer PHP versions where feasible.

For an overview of the supported security rules, visit [PHP rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/php-rules).

### Available features

* Reports
* Interfile analysis

### Supported frameworks and libraries

For PHP, the following frameworks and libraries are supported:

* grpc-php
* Laravel
* llphant
* openai-php/client
* orhanerday/open-ai
* Pclzip
* Symfony
* theodo-group/llphant

### Supported file formats

The following file formats are supported: `.php`, `.phtml`, `.module`, `.inc`, `.install`, `.theme`, `.profile`.

## PHP for Snyk Open Source

For PHP with Snyk Open Source, PHP versions 5.2 through 8.5 are supported.

For PHP with Snyk Open Source, the following file formats are supported: `composer.json` and `composer.lock`

### Available integrations

* SCM import
* CLI and IDE: test or monitor your app

### Supported package managers and package registries

* Supported package manager: [Composer](https://getcomposer.org)
* Supported package registry: [packagist.org](https://packagist.org/)

### Available features

* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:composer` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command.

{% hint style="info" %}
The **Snyk Fix PR** feature is not available for PHP. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}

## CLI support for PHP

A [build is required](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-open-source/open-source-projects-that-must-be-built-before-testing-with-the-snyk-cli) to scan with the CLI if there is no `composer.lock` file present. There are no unique options for use when running Snyk for PHP.

## SCM integrations for PHP

PHP Projects can be imported from any of the available Snyk SCM integrations. After Projects have been imported, Snyk analyzes your Projects based on their supported manifest files.

After you select a Project for import, Snyk builds the dependency tree based on these manifest files. Both of the following files are required:

* `composer.json`
* `composer.lock`

If the `composer.lock` file is not present in the repository, the import will not process the `composer.json` manifest.

By default, Snyk scans your production dependencies. Using the Snyk Web UI, you can configure whether or not to include your development dependencies, such as `require_dev` \[...] in the scan for vulnerabilities.

To update language preferences:

1. Log in to your account and navigate to the relevant Group and Organization that you want to manage.
2. Select **Settings** > **Languages**.
3. Select **Edit settings** for PHP and select **Scan dev dependencies** to set your PHP projects in the specific Organization to include both development and production dependencies.
4. Select **Update settings**.

These settings are applied to all newly imported Projects and to all existing Projects when they are re-tested.


# Python

Snyk support for Python with Snyk Code and Snyk Open Source, including SCM import, CLI and IDE testing, and supported versions

## Applicability and integration

{% hint style="info" %}
Python is supported for Snyk Code and Snyk Open Source.
{% endhint %}

Available integrations:

* SCM import
* CLI and IDE: test or monitor your app

## Python for Snyk Code

For an overview of the supported security rules, visit [Python rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules).

For Python with Snyk Code, Python versions up to `3.12` are supported. Language features introduced in newer versions are not supported.

For Python with Snyk Code, the following file format is supported: `.py`

Available features:

* Reports
* Interfile analysis

### Supported frameworks and libraries

For Python, the following frameworks and libraries are supported:

{% columns %}
{% column %}

* AioHTTP
* iopg
* aiofiles
* argparse
* anthropic
* bottle
* CherryPy
* Django
* defusedxml
* fastapi
* fastMCP
* flask
* flask\_pymongo
* google.cloud.bigquery
* google\_generativeai
* grpcio
* huggingface\_hub
* httpx
* ldap3
* libxml
* lxml
* mistralai
* modelcontextprotocol/python-sdk
* mongoengine
  {% endcolumn %}

{% column %}

* openai
* pandas
* paramiko
* peewee
* pickle
* pilyaml
* pyca/cryptography
* pymongo
* pymssql
* pyramid
* psycopg
* python-ldap
* Python Standard Library
* requests
* sqlite3 (or pysqlite2)
* sqlalchemy
* turboGears
* urllib
* werkzeug
  {% endcolumn %}
  {% endcolumns %}

### Directory layout

Snyk Code relies on Python projects to follow a standard directory layout for accurate analysis. Specifically, Snyk Code expects Projects to be compatible with [`setuptools` automatic discovery](https://setuptools.pypa.io/en/latest/userguide/package_discovery.html#auto-discovery), which identifies packages and modules automatically based on the directory structure. This includes support for `init.py` files to ensure that symbols defined in package initialization files are imported correctly, leading to a more accurate and deeper analysis.

Both `src-layout` and `flat-layout` are supported. Proper adherence to these conventions allows the scanner to trace code effectively and provide accurate results.

## Python for Snyk Open Source

{% hint style="info" %}
It is possible that some Python Projects contain dependencies that require specific versions of Python. Therefore, the version of Python used when scanning can affect the dependency tree that Snyk generates.
{% endhint %}

For Python with Snyk Open Source, the following Python versions are supported: `2.7`, `3.7`, `3.8`, `3.9`, `3.10`, `3.11`, `3.12`, `3.13`, `3.14`

### Supported package managers and registries

* Supported package managers: [Pip](https://pypi.org/project/pip/), [Poetry](https://python-poetry.org/), [pipenv](https://pipenv.pypa.io/en/latest/), and setup.py
* Supported package registry: [pypi.org](https://pypi.org/)

For pipenv Projects, Snyk uses Python version information specified in each `Pipfile` to choose the major and minor versions to use in scanning, for example:

```python
[requires]
python_version = "3.8"
```

Specific patch versions are ignored; Snyk uses a recent patch version from each series.

Snyk defaults to Python `3.10` if the `Pipfile` contains:

* No Python version information
* Only a major version
* An unsupported version

For Poetry Projects, you do not need to specify the Python version. Poetry files contain sufficient information to build a full dependency tree without running native tooling.

### Supported file formats

* For poetry: `pyproject.toml` and `poetry.lock`
* For pip: `requirements.txt`
* For pipenv: `pipfile` and `pipfile.lock`
* For setup.py: `setup.py`

### Available features

* Automatic and manual Fix PRs (supported only for pip)
* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:pypi` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command

{% hint style="info" %}
Depending on your plan, some features may not be available. For more information, see [plans and pricing](https://snyk.io/plans/).
{% endhint %}

### IDE and CI/CD support

If you are using any of the supported IDEs to write Python, there are some configurations you must add to scan Python manifest files properly.

To scan your Projects, you must first install the relevant package manager and ensure that your Project contains the supported manifest files.

Python packages that are operating system-specific and not supported by Linux may not be compatible with Snyk SCM scans, leading to errors.

#### Virtual environment configuration

If you are using a virtual environment, you must add the following information:

* In your Snyk integration settings, locate the **Additional Options** field.
* Add the `PYTHON_PATH` to this field, for example `--command=.venv/bin/python`.

By default, the Snyk IDE integration looks for a `*req*.txt` file in the root of the Project as it is seen in the IDE.

#### Scan multiple directories

If you have manifest files in other directories within the root of the Project, Snyk cannot identify them unless directed to do so.

In your Snyk integration settings, locate the **Additional Options** field. Enable a recursive search and add the `--all-projects` option in the **Additional Options** field.

{% hint style="warning" %}
If each directory needs a different virtual environment, it is possible that the Snyk scan fails because it uses a single virtual environment for dependency detection. In such cases, Snyk recommends using the CLI or SCM integration instead of an IDE , in order to gather vulnerability details for all dependencies in each Project directory.
{% endhint %}


# CLI support for Python

How to test Python Projects with the Snyk CLI, including setting the Python version and preparing pip dependencies before scanning

## Set the Python version in the CLI

To set the Python version in the CLI, add the following option to `snyk test` or `snyk monitor` with the name of the Python binary:

```sh
--command=python3
```

For details, see the options for Python Projects in the [`snyk test`](/developer-tools/snyk-cli/snyk-cli/commands/test) and [`snyk monitor`](/developer-tools/snyk-cli/snyk-cli/commands/monitor) help.

## Pip and CLI

{% hint style="info" %}
Run `pip install` before scanning with the CLI, for example:

```
pip install -r requirements.txt
```

{% endhint %}

Pip `requirements.txt` files specify only top-level dependencies, not nested or transitive ones. Therefore, the full Pip Project must be installed to ensure the CLI can build a complete dependency tree.

## Poetry and CLI

{% hint style="info" %}
[PEP 621](https://peps.python.org/pep-0621/) is a standard for defining direct dependencies in `pyproject.toml` files. Snyk supports PEP 621 only for Poetry v2. Poetry v1 uses an alternative approach.

Snyk does not support PEP 621 for any package manager other than Poetry.
{% endhint %}

Poetry v1 and v2 are supported.

To build the dependency tree for a Poetry application, Snyk uses `pyproject.toml` and `poetry.lock` files. Both files must be present for Snyk to scan Poetry dependencies and identify issues.

If no `poetry.lock` file is present; you should run `poetry lock` to generate one before scanning.

For Poetry, it is possible to get mixed `include` entries in `pyproject.toml`

Snyk fails to scan Poetry Projects and returns an "unparsable manifest" or "unable to parse pyproject.toml" error if you define mixed include entries in the `pyproject.toml` file.

Under `[tool.poetry]`, Poetry allows the `include` array to mix plain path strings and `{ path = "...", format = [...] }` inline tables. This is valid TOML 1.0 and a valid Poetry configuration.

However, Snyk parses `pyproject.toml` using a TOML implementation that does not accept mixed-type inline arrays. Snyk stops parsing at the mixed array and treats the file as invalid before it runs the dependency logic.

Example of a failing configuration:

```
include = [
  "py.typed",
  { path = "src/my_package/templates/**/*", format = ["sdist", "wheel"] },
]
```

To fix this issue, use only one format for every entry. For example, use only inline tables:

```
include = [
  { path = "py.typed" },
  { path = "src/my_package/templates/**/*", format = ["sdist", "wheel"] },
]
```

## Pipenv and CLI

To build the dependency tree for a Pipenv application, Snyk uses `Pipfile` and `Pipfile.lock` files. Both files must be present for Snyk to scan Pipenv dependencies and identify issues.

Run `pip install` before scanning with the CLI.

Run `pipenv install` to ensure the CLI can build an up-to-date, accurate dependency tree using `pipenv graph`.

## setup.py and CLI

To build the dependency tree, Snyk analyzes the `setup.py` file, and detects packages listed in the `install_requires` key.

This file will not be discovered automatically by the CLI. It must be specified manually using the `--file` option, for example:

```python
snyk test --file=setup.py
```

You can also convert `setup.py` to `requirements.txt` by installing the packages into a virtual environment and then running `pip freeze`.


# SCM integration support for Python

How Snyk scans Python Projects through SCM integrations, including required manifest files and setting the Python version

{% hint style="warning" %}
Python packages that are operating system-specific and not supported by Linux may not be compatible with Snyk SCM scans, leading to errors.
{% endhint %}

To scan your Projects, you must ensure your repository contains the supported manifest files.

## Set the Python version in SCM Projects

When scanning Pip Projects imported from an SCM integration, Snyk uses the version of Python specified in Organization settings or `.snyk` files.

{% hint style="info" %}
It is important to specify the correct Python version for your Organization, as it can affect the version of dependencies used in scanning your Projects.
{% endhint %}

Snyk uses a recent `patch` version for each of the supported `minor` version.

By default, Snyk tests Pip Projects using Python 3.7.

{% hint style="warning" %}
The behavior of imports, re-tests, and PR checks for Projects with dependencies requiring a higher version of Python varies according to the version specified:

* Python 3.8 or above: scans will fail with an [error](/scan-fix-and-prevent/prevent/error-catalog) message that includes details of the first failed package, the Python version it requires, and the Python version used.
* Python 2.7 or 3.7: scans will succeed, but the incompatible dependencies are omitted from the results.
  {% endhint %}

To define which Python minor version Snyk uses to test your Pip Projects imported using SCM integrations, you can use Organization settings and [`.snyk` policy file](/scan-fix-and-prevent/prevent/policies/the-.snyk-file).

To define the Python version for all Projects in an Organization:

1. Log in to your Snyk account and navigate to the relevant Group and Organization.
2. Select **Settings** > **Snyk Open Source**.
3. Select **Edit settings** for **Python**.
4. From the **Python version** dropdown, select the Python version to use when testing Projects for this Organization.

<figure><img src="/files/YiNHG6XvAILqY381303t" alt="Pip Python version settings"><figcaption><p>Pip Python version settings</p></figcaption></figure>

If you need a Project in an Organization to use a different Python version, you can add a `.snyk` file to the Project repository and specify the desired version.

```python
language-settings:
  python: '3.10'
```

The `.snyk` file must be in the same directory as the Project manifest file.

Snyk will select which Python version to use according to the `major`, `minor` and `patch` versions specified in the `.snyk` file.

* `Major` version only (for example, 2 or 3): scanned with default `minor` versions - 2.7 or 3.7
* `Major` and `minor` version (for example, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 3.14): scanned with 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, or 3.14
* `Major`, `minor` and `patch` version (or example, 3.8.x, 3.9.x, 3.10.x, 3.11.x, 3.12.x, 3.13.x): the specific `patch` version is ignored, the Project is scanned with default versions of 3.8, 3.9, 3.10, 3.11, 3.12, 3.13 or 3.14
* Any versions specified with an unsupported `minor` version: defaults to 2.7 or 3.7

## SCM repositories and Pip

The following dependencies are not supported and are removed before the file is scanned. The remaining dependencies are included in the scan.

* Private PyPI repos
* `file://`, regular URLs, relative paths, and more generally URIs in `requirements.txt` files
* Setting a different package index with `--index-url`, `-i`, `--extra-index-url`
* Specifying dependency archive locations with `--find-links`, `-f`
* Installing a dependency in editable mode with `--editable`, `-e`
* Relying on a version constraints file with `--constraint`, `-c`
* Including another requirement file with `--requirement`, `-r`
* Specific packages: `virtualenv` and `pip` for Python 2.7 and 3.7

To scan Pip Projects, Snyk analyzes your `requirements.txt` files using native `pip` tooling in an isolated Linux environment.

Pip Projects scanned using the SCM integration will be given the same name as the directory where they are located.

Snyk imports any file that follows the `**/*req*.txt` pattern. This can help if you have renamed the `requirements.txt` files, for example, to `requirements-dev.txt`.

Snyk also looks for files using the `**/requirements/*.txt` pattern. This can help if you have placed your files in a `requirements` folder, for example, `requirements/requirements.txt`.

If you are using a package manager that creates different manifest file formats from `requirements.txt`, then you may be able to convert or export the manifest file to the `requirements.txt` format.

An example follows of how `dephell` is used to convert from Conda `environments.yml` to a `requirements.txt`.

```python
dephell deps convert --from=conda --to=requirements.txt
```

## SCM repositories and Poetry

Poetry v1 and v2 are supported.

To scan Poetry Projects, Snyk inspects your `pyproject.toml` and `poetry.lock` files.

You can choose whether Snyk should include [dev dependencies](https://python-poetry.org/docs/managing-dependencies/) when scanning your Poetry Projects.

Snyk regards non-dev dependencies to be those declared in `tool.poetry.dependencies`, the implicit `main` group. All others are classed as dev dependencies.

Poetry dev dependencies are not included in scans by default. To change this, modify your settings as follows:

1. Log in to your Snyk account and navigate to the relevant Group and Organization.
2. Select **Settings** > **Languages**.
3. Select **Edit settings** for **Python**.
4. Enable or disable the **Scan Poetry dev dependencies** option under the **Poetry dev dependencies** settings.

<figure><img src="/files/LmdljbMbAlWB9xqesDLB" alt="Poetry dev dependency settings"><figcaption><p>Poetry dev dependency settings</p></figcaption></figure>

A known limitation for Poetry is mixed `include` entries in `pyproject.toml`

Poetry scans fail with an unparsable manifest / unable to parse `pyproject.toml` if mixed `include` entries are defined in `pyproject.toml`

Under `[tool.poetry]`, Poetry allows `include` to mix plain path strings and `{ path = "...", format = [...] }` inline tables in one array. That is valid TOML 1.0 and a valid Poetry configuration.

Snyk’s Poetry analysis parses `pyproject.toml` with a TOML implementation that does not accept mixed-type inline arrays. Parsing stops at that array, so the file is treated as invalid before dependency logic runs.

Example of a failing configuration:

```
include = [
  "py.typed",
  { path = "src/my_package/templates/**/*", format = ["sdist", "wheel"] },
]
```

To fix this issue, use only one shape for every entry. For example, use only inline tables:

```
include = [
  { path = "py.typed" },
  { path = "src/my_package/templates/**/*", format = ["sdist", "wheel"] },
]
```

## SCM repositories and Pipenv

{% hint style="warning" %}
Private PyPI mirrors are not supported. `Pipfiles` specifying a private mirror as their only source will not be imported.
{% endhint %}

To scan Pipenv Projects, Snyk analyzes your `Pipfile` and `Pipfile.lock` files using native `pipenv` tooling in an isolated Linux environment.

{% hint style="info" %}
Packages from private repositories and those with non-Linux OS requirements may be unresolvable and omitted from the dependency tree.

If a `Pipfile.lock` is present, any unresolved packages it contains are added to the top level of the dependency tree using versions from the lock file.
{% endhint %}

You can choose whether Snyk should include dependencies specified in `[dev-packages]` when scanning your Pipenv Projects.

Pipenv dev dependencies are not included in scans by default. To change this, modify your settings as follows:

1. Log in to your Snyk account and navigate to the relevant Group and Organization.
2. Select **Settings** > **Languages**.
3. Select **Edit settings** for **Python**.
4. Enable or disable the **Scan Pipenv dev dependencies** option under the **Pipenv** settings.

<figure><img src="/files/94eTGsxWRFUcUNpRcezf" alt="Pipenv dev dependency settings"><figcaption><p>Pipenv dev dependency settings</p></figcaption></figure>


# Support for uv

Snyk support for the uv package manager with Python, available in Early Access on Enterprise plans through the CLI and SCM

{% hint style="info" %}
**Release status**

CLI and SCM support for uv is in Early Access and available only with Enterprise plans. To enable the feature, visit [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

## CLI support for uv

### Prerequites

Ensure you have `uv` version 0.9.29 or later installed.

Snyk uses the `uv.lock` file to build the dependency graph for a `uv` application. This file must be present for Snyk to identify the Project, scan dependencies, and identify issues. Ensure you check this file into your repository and that it reflects your current `pyproject.toml`. That is, ensure you run `uv lock` after adding, removing, or updating dependencies.

You do not need to run `uv sync` before you run the Snyk CLI.

Test results are not specific to the platform where you run the test. For example, if your `uv` Project has a Windows-only dependency with a vulnerability, this vulnerability also appears in the results if you run your test on Linux. Contact Snyk to provide feedback on this behavior or if you want to narrow down results to the platform where you run the test, either by default or using a flag.

### Supported commands and options <a href="#set-the-python-version-in-the-cli" id="set-the-python-version-in-the-cli"></a>

Snyk supports the `snyk test`, `snyk monitor`, and `snyk sbom` commands.

#### `snyk test`

The following flags, options, and arguments are not available:

* `--detection-depth`: There is no maximum depth for directory traversal. In later releases, Snyk scans only `uv` Projects in directories up to the given depth.
* `--print-deps`: The test incorrectly fails with a `Could not detect supported target files` error. In later releases, Snyk outputs dependency graphs for all found Projects without running a test.
* Input directory positional argument: When you run `snyk test <directory>`, Snyk ignores the directory. In later releases, Snyk scans only the specified directory.

The following flags and options are supported with limitations:

* `--file`: Snyk respects this flag only for `uv.lock` files. In later releases, Snyk supports `pyproject.toml` manifest files (both root and workspace packages).
* `--exclude`: This flag works only to exclude `uv.lock` files. In later releases, this option supports workspace packages. For example, `--exclude=foo` excludes all dependencies from `packages/foo/pyproject.toml`.

{% hint style="info" %}
For `uv`, the `--package-manager` option is not supported because `uv` does not permit lockfiles with names other than `uv.lock`.
{% endhint %}

#### `snyk monitor`

Snyk does not render error messages from the `uv` plugin in the traditional CLI error style.

#### `snyk sbom`

For SBOMs generated for `uv` Projects:

* When you generate an SBOM in a monorepo containing both `uv` and Maven Projects using the `--all-projects` flag, Snyk prunes some Maven dependencies in the resulting SBOM. All dependencies appear in the graph, but there are fewer instances than expected. When there are no `uv` Projects present, all dependencies are present as expected for Maven Projects.

## SCM support for uv

Snyk imports and tests `uv` Projects directly from your connected Git repositories.

Snyk resolves the following:

* Direct and transitive dependencies from `uv.lock`.
* Git-sourced dependencies (`[tool.uv.sources]` with a git entry) in a standard, non-workspace project, and their transitive dependencies.
* For `uv` workspaces, Snyk imports the root `pyproject.toml`. Snyk includes workspace members that the root depends on as path dependencies in the root Snyk Project's graph.

### Prerequisites

The repository must contain a `uv` project: a `pyproject.toml` and a `uv.lock` file in the same directory. Both files are required.

You must have a connected SCM integration on an Organization, on the Enterprise plan, with the uv SCM Preview feature enabled.

### How Snyk discovers uv Projects

When you import a repository, Snyk scans every directory for a `pyproject.toml` and `uv.lock` pair and creates one Snyk Project per pair.

* Both files must be in the same directory. If a directory contains only a `pyproject.toml` (no lock file) or only a `uv.lock` (no manifest file), Snyk does not create a Project.
* When both `uv.lock` and `poetry.lock` exist for the same `pyproject.toml` , `uv.lock` takes precedence, and Snyk identifies the Project as a `uv` Project.
* Snyk identifies a `requirements.txt` in the same repository as a separate pip Project, independent of the `uv` Project.
* Snyk identifies Projects by path. Two directories with byte-identical manifests, therefore, become two separate Projects.

Snyk does not support the following dependencies:

* Dev-dependency groups (PEP 735 `[dependency-groups]`)
* Mixed git/URL/path sources in workspace members
* Optional extras (`[project.optional-dependencies]`)


# Ruby

Snyk support for Ruby with Snyk Code and Snyk Open Source, including SCM import, CLI and IDE testing, and supported versions

## Applicability and integration

{% hint style="info" %}
Ruby is supported for Snyk Code and Snyk Open Source.
{% endhint %}

Available integrations:

* SCM import
* CLI and IDE: test or monitor your app

## Technical specifications

### Supported versions

Snyk supports the following Ruby versions:

| Ruby main version | Ruby specific version |
| ----------------- | --------------------- |
| `2.4.X`           | `2.4.0` to `2.4.10`   |
| `2.5.X`           | `2.5.0` to `2.5.9`    |
| `2.6.X`           | `2.6.0` to `2.6.10`   |
| `2.7.X`           | `2.7.0` to `2.7.8`    |
| `3.0.X`           | `3.0.0` to `3.0.7`    |
| `3.1.X`           | `3.1.0` to `3.1.7`    |
| `3.2.X`           | `3.2.0` to `3.2.9`    |
| `3.3.X`           | `3.3.0` to `3.3.9`    |
| `3.4.X`           | `3.4.0` to `3.4.5`    |

### Supported frameworks and libraries

For Ruby, the following frameworks and libraries are supported:

* ActiveRecord
* Connection
* grpc-ruby
* LibXML
* mysql2
* Nokogiri
* OpenSSL
* openai ruby client
* ruby-openai
* rexml
* Ruby On Rails
* sinatra
* sqlite3-ruby

### Supported package managers and registries

For Ruby, Snyk supports [Bundler](https://bundler.io/) as a package manager. All Gemfile and Gemfile.lock are compatible with the Ruby versions that Snyk supports.

As a package registry, [rubygems.org](https://rubygems.org/) is supported.

## Ruby for Snyk Code

For an overview of the supported security rules, visit [Ruby rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules).

For Ruby with Snyk Code, the following file formats are supported: `.erb`, `.haml`, `.rb`, `.rhtml`, `.slm`

Available features:

* Reports
* Interfile analysis

## Ruby for Snyk Open Source

{% hint style="info" %}
Depending on your plan, some features may not be available. For more information, see [plans and pricing](https://snyk.io/plans/).

Platform-specific packages are not supported. If these are present in your `Gemfile.lock`, this can cause an invalid Fix PR to be created. If possible, use the non-platform-specific variant of a package.
{% endhint %}

For Ruby with Snyk Open Source, the following file formats are supported: `gemfile`, `gemfile.lock`

Available features:

* Fix PRs
* License scanning
* Test your app's SBOM and packages using `pkg:gem` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command.

### Bundler support

Snyk supports testing, monitoring, and fixing Ruby Projects in the CLI and Git integrations that have their dependencies managed by [Bundler](https://bundler.io/) and comparing the specific dependency versions against the [Ruby vulnerability database](https://snyk.io/vuln?type=rubygems).

Snyk tests all Bundler groups. It is not possible to exclude certain groups, such as test or development groups.

### Manifest files supported for Ruby

For Ruby, Snyk supports the following manifest files:

* `Gemfile`
* `Gemfile.lock`

Snyk requires both files to be present to correctly test, monitor, and fix Ruby Projects.

### Private Gem sources

If your Gemfile needs access to private Gem sources, see [Private gem sources for Ruby configuration](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations/private-gem-sources-for-ruby-configuration).

Using private Gem sources should work normally when you are using the Snyk CLI.

When creating Fix PRs for Ruby Projects using private Gem sources, Snyk may need access to the service hosting the Gems to update the file correctly.

### Fixing vulnerabilities in your Ruby Projects

{% hint style="info" %}
For Ruby versions < 3.2, Snyk does not support pinning a specific version of Ruby in the Gemfile, for example, `ruby "2.7.7".` You must use a more permissive version range that encapsulates all point versions, such as`ruby "~> 2.7.x"`
{% endhint %}

Snyk can fix vulnerabilities by updating vulnerable gems using `bundle update` after modifying your Gemfile, adhering to the rules you have specified there as far as possible.

In some scenarios, Snyk cannot upgrade all dependencies to non-vulnerable versions. In this case, consider updating the rules in your Gemfile.


# Rust

Snyk support for Rust, with full Snyk Code coverage in Early Access on Enterprise plans and limited Snyk Open Source support

{% hint style="info" %}
Rust is supported for Snyk Code (full support) and for Snyk Open Source (limited support).
{% endhint %}

## Rust for Snyk Code

{% hint style="info" %}
Code analysis support for Rust is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

### Supported frameworks and libraries

For Rust with Snyk Code, the following frameworks and libraries are supported:

{% columns %}
{% column %}

* actix\_files
* actix\_identity
* actix\_multipart
* actix\_session
* actix\_web
* age
* ammonia
* async\_graphql
* axum
* diesel
* handlebars
* hyper
* iron
  {% endcolumn %}

{% column %}

* orion
* postgres
* reqwest
* ring
* rustcrypto
* sqlx
* tera
* tokio
* tokio\_dbs
* tonic
* uuid
* warp
  {% endcolumn %}
  {% endcolumns %}

For an overview of the supported security rules, visit [Rust rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules).

### Supported file formats

For Rust with Snyk Code, the following file formats are supported: `.rs`.

### Available features

* Support for Interfile analysis
* Reports

## Rust for Snyk Open Source

### Supported package managers and registries

For Rust with Snyk Open Source, the following are supported:

* Supported package registry: [crates.io](https://crates.io/)
* Supported files: CycloneDX and SPDX SBOMs

### Available features

* Test your SBOM containing `cargo` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command or API.
* Test your individual Rust packages using the [List issues for a package](/developer-tools/snyk-api/using-specific-snyk-apis/issues-list-issues-for-a-package) API.

{% hint style="info" %}
SCM import and the standard CLI commands `snyk test`, `snyk monitor` are not available.
{% endhint %}

Open Source scanning of Rust manifests and dependencies is limited to testing using the CLI command `snyk sbom test`, or through the Snyk API, using either SBOM testing or individual package testing. API access is available only with Ignite or Enterprise plans.

{% hint style="info" %}
License scanning is not available for Cargo.
{% endhint %}

### Scan Rust dependencies in bulk using the CLI

To do this:

* Use a third party tool to create a SBOM document from the `Cargo.toml` and `cargo.lock` file, in one of the supported SBOM formats.
* Use `snyk sbom test --file=<path to your SBOM>` to scan the SBOM document.

Alternatively, you can use the REST API, as follows:

* Use the REST API to `POST` the SBOM document to the `sbom_tests` endpoint.
* Retrieve the results by calling the `sbom_tests/{job_id}` endpoint. For more information, visit [SBOM](/developer-tools/snyk-api/reference/sbom) and [Test an SBOM document for vulnerabilities](/developer-tools/snyk-api/using-specific-snyk-apis/sbom-apis/rest-api-endpoint-test-an-sbom-document-for-vulnerabilities).

### Scan Rust dependencies individually using the API

To test your individual Rust packages from the Cargo package manager, you can use the [List issues for a package](/developer-tools/snyk-api/reference/issues) API. You can obtain the PURL from the metadata section of the package on [crates.io](http://crates.io) and it must adhere to the [purl specification](https://github.com/package-url/purl-spec).

Before using it in the API, ensure you URL encode it. For example, `pkg:cargo/sd@0.1.0` becomes `pkg%3Acargo%2Fsd%400.1.0`

This reports only the direct vulnerabilities for that package. For more information, visit [List issues for a package](/developer-tools/snyk-api/using-specific-snyk-apis/issues-list-issues-for-a-package).

### Gating commits and PRs

To avoid introducing vulnerabilities on commits and PRs, Snyk recommends incorporating the above testing into your CI/CD pipeline.


# Scala

Snyk support for Scala with Snyk Code and Snyk Open Source, including SCM import, CLI and IDE testing, and supported frameworks

## Applicability and integration

{% hint style="info" %}
Scala is supported for Snyk Code and Snyk Open Source.
{% endhint %}

Available integrations:

* SCM import
* CLI and IDE: test or monitor your app

## Technical specifications

Snyk supports the following Scala versions: 2.x

### Supported frameworks and libraries

For Scala, the following frameworks and libraries are supported:

* Akka
* HTTP4S
* io.cequence.openaiscala
* Play Framework
* Scala standard library
* Slick Framework
* Tapir Framework
* All [Java frameworks and libraries](/supported-languages/supported-languages-list/java-and-kotlin#supported-frameworks-and-libraries)

### Supported package managers and registries

* Supported package managers: [sbt](https://www.scala-sbt.org/)
* Supported package registries: [maven.org](https://maven.org/)

## Scala for Snyk Code

For an overview of the supported security rules, visit [Scala rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/scala-rules).

For Scala with Snyk Code, the following file format is supported: `.scala`

Available features:

* Reports
* Interfile analysis

{% hint style="info" %}
The **Snyk Fix PR** feature is not available for Swift and Objective-C. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}

## Scala for Snyk Open Source

For Scala with Snyk Open Source, the following file format is supported: `build.sbt`

Available features:

* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:maven` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command

For sbt, Snyk provides: CLI support, SCM support, and license scanning.

### CLI support for Scala

The [Snyk CLI](/developer-tools/snyk-cli/snyk-cli) uses the [`sbt-dependency-graph`](https://github.com/sbt/sbt-dependency-graph) plugin, which has been [included](https://www.scala-sbt.org/1.x/docs/Combined+Pages.html#sbt-dependency-graph+is+in-sourced) in `sbt` as a built-in plugin since `sbt` 1.4.

However, the recommended method of calling the plugin in sbt 1.4+ is not compatible with Snyk. Use the legacy method, `addSbtPlugin()` instead. Snyk recommends installing the `sbt-dependency-graph` as a [global plugin](https://www.scala-sbt.org/1.x/docs/Using-Plugins.html#Global+plugins) so you can use it in any `sbt` project.

To do this, add the plugin dependency to `~/.sbt/0.13/plugins/plugins.sbt` for `sbt` 0.13 or `~/.sbt/1.0/plugins/plugins.sbt` for `sbt` 1.0+.

To add the plugin to a single Project only, update the `project/plugins.sbt` of your Project instead.

Regardless of which `sbt` version you are using, you must use the following command in the relevant `plugins.sbt` file:

`addSbtPlugin("net.virtual-void" % "sbt-dependency-graph" % "0.10.0-RC1")`

{% hint style="warning" %}
Do not use the `addDependencyTreePlugin` command which the `sbt-dependency-graph` plugin docs recommend for `sbt` 1.4+. This is incompatible with the Snyk CLI. Use the `addSbtPlugin()` command as given above.
{% endhint %}

For more information on installing `sbt-dependency-graph` for use with the Snyk CLI, see [How to install the SBT dependency graph plugin to test Scala projects with Snyk CLI](https://support.snyk.io/s/article/How-to-install-the-SBT-dependency-graph-plugin-to-test-Scala-projects-with-Snyk-CLI).

### SCM integration support for Scala

You can import Scala `sbt` Projects from any of the supported Git repositories. For more information, see [Organization-level integrations](/developer-tools/integrations/scm-integrations/organization-level-integrations).

To test your Scala Projects using `sbt` as a package manager, Snyk analyzes your `build.sbt` file.\
To ensure that this works properly, you must have this file in your repository before importing your Projects.

You cannot declare versions of dependencies in a file that is not accessible to Snyk using a Source Code Manager (SCM) integration, for example, `Dependencies.scala`.

To ensure that your Scala dependencies are detected when you import your Projects using an SCM integration, your `build.sbt` dependencies must be declared in a format that Snyk can detect, for example:\
`"commons-io" % "commons-io" % "2.11.0"`.

You can use a version declared in a variable if the variable is in the `build.sbt` file, for example:

```scala
  lazy val derbyVersion = "10.4.1.3"
  libraryDependencies ++= Seq(
    "org.apache.derby" % "derby" % derbyVersion
  ) 
```

For more information, see [Differences in Open Source vulnerability counts across environments](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/manage-vulnerabilities/differences-in-open-source-vulnerability-counts-across-environments).


# Swift and Objective-C

Snyk support for Swift and Objective-C with Snyk Code and Snyk Open Source, including Early Access Objective-C code analysis on Enterprise plans

{% hint style="info" %}
Swift and Objective-C are supported for Snyk Code and Snyk Open Source.
{% endhint %}

## Swift and Objective-C for Snyk Code

{% hint style="info" %}
Code analysis support for Objective-C is in Early Access and is available only with Enterprise plans. To enable the feature, see [Snyk Preview](/platform-administration/snyk-hierarchy/snyk-preview).
{% endhint %}

For an overview of the supported security rules, visit [Swift rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/swift-rules) and [Objective-C rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/objective-c-rules).

For Swift with Snyk Code, Snyk supports Swift versions up to 5.7.x. You can use higher versions, but Snyk does not provide support for them.

### Supported frameworks and libraries

For Swift and Objective-C, the following frameworks and libraries are supported:

{% columns %}
{% column %}

* AFNetworking
* AlamoFire
* AppKit
* Asynchttpclient
* CocoaLumberjack
* CommonCrypto (Native API)
* Commoncrypt
* Cryptokit
* Cryptor
* Cryptoswift
* dylanshine/openai-kit
* Filekit
* FMDB
* Foundation
* google-gemini/generative-ai-swift
* IDZSwiftCommonCrypto
* JLRoutes
* MacPaw/OpenAI
* Mantle
* NSTask (Native API)
  {% endcolumn %}

{% column %}

* OneSignal-iOS-SDK
* Pathos
* Realm
* RNCryptor
* SDWebImage
* ShellOut
* Shout
* SQLite3
* Subprocess
* Swift standard library
* Swift UI
* SwiftCLI
* Swiftline
* SwiftShell
* UI Kit
* Webkit
* XLForm
* ZXingObjC
  {% endcolumn %}
  {% endcolumns %}

### Supported file formats

For Swift, Snyk supports .`swift`

For Objective-C, Snyk supports `.m` files, and implicitly supports `.h` files.

### Available features

* Reports
* Interfile analysis

## Swift and Objective-C for Snyk Open Source

For Swift with Snyk Open Source, Snyk supports Swifts versions from 3.0 up to 6.2.x.

### Supported package managers and registries

For Swift and Objective-C, Snyk supports the following package managers: CocoaPods, Swift Package Manager v3.0 or higher.

As package registries, Snyk for Swift and Objective-C uses multiple sources, including [cocoapods.org](https://cocoapods.org/) and [swiftpackageregistry.com](https://swiftpackageregistry.com/).

### Supported file formats

For Swift and Objective-C with Snyk Open Source, the following file formats are supported:

* For CocoaPods: `podfile` and `podfile.lock`
* For Swift: `package.swift`

For Swift and Objective-C with Snyk Open Source, Snyk provides support for package managers as follows:

* For CocoaPods: CLI support, Git support, License scanning
* For Swift Package Manager: CLI support

{% hint style="info" %}
The **Snyk Fix PR** feature is not available for Swift and Objective-C. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available**.
* **"Fixed in" available** is set to **Yes**.
  {% endhint %}

### Requirements for Swift Package Manager

{% hint style="info" %}
Snyk supports only Projects using Swift 3.0 or higher.
{% endhint %}

In order for Snyk to discover a Project, a `Package.swift` file must be present. Also, Snyk uses the `swift package show-dependencies` command to build the dependency graph.

When the .build folder of your Project is not present - in a pipeline, for example, it is possible that Snyk takes longer to scan your Swift Projects. When the CLI runs the command `swift package show-dependencies`, Swift must resolve the dependencies as part of this process, which can add to the overall time it takes Snyk to complete the scan. Therefore, ensuring that you have your Projects built first and that the .build folder is present can speed up the CLI processing time.

Swift Package Manager supports pre-processing and post-processing. For post-processing, custom commands can add extra dependencies. Detecting such dependencies is not supported.

It is not possible to scan Swift Package Manager Projects using SCM import.

### Cocoapods and CLI

To build the dependency graph, Snyk examines the `Podfile` and `Podfile.lock` files.

When working with Swift and Objective-C projects from the Snyk CLI, you can prevent testing any lock files that are out-of-sync by using the `--strict-out-of-sync=true`

For Cocoapods and Git, to test your Projects, Snyk analyzes the `Podfile` and `Podfile.lock` files.


# TypeScript

Snyk support for TypeScript with Snyk Open Source and Snyk Code, including SCM import, CLI and IDE testing, and JavaScript frameworks

## Applicability and integration

{% hint style="info" %}
TypeScript is supported for Snyk Open Source and Snyk Code.
{% endhint %}

Available integrations:

* SCM import
* CLI and IDE: test or monitor your app

## Technical specifications

You can use TypeScript versions up to 4.2

### Supported frameworks and libraries

Snyk supports all JavaScript frameworks and libraries. For more information, see [JavaScript frameworks and libraries](/supported-languages/supported-languages-list/javascript#supported-frameworks-and-libraries).

### Supported package managers and registries

For TypeScript, Snyk supports npm, pnpm, Yarn as package managers, with the following versions:

* npm: `Lockfile 1`, `Lockfile 2`, `Lockfile 3`
* pnpm: `pnpm 7`, `pnpm 8`, `pnpm 9`
* Yarn: `Yarn 1`, `Yarn 2`, `Yarn 3`

As a package registry, Snyk supports [npmjs.org](https://www.npmjs.org/).

## TypeScript for Snyk Code

For an overview of the supported security rules, visit [JavaScript and TypeScript rules](/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/javascript-and-typescript-rules).

For TypeScript with Snyk Code, the following file formats are supported: `.ejs`, `.es`, `.es6`, `.htm`, `.html`, `.js`, `.jsx`, `.ts`, `.cts`, `.mts`, `.tsx`, `.vue`, `.mjs`, `.cjs`

Available features:

* Reports
* Interfile analysis

## TypeScript for Snyk Open Source

For TypeScript with Snyk Open Source, the following file formats are supported:

* npm: `package.json` and `package-lock.json`
* pnpm: `pnpm-lock.yaml`
* Yarn: `yarn.lock`

Available features:

* License scanning
* Reports
* Test your app's SBOM and packages using `pkg:npm` PURLs through the [SBOM test](/developer-tools/snyk-cli/snyk-cli/commands/sbom-test) CLI command

{% hint style="info" %}
The **Snyk Fix PR** feature is not available for TypeScript. This means that you will not be notified if the PR checks fail when the following conditions are met:

* The **PR checks** feature is enabled and configured to **Only fail when the issues found have a fix available.**
* "**Fixed in" available** is set to **Yes.**
  {% endhint %}


# Getting started

How to start using Snyk, including supported browsers, prerequisites, and your first scanning and remediation tasks

{% hint style="info" %}
Ensure you use languages, package managers, and frameworks supported by Snyk. See [Supported languages, package managers, and frameworks](/supported-languages/supported-languages-package-managers-and-frameworks).
{% endhint %}

## Supported browsers

Snyk supports the latest versions of the following web browsers:

* [Chrome](https://www.google.com/chrome/)
* [Edge](https://www.microsoft.com/en-us/edge?form=MA13FJ)
* [Firefox](https://www.mozilla.org/en-US/firefox/new/)
* [Safari](https://www.apple.com/safari/) (except for [Opening Fix PR](https://docs.snyk.io/fix/snyk-pull-or-merge-requests))

{% hint style="warning" %}
Snyk requires Javascript to be enabled on your browser.
{% endhint %}

To start performing basic tasks in the Snyk application:

## Create or log in to a Snyk account

To create a free account or sign up for a pricing plan, navigate to [snyk.io](https://snyk.io/). For details, see [Snyk Pricing Plans](/implementation-guides/enterprise-implementation-guide/trial-limitations).

If your company has an existing Snyk account and uses single sign-on (SSO), use the SSO link provided by your administrators.

If your company requires an invitation to use Snyk, when you log in for the first time, you may see a list of Organizations, which in Snyk control access to Projects. To request access to an Organization, select the name of an Organization Admin in order to request access.

{% hint style="info" %}
If you log in with a different authentication provider from the one your company uses for the Snyk account, you create a new account. You will not be logged in to the correct Organization for your company.
{% endhint %}

When you log in to the Snyk Web UI, Snyk shows your preferred (default) Organization. Snyk also uses the settings for your preferred Organization when you test a Project locally using the CLI.

## Set up a Snyk integration

For Snyk to know where to scan, you must provide it with access to your environment. The type of integration you need depends on what systems you use, what you want to scan, and where you want to add the integrations - [Organization](https://docs.snyk.io/integrations/integrate-with-snyk) or [Group](https://docs.snyk.io/integrations/integrate-with-snyk). For information about available integrators, see [Snyk SCM integrations](https://docs.snyk.io/integrations/scm-integrations/organization-level-integrations) and [Integrate with Snyk](https://docs.snyk.io/integrations/integrate-with-snyk).

To scan your code, you must first integrate Snyk with the repository holding that code.

### Guided process

After creating a Snyk account, you can follow the optional getting-started walkthrough prompts to provide information and help Snyk guide your experience. This includes choosing an integration method, setting access permissions, configuring automation settings, and authenticating that integration.

Alternatively, if you want to scan your code without authenticating to your source code repository, you can select the CLI integration. This allows you to run scans from your local machine and upload results to your Organization in Snyk.

### Manual process

You can add an integration to Snyk manually at any point from the Snyk Web UI. To do this, navigate to **Integrations** > **Source Control**. For more information, see [Integrate with Snyk](https://docs.snyk.io/integrations/integrate-with-snyk).

{% hint style="info" %}
If an integration is already configured for your Organization, it is marked as **Configured**.
{% endhint %}

## Obtain and use your Snyk API token

{% hint style="warning" %}
Before authenticating, be sure you have set your region properly. For details, see [Regional hosting and data residency](https://docs.snyk.io/regional-hosting-and-data-residency), which has the [list of regional URLs](https://docs.snyk.io/regional-hosting-and-data-residency#regional-urls).
{% endhint %}

Your Snyk API token is a personal token available under your user profile. The Snyk API token is associated with your Snyk Account and not with a specific Organization.

Free and Team plan and trial users have access only to tokens under the user profile. Your personal tokens can be used to authenticate with the Snyk CLI running on a local or a build machine and an IDE when you are setting a token manually. Use a personal token with caution if you are authenticating for CI/CD or with the API, which is available for Enterprise plan users only.

#### Personal Access Tokens (recommended)

To create your Snyk personal access token:

1. Log in to Snyk and navigate to your personal account settings.
2. Navigate to **Personal Access Tokens** using the sidebar navigation.
3. Create your first personal access token by completing the form and clicking **Generate new token**.
4. Highlight and copy your personal access token.

{% hint style="info" %}
For more information, visit [Personal Access Tokens](https://docs.snyk.io/snyk-api/authentication-for-api/personal-access-tokens-pats).
{% endhint %}

#### Legacy API Tokens

To obtain your personal Snyk API token:

1. Log in to Snyk and navigate to your personal account settings.
2. In your **General** settings, under API Token, select **click to show**.
3. Highlight and copy your API key.

If you want a new API token, select **Revoke & Regenerate**, but this will make the previous API token invalid.

{% hint style="info" %}
For information on when to use an API token and when to use a service account token, available to Enterprise plan users only, visit [Authentication for API](https://docs.snyk.io/snyk-api/authentication-for-api).
{% endhint %}

## Import a Project to scan and identify issues

Snyk Projects are items that Snyk scans for issues, for example, a manifest file listing your open-source dependencies.

When you import a Project, Snyk scans that imported Project, and displays the results for you to review.

Importing a Project also does the following:

* Sets Snyk to run a regular scan on that Project for issues. See [Usage settings](https://docs.snyk.io/snyk-hierarchy/usage-settings).
* Initiates some automation, especially default Snyk tests on pull and merge requests, which help prevent vulnerabilities from being added to the Project. This automation fails builds according to your conditions and can be disabled or customized in your [integration settings](https://docs.snyk.io/integrations/scm-integrations/organization-level-integrations).

## Set up Snyk Essentials

{% hint style="info" %}
Snyk Essentials is available only with Enterprise plans. For more information, see [plans and pricing](https://snyk.io/plans/).
{% endhint %}

Snyk Essentials enables Application Security teams to implement, manage, and scale a modern, high-performing, developer security program. It covers use cases under Application Security Posture Management (ASPM).

For more information, see [Snyk Essentials](https://docs.snyk.io/scan-with-snyk/snyk-essentials).

## Review results and fix your issues

After you have imported a Project, and Snyk has scanned that Project for issues, you can view the results of your scan and take action to fix issues. You can see the number of issues found, grouped by severity level (**C**ritical, **H**igh, **M**edium or **L**ow). For details, see [Severity levels](https://docs.snyk.io/fix/prioritize-issues-for-fixing/severity-levels).

The scan results and available actions depend on the type of Project you scan:

* Open-source libraries: see [Snyk Open Source](https://docs.snyk.io/scan-with-snyk/snyk-open-source).
* Application code: see [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code).
* Hard-coded secrets, credentials, and API keys: see [Snyk Secrets](https://docs.snyk.io/scan-with-snyk/snyk-secrets).
* Container images: see [Snyk Container](https://docs.snyk.io/scan-with-snyk/snyk-container/scan-container-images).
* Infrastructure as Code (IaC), Kubernetes, Helm and Terraform configuration files and cloud misconfigurations: see [Snyk IaC](https://docs.snyk.io/scan-with-snyk/snyk-iac).


# Structure your account for high application performance

Guidelines for structuring Snyk accounts, Groups, Organizations, and Projects to maintain high performance at scale

To ensure the best experience using Snyk, consider these guidelines when making decisions about your Snyk user accounts, Groups, Organizations, and Projects.

## Structure of accounts for users

You can have a large number of users in your Organizations and Groups.

Snyk recommends structuring your Organizations so that there are no more than 2,000 users in each Organization.

If you have more than 2,000 users in an Organization, you begin to risk performance issues. When the application must load a large number of users, performance is slowed for the dashboard and the Group members management page.

If users have a large number of memberships in a given Group, all requests--in the Snyk Web UI and through the CLI and the API, are slowed because, on most requests, calculations and queries occur to check access and permissions.

## Structure of Groups

A small number of Snyk customers have more than one Group, for example, to keep different business units completely separate. However, anyone considering multiple Groups must understand the limitations of setting up their account with multiple groups.

Specifically, each Group is a standalone entity. This has the following consequences:

* The functionality for Groups is not tied together.
* There is no cross-Group reporting.
* Users, Projects, and Organizations cannot be shared between Groups.
* SSO is more difficult to manage across multiple Groups.
* Service accounts cannot span multiple Groups.
* Getting data for multiple Groups through the API requires multiple calls.

If you believe your business case requires multiple Groups, consult with your Snyk account team for assistance.

## Structure of Organizations

Using either the Snyk Web UI or the Snyk API, you can create a large number of Organizations in your Group. However, if you have more than 2,000 Organizations in your Group, you begin to risk performance issues.

When Snyk loads a large number of Organizations, these consequences follow:

* Performance is slowed for Group administrators and Group-level notifications.
* Group-level service account creation may fail.

## Structure of Projects

You can import a large number of Projects into your Organizations.

Snyk recommends limiting each Organization to **no more than 10,000 Project**s, and does not allow more than 25,000 Projects in each Organization.

If you need more than 10,000 Projects, consider how a large number of Projects affects the experience with slower performance for listing Projects, sending notifications, displaying the dashboard, and displaying the Usage page. Also, it is difficult to delete Organizations with a large number of Projects.

While there is no limit to the overall number of Projects across all Organizations in a Group, Group-level reporting and displaying dependencies and license issues are slowed when there are several hundred thousand Projects.


# Start scanning

How to scan your code with Snyk manually and automatically using the Snyk CLI, web UI, API, and PR Checks

<table><thead><tr><th width="220">Features</th><th width="126">Snyk Web UI</th><th width="111">Snyk CLI</th><th width="135">Snyk API</th><th>PR Checks</th></tr></thead><tbody><tr><td>Auto scanning</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td></tr><tr><td>Manual scanning</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td></tr><tr><td>Local scans</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td></tr><tr><td>Incorporate into the CI/CD pipelines</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td></tr><tr><td>Obtain results precisely reflecting the Project vulnerabilities and configurations</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td></tr></tbody></table>

<table><thead><tr><th width="190">Command</th><th width="236">Function</th><th>More details</th></tr></thead><tbody><tr><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/3TgqkqC2xA7DzvPAiT9j">snyk test</a></td><td>Scan open-source code</td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/JJALmpkBEQ1n1F1T9pFy">Use Snyk Open Source from the CLI</a></td></tr><tr><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/TY0yZvCmeGrtN6E6To4d">snyk code test</a></td><td>Scan application code</td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/dEvflY7lzsU5DwYDyBbj">Use Snyk Code from the CLI</a></td></tr><tr><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/WUxbuwAzJZomEt6HxUuU">snyk container test</a></td><td>Scan container images</td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/YnCzVNwBRDTTEKmnGxCJ">Use Snyk Container from the CLI</a></td></tr><tr><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/JnbupqcVED0Z5jZfJKZm">snyk iac test</a></td><td>Scan infrastructure as code (IaC) files</td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/zjReFVHAcLCvu6sE2yQG">Snyk CLI for IaC</a></td></tr><tr><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/yqBqf18shiuIZ4xyfeZN">snyk monitor</a> and <a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/cTHkickdLDFedMB4NutB">snyk container monitor</a></td><td>Continually monitor a Project for new vulnerabilities.</td><td><a href="/spaces/IEEjSXQQu36y0vmFV8zf/pages/DNysSyzuFfgmZvpFWq8y">Monitor your projects at regular intervals</a></td></tr></tbody></table>

You can use Snyk to scan your code manually and automatically using the [Snyk CLI](#scan-using-the-cli), the [Snyk web UI](#scan-using-the-web-ui), the [Snyk API](#scan-using-the-api), and by running [PR Checks](#using-pr-checks).

{% hint style="info" %}
Scans (tests) may be limited on your account, depending on your [pricing plan](/implementation-guides/enterprise-implementation-guide/trial-limitations). For more information, see [What counts as a test?](https://docs.snyk.io/what-counts-as-a-test)
{% endhint %}

<table><thead><tr><th width="220">Features</th><th width="126">Snyk Web UI</th><th width="111">Snyk CLI</th><th width="135">Snyk API</th><th>PR Checks</th></tr></thead><tbody><tr><td>Auto scanning</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td></tr><tr><td>Manual scanning</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td></tr><tr><td>Local scans</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td></tr><tr><td>Incorporate into the CI/CD pipelines</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2796">➖</span></td></tr><tr><td>Obtain results precisely reflecting the Project vulnerabilities and configurations</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2714">✔️</span></td></tr></tbody></table>

## Scan using the CLI

{% hint style="info" %}
See [Getting started with the CLI](https://docs.snyk.io/developer-tools/snyk-cli/getting-started-with-the-snyk-cli) for more details.
{% endhint %}

Use the following Snyk [CLI commands](https://docs.snyk.io/developer-tools/snyk-cli/cli-commands-and-options-summary) for specific scanning methods:

<table><thead><tr><th width="190">Command</th><th width="236">Function</th><th>More details</th></tr></thead><tbody><tr><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/test">snyk test</a></td><td>Scan open-source code</td><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-open-source">Use Snyk Open Source from the CLI</a></td></tr><tr><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/code">snyk code test</a></td><td>Scan application code</td><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-code">Use Snyk Code from the CLI</a></td></tr><tr><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/secrets-test">snyk secrets test</a></td><td>Scan for hard-coded secrets, credentials, and API keys</td><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/secrets-scanning-in-the-snyk-cli">Secrets scanning in the Snyk CLI</a></td></tr><tr><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/container">snyk container test</a></td><td>Scan container images</td><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-snyk-container">Use Snyk Container from the CLI</a></td></tr><tr><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/iac">snyk iac test</a></td><td>Scan infrastructure as code (IaC) files</td><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/monitor">Snyk CLI for IaC</a></td></tr><tr><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/monitor">snyk monitor</a> and <a href="https://docs.snyk.io/developer-tools/snyk-cli/commands/container-monitor">snyk container monitor</a></td><td>Continually monitor a Project for new vulnerabilities.</td><td><a href="https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/monitor-your-projects-at-regular-intervals">Monitor your projects at regular intervals</a></td></tr></tbody></table>

## Scan using the Web UI

A scan runs when you import a Snyk Project (see [Import a Project to scan and identify issues](/getting-started-guides/getting-started#import-a-project-to-scan-and-identify-issues) or click **Retest now** on a Project). Snyk then automatically runs periodic scans on that imported Project, to see if your code is affected by newly disclosed vulnerabilities.

The default scanning frequency and available frequencies vary depending on the type of Project. For more information, see [Usage settings](https://docs.snyk.io/snyk-hierarchy/usage-settings).

You can also set the frequency in the Project **Settings** (see [View and edit Project settings](https://docs.snyk.io/scan-with-snyk/snyk-projects/view-and-edit-project-settings)) or use the API Endpont [Updates project by project ID](https://docs.snyk.io/snyk-api/reference/projects#orgs-org_id-projects-project_id).

## Scan using the API

The Snyk API offers a set of endpoints to test your code. Scans are counted when calls are made to the test endpoint.

For more information, see the API [Test](https://docs.snyk.io/snyk-api/reference/test-v1) endpoint documentation.

## Using PR Checks

Snyk can scan every new Pull Request (PR) submitted on your monitored repositories to help prevent new vulnerabilities from being added to your codebase.

For more information, see [Pull Request Checks](https://docs.snyk.io/prevent/pull-request-checks).


# Getting started with the REST API

How to make your first Snyk REST API call with curl, including finding your Organization ID and authentication token

Follow these steps to make a simple call to the REST API using `curl` in the command line.

1. Log in to [Snyk](https://snyk.io/).
2. In your account, use the left navigation to find an **Organization** where you have Projects you can list.
3. Navigate to your **Organization Settings**, and on the **General** settings page, find your **Organization ID** and copy the value.
4. Navigate to your personal [General Account Settings](https://app.snyk.io/account/) and copy your **API Token**. For instructions, see [Authentication for API](/developer-tools/snyk-api/authentication-for-api).
5. Use a `curl` command to make your request. Replace the `{orgId}` and API\_TOKEN with your **Organization ID** and **API Token**, respectively. Snyk recommends using 2024-10-15 for the version number unless you are using an earlier version for a specific reason. Using the current day's date will call the most recent version of the API. An example follows:

```sh
curl --request GET \
--url "https://api.snyk.io/rest/orgs/{orgId}/projects?version=2024-10-15" \
--header "Content-Type: application/vnd.api+json" \
--header "Authorization: token API_TOKEN"
```

{% hint style="info" %}
The API URL to use when calling an API is different for different regions. For a complete list, see [API URLs](/developer-tools/snyk-api/rest-api/about-the-rest-api#api-urls).

As an example, the`SNYK-US-02`region API URLs are the following:

* **API V1:** <https://api.us.snyk.io/v1/>
* **REST API:** <https://api.us.snyk.io/rest/>
  {% endhint %}

Note that if you use the parameter `target-reference`, you must URL-encode it.

If you have any problems or questions, contact [Snyk support](https://support.snyk.io).


# Overview

Overview of implementing Snyk across your organization, from development through deployment, to fix vulnerabilities and build a security culture

Implementing a developer security tool like Snyk is critical to ensuring the security of your applications, from development through deployment. Whatever the size of your team, the goals are to fix vulnerabilities and foster a culture of security awareness and responsibility across your entire business.

Here is a brief overview of the process:

1. **Assessment**: Evaluate your current security practices and identify areas for improvement.
2. **Planning**: use the provided Project plans to outline your goals, timelines, and necessary resources.
3. **Configuration**: Follow configuration guidance to tailor the security platform to your needs, ensuring it integrates seamlessly with your existing tools and workflows.
4. **Rollout**: Implement the platform across your development teams, following the specific guidance for small teams or enterprise environments.
5. **Training**: Educate your developers on the importance of security and how to use the platform effectively.
6. **Monitoring and iteration**: Continuously monitor the health and performance of your applications and make adjustments as needed to maintain optimal security.

If you have a small team looking for guidance on rolling out Snyk in your processes, see the [Team implementation guide](/implementation-guides/team-implementation-guide).

If you are part of an enterprise implementing a large-scale rollout, see the [Enterprise implementation guide](/implementation-guides/enterprise-implementation-guide).

The guides include a downloadable project plan, a planning phase, configuration guidance, and guidance on rollout specific to each context.


# Auto-provisioning guide

How Snyk auto-provisions accounts for Pilot and Enterprise plans, including the setup questions you answer first

{% hint style="info" %}
**Feature availability**

Auto-provisioning is available only for customers starting a Pilot or Enterprise plan.
{% endhint %}

Provisioning is the first interaction you have with Snyk before getting access. You provide answers to the following questions about how you will be using the platform:

* What is the name of your business?
* Where do you want your data to be hosted?
* What is the authentication method your users will use to access Snyk?
* Do you already have a Snyk account you want to use (a previously completed Pilot), or do you want to start from scratch?

This guide covers the following aspects of automated provisioning:

1. [Prerequisites](#prerequisite-the-welcome-to-snyk-email)
2. [New account sign-up](#sign-up-start-from-scratch)
3. [Existing account sign-up](#logging-in-provision-using-an-existing-user-account)
4. [Error types and solutions](#error-types-and-solutions)

## Prerequisite: the "Welcome to Snyk" email

You should receive an email in your inbox containing links to start provisioning. Search for "Welcome to Snyk" as a subject, sent from <no-reply@snyk.io>.

If you have not received this email, look into your spam folder or reach out to your account executive.

This email contains two links:

1. **Log in and activate your existing account** - To be used if you already have an account and wish to apply your plan to it.
2. **Create and activate a new account** - To be used if you're entirely new to Snyk or want to start from scratch with a different user.

{% hint style="warning" %}
Once provisioning is complete, these links will become invalid, and you will see an "Access denied" error page.

If you have not completed provisioning but still see this error, make sure someone else in your organization has not already completed the flow themselves, in case the welcome email has more recipients.
{% endhint %}

## Sign up - start from scratch

Clicking the sign-up link in your welcome email will take you to the sign-up page in the provisioning app.

{% hint style="warning" %}
The provisioning app is only accessible through a unique link; all other access is disabled and will show an error page.
{% endhint %}

<figure><img src="/files/MsnYXJThmwY7KrJqKDhM" alt="Sign up page on provision.snyk.io"><figcaption><p>Sign up page on provision.snyk.io</p></figcaption></figure>

### Step 1: Enter the company name

The company name you enter here will be used to create the [Tenant](/platform-administration/snyk-hierarchy/tenant), the top-level instance you'll see in the Snyk Platform. It is a required field and has a 60-character limit.

Provisioning will also create a [Group](/platform-administration/snyk-hierarchy/groups) and a default [Organization](/platform-administration/snyk-hierarchy/organizations) using the same name.

### Step 2: Choose where to host the account

<div align="center" data-full-width="false"><figure><img src="/files/1Goj1oAWBu5FHas2zdBI" alt="Available hosting regions" width="375"><figcaption><p>Available hosting regions</p></figcaption></figure></div>

Snyk offers [regional hosting](/snyk-data-and-governance/regional-hosting-and-data-residency) to comply with regional data protection laws and improve service performance. This ensures data residency requirements are met and reduces data latency.

Provisioning is enabled for these [three regions](/snyk-data-and-governance/regional-hosting-and-data-residency#available-snyk-regions). Each of these regions is running at least one instance of the Snyk Platform:

* :flag\_us: **United States**: SNYK-US-01, SNYK-US-02
* :flag\_eu: **Europe**: SNYK-EU-01
* :flag\_au: **Australia**: SNYK-AU-01

In the case of [multiple instances](/snyk-data-and-governance/regional-hosting-and-data-residency#regional-multi-and-single-tenant-hosting) being available in a chosen region (United States), Snyk reserves the right to choose the specific instance where your account will be created. For more information, see [Regional Hosting and data residency](/snyk-data-and-governance/regional-hosting-and-data-residency).

If you select the United States region and use SSO for authentication, your account is provisioned on SNYK-US-02. Use <https://app.us.snyk.io> to access Snyk and <https://api.us.snyk.io> for CLI and IDE integrations. See[ Regional hosting and data residency](https://docs.snyk.io/snyk-data-and-governance/regional-hosting-and-data-residency) for the full list of regional endpoints.

{% hint style="warning" %}
Automated provisioning is only possible for multi-tenant environments. For single-tenant availability (Snyk Private Cloud), reach out to your account team in advance of provisioning.
{% endhint %}

### Step 3: Select an authentication method

<figure><img src="/files/69jjpoMkFEag0XLn722P" alt="Available authentication methods" width="363"><figcaption><p>Available authentication methods</p></figcaption></figure>

The available authentication methods are either Single Sign-On (SSO) or Third-party authentication.

1. **Single Sign-On** - use your company's existing identity management system, see [Single Sign-On (SSO) for authentication to Snyk](/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk) for more details.
2. **Third-party authentication** - Snyk supports a list of third-party identity providers; see [Authentication for third-party tools](/developer-tools/authentication-for-third-party-tools) for more details. This method is only available for the United States region.

#### Which authentication methods are available for each region?

| Region                   | Single Sign-On       | Third-party providers      |
| ------------------------ | -------------------- | -------------------------- |
| :flag\_us: United States | :heavy\_check\_mark: | :heavy\_check\_mark:       |
| :flag\_eu: Europe        | :heavy\_check\_mark: | :heavy\_multiplication\_x: |
| :flag\_au: Australia     | :heavy\_check\_mark: | :heavy\_multiplication\_x: |

Snyk recommends selecting SSO since it is best supported across all environments. Selecting this option will then prompt you to enter a valid, work-issued email address, used to create an initial Snyk Admin user. No extra configuration for SSO is required at this point.

<figure><img src="/files/RiNL3MABym6HuZKUzoEd" alt="Email address input" width="375"><figcaption><p>Email address input</p></figcaption></figure>

### Step 4: Confirm details and start provisioning

As a final step, you must confirm that the details entered are correct.

* If you have selected SSO as the authentication method, clicking "Sign up" will then show a loading page while Snyk does the background work.
* If you have selected Third-party authentication, clicking "Continue to sign up options" will redirect you to the Snyk Login page, where you can choose your identity provider (GitHub, Google, and so on). Once you have completed signing up, you will be redirected back to the provisioning application, where the loading page will indicate in-progress background work.

Snyk advises you not to close the page; otherwise, you risk not seeing the process complete successfully.

### Step 5: Access the Snyk platform

If you have selected SSO as the authentication method, once plan activation is done, you will see a success message and a verification button. Snyk also sends an email to indicate a successful provisioning containing the same login verification link. This link does not expire, and it can be used for multiple authentications if needed.\
\
Once clicked, a login code will be sent to the previously entered email address. This is known as a Passwordless Login. Enter the code where prompted, and you are ready to start using Snyk!

<figure><img src="/files/pvTCQQU34A2ok9fFIaSj" alt="Successful provisioning for SSO" width="375"><figcaption><p>Successful provisioning for SSO</p></figcaption></figure>

If you have selected **Third-party authentication**, once plan activation is done, you are all set! You can click "Continue to your account" and start using the platform.

{% hint style="info" %}
Your plan might not have all the features enabled if your contract's start date is in the future. You will gain full access to all features when the start date is met.
{% endhint %}

## Logging in - provision using an existing user account

Clicking the sign-up link in your welcome email will take you to the login page in the provisioning app.

### Step 1: Logging in

If you have a user account connected through a third-party provider, you will need to use SNYK-US-01

You can find the links for all the regions in the [Login and Web UI URLs section](/snyk-data-and-governance/regional-hosting-and-data-residency#login-and-web-ui-urls).

<figure><img src="/files/esWxPzhW06J0h2KNjDmt" alt="Log in page on provision.snyk.io"><figcaption><p>Log in page on provision.snyk.io</p></figcaption></figure>

### Step 2: Select an existing Tenant or start fresh

<figure><img src="/files/6s5BWHYzmkhC1qVyD0hV" alt="Linking to an existing Tenant or creating a new one" width="375"><figcaption><p>Linking to an existing Tenant or creating a new one</p></figcaption></figure>

If you already have a Snyk User, you can choose how you activate your Enterprise plan or Pilot after logging in:

* Linking the plan to an existing [Tenant](/platform-administration/snyk-hierarchy/tenant).\
  If your user is a member of multiple Tenants, you have the option to choose between them. Click the card of the Tenant you wish to select and then click "Confirm and activate".
* Starting fresh with a new [Tenant](/platform-administration/snyk-hierarchy/tenant) linked to your user.\
  Click "Create new Tenant account" and enter the company name. It's the same field as [#step-1-enter-the-company-name](#step-1-enter-the-company-name "mention") of signing up. You will be asked to confirm the name you entered before starting the provisioning process.

### **Step 3: Access the Snyk platform**

This step is the same as [#step-5-access-the-snyk-platform](#step-5-access-the-snyk-platform "mention") when signing up. Once the process is done, you can "Continue to your account" and begin using Snyk.

{% hint style="info" %}
Your plan might not have all the features enabled if your contract's start date is in the future. You will gain full access to all features when the start date is met.
{% endhint %}

## Error types and solutions

### Validation errors

When creating a new Tenant or User, Snyk checks for duplicates and surfaces any issues.

* **The business name provided is already in use.** - Use a different name or reach out to your account executive if you want to link your plan to that existing Tenant, but you are not a member of it.

<figure><img src="/files/hp6WGEVmgfkaWbIbF0q7" alt="Business name already in use error" width="375"><figcaption><p>Business name already in use error</p></figcaption></figure>

* **An account with this email already exists.** - In this scenario you can use a different work email address or you can login ([#logging-in-provision-using-an-existing-user-account](#logging-in-provision-using-an-existing-user-account "mention")), then create the new Tenant.

<figure><img src="/files/VjkdLptsSxi38uqawnOM" alt="User with the same email address already exists error" width="375"><figcaption><p>User with the same email address already exists error</p></figcaption></figure>

### Plan Activation errors

Snyk is doing its best to ensure that you never see this screen, but in case you do, save the **reference ID** and send it to your account executive or reach out to support with the reference ID and the steps taken.

<figure><img src="/files/o3ntAgzNWFFBKFo2fF2p" alt="Plan activation error" width="375"><figcaption><p>Plan activation error</p></figcaption></figure>


# Team implementation guide

Guide to implementing Snyk for a team on the Team plan, covering discovery, configuration, visibility, and a fix strategy

Accelerate your team performance by using Snyk. This guide aims to help you implement Snyk for your team. The team plan applies to teams of up to 10 members.

We start with the awareness that most businesses:

* Have a backlog of issues in their existing software
* Are continuously creating new software and need to secure new code.

## **Typical timelines**

Once your Snyk Organization is set up, you can immediately start gaining visibility into your code by integrating your code repositories (with PR checks disabled), CI/CD pipelines, or container registries.

To minimize disruption, Snyk recommends a gradual rollout of your "shift left" security strategy, focusing on backlog remediation and prevention. Key recommendations include providing developers with access to the IDE and piloting on a single Project before expanding best practices to the wider team.

## Implementation strategy overview

This guide is composed of multiple phases, outlining a series of actions configuring your account, as well as actions outside the system, that align with the following goals:

* [Achieve visibility](#achieve-visibility)
* [Achieve prevention and drive developer adoption](#achieve-prevention-and-drive-developer-adoption)
* [Fix the backlog and triage issues](#fix-the-backlog-and-triage-issues)

### Achieve visibility

If you focus on visibility first, you can get a clear sense of the security issues, but without always fixing them.

{% hint style="info" %}
This does not stop you from fixing issues using Snyk. You can start fixing issues early, but the emphasis is to avoid blocking development early on, build trust, and slowly introduce gating in later phases, usually the prevention phase. This is true of the smallest or largest teams - communication is key.
{% endhint %}

Visibility achieves a broad view of security across your application portfolio, avoids Snyk scans being seen as a blocker, and minimizes impact on development processes.

This visibility helps build trust while rolling out Snyk. With the Team plan, this equates to onboarding your projects through Git repository and disabling PR Checks/Auto PRs in the integration settings. Choose an important project and enable PR checks after communicating with the relevant team members. This guide details this later on.

### Achieve prevention and drive developer adoption

Next is the prevention stage. You should stop new security issues from being added to your applications. During this stage, you can put controls in place to allow developers to see issues in their pipelines using Pull Request (PR)/Merge Request (MR) checks, and checks in the pipeline that may block.

As part of this, developers may use IDE plugins and other tools like [Snyk Advisor](https://snyk.io/advisor) to select secure packages and [Snyk Learn](https://learn.snyk.io/) to educate on secure coding, security, and the product. It's quite common to see developers download and use IDE plugins. Provide guides indicating the settings they should use and guidelines on what they should fix to start often Criticals and Highs, where fixes are available.

### Fix the backlog and triage issues

Finally, you can focus on fixing your backlog of security issues. This can take several forms:

* As part of the initial rollout, security or initial stakeholder may triage the initial results for the existing portfolio, create tickets for priority items to investigate or address, or have the teams do that for their applications as part of the weekly triage process.
* After gaining visibility and achieving prevention, you can review your backlog of issues. For example, a weekly triage process with the key stakeholders can guide the teams on what to address.

## Use enhanced resources with Snyk

Snyk was built with developers in mind, providing:

* Tools to create secure applications using integrations for IDE, Git, and CI/CD.
* [Snyk Advisor](https://snyk.io/advisor) and other tools to make decisions.
* [Snyk Learn](https://learn.snyk.io) training materials on products, securing code, and best practices.


# Prerequisites: project plan templates

Downloadable project plan templates and suggested timelines to guide your Snyk team implementation

The templates provided below are the basis of the following sections of this guide.\
You can download and use these templates in your project management system.

{% hint style="info" %}
The suggested timelines are typically for individual teams and small companies, which may involve a small team or company. Adjust accordingly for what makes sense for your company.
{% endhint %}

You can download or import these plans:

* Comma Separated Values (.csv) - [*Download*](https://assets.ctfassets.net/4un77bcsnjzw/5IT8v4WlcYTlq5LHYGC82T/62b88657a50d1051b45c752c72252175/Team_Implementation_Project_Plan.csv)
* .csv formatted for Asana - [*Download*](https://assets.ctfassets.net/4un77bcsnjzw/2xnLzEX3mZ9oxqCPS3m9qd/3e5ac6f600109f401f63f082045053b0/Team_Implementation_Project_Plan_-_Asana.csv)
* Microsoft Excel - [*Download*](https://assets.ctfassets.net/4un77bcsnjzw/6UGko1dUlCd9kCZt4BqkKe/d6a46b052f2ebf873ad84c6e8b8e0b60/Team_Implementation_Project_Plan.xlsx)


# Phase 1: Discovery and planning

Phase 1 of the Snyk team implementation: validate your plan, run discovery, and plan your rollout

## Discovery phase steps

* [Validate your Snyk plan](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/validate-your-snyk-plan): confirm your license has been applied correctly.
* [Conduct discovery](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/discovery): identify stakeholders, integrations, and applications to monitor.
* [Name your Organization](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/name-your-organization): decide what to name your Organization.
* [Determine user roles](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/determine-member-roles): who will be administrators?
* [Plan for success](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/plan-for-success): decide how to judge the success of your rollout.
* [Choose rollout integrations](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/choose-rollout-integrations): decide which integrations to implement initially.
* [Create rollout plan](/implementation-guides/team-implementation-guide/phase-1-discovery-and-planning/create-rollout-plan): create your high-level plan for rolling out Snyk in your business.

## General pre-rollout questions

Before starting rollout, here are some initial questions you can ask to assist in planning, as an alternative way of deciding your rollout planning process.

### Who's involved?

* Who will manage and oversee the project?
* Who will champion Snyk?
* Who will be the administrators?

### What are your goals?

* Why did you choose Snyk?
* Why are you implementing it now?

### How will your users use Snyk?

How will you provision users, and integrate Snyk with your platforms?

* Who will need access to Snyk?
* Who can grant Snyk access to platforms like Git Repositories?

### What will you name your Organization?

* What will you name the Organization in Snyk? The Organization name will be public to all users.

### How will you measure success?

* What KPIs will be tracked?
* How will you know you’re making progress?
* Are there key development projects that progress tracking should be aligned with, or at least included to measure progress against?


# Validate your Snyk plan

How to confirm your Snyk license is applied correctly to your Organization in Usage, Plans, and Billing

Confirm your Snyk license has been applied correctly. Navigate to your Organization by clicking the Organization name on the left menu and click **Settings**. Confirm the license has been applied to this Organization by reviewing Usage, Plans, and Billing. Tests should be unlimited for the products purchased, and a Team plan should be indicated.

The proper license setup ensures you can fully use Snyk capabilities without limitations. It also guarantees you remain compliant with Snyk terms of use. If the license was incorrectly assigned, contact Snyk support.


# Discovery

How to identify business-critical applications, stakeholders, and success metrics before rolling out Snyk

## Identify business-critical applications

Identifying key applications early helps you identify important contacts to make, helps define success metrics, and helps early prioritization. Your business may have thousands of applications, but can you identify a few key applications to benchmark progress and priority?

For large enterprises, you can import everything, but that additional information can be collected in parallel to help prioritize work and measure success. This should not be a blocker or delay, it can be done in parallel in the planning and implementation phases.

## For implementations in smaller organizations/startups - confirm internal points of contact and roles

To successfully implement Snyk, you must identify the skills needed and the stakeholders who will be involved. For example, you must identify people who can:

* Perform the initial setup/admin tasks.
* The developers who may want to trial the workflows/functionality.
* Generate tokens with the necessary permissions for git repositories, and other integrations being considered like Jira, or container registries.
* Modify pipeline scripts.
* Who would want input on open-source licensing if this was a priority for purchasing, otherwise the default policy is often sufficient.
* Any stakeholders that need to be reported to.

## For implementations for a Team plan within an Enterprise - identify stakeholders with a RACI matrix

In smaller organizations where a few individuals may have the necessary access, involving the stakeholders can be quick and easy. For a small team, early startup, it can be as simple as finding who can create credentials for Snyk to access the system or update a CI/CD script. In a larger enterprise, where you may have a single team using Snyk, this tends to be more organizationally complex, and the following RACI matrix can assist in determining:

* **R**esponsible: the person ultimately accountable for carrying out the task or deliverable.
* **A**ccountable: the approver who must sign off on work before it is considered complete.
* **C**onsulted: those whose opinions are sought, two-way communication.
* **I**nformed: kept up-to-date on progress, one-way communication.

For large enterprises, the following RACI matrix is useful to clearly define roles and responsibilities during rollout:

<table><thead><tr><th width="179">Task</th><th width="136">Champion</th><th width="146">Admin</th><th width="132">Security</th><th>DevOps</th></tr></thead><tbody><tr><td>Onboarding</td><td>Responsible</td><td>Responsible</td><td>Responsible</td><td>Responsible</td></tr><tr><td>Admin Training</td><td>Accountable</td><td>Responsible</td><td>Consulted</td><td>Responsible</td></tr><tr><td>Security Training</td><td>Responsible</td><td>Consulted</td><td>Accountable</td><td>Responsible</td></tr><tr><td>DevOps Training</td><td>Responsible</td><td>Consulted</td><td>Consulted</td><td>Accountable</td></tr><tr><td>Source Control/IDE/PIPELINE Setup</td><td>Responsible</td><td>Responsible</td><td>Responsible</td><td>Accountable</td></tr><tr><td>License Policy Management</td><td>Responsible</td><td>Responsible</td><td>Responsible</td><td>Accountable</td></tr><tr><td>Security Triage</td><td>Responsible</td><td>Consulted</td><td>Accountable</td><td>Consulted</td></tr></tbody></table>

This ensures all stakeholders are engaged in suitable capacities without duplicated or neglected efforts. Following the matrix enables smooth collaboration, with individuals contributing specialized skills within their designated areas.

The clear delineation of duties promotes productivity, efficiency, and accountability. Overall, the RACI framework is an effective method for orchestrating a structured, well-coordinated onboarding process resulting in the successful implementation of Snyk.


# Name your Organization

How to name your Snyk Organization and plan your account structure of Groups and Organizations

Organizations contain your scan, setup integrations, and view results.

The first step is to set the name of your Organization to be used by Snyk and others when referring to Snyk.

## Introduction to structure

<div align="left"><figure><img src="/files/xQsWHMzKEvN6i9BpxOrY" alt="Determine your account structure"><figcaption><p>Determine your Snyk account structure</p></figcaption></figure></div>

Snyk uses a hierarchical approach to managing assets, access, and rollup reporting.

* **Snyk Tenant:** A Tenant encompasses the entire Snyk workspace of your company, team and individual users. It is typically named after your company.
* **Snyk Group:** This is the top entity used to group Organizations. Groups are typically named after your company or line of business.
* **Snyk Organizations**: below the Group level, typically representing:
  * Line of business
  * Git organization or team structure
  * Types of application
  * Development teams
* **Snyk Projects:** The targets you have tested/monitored with Snyk, such as a CLI scan, a container being monitored in registry, or open source files identified.

All customers have a Group and at least one Organization. On the Free and Team plans, you can create up to five Organizations in your Tenant. On the Enterprise plan, you can create an unlimited number of Organizations.

For more details, visit [Manage Groups and Organizations](/platform-administration/snyk-hierarchy/groups-and-organizations).

{% hint style="info" %}
If you have hundreds or thousands of repositories, consider the Snyk Enterprise plan for access to additional organizations to restrict access, separate reporting, and manageable lists to interact with.
{% endhint %}


# Determine user roles

How to choose Snyk user roles for your team, including the fixed default roles and permissions on the Team plan

## Default roles

A key consideration when setting up Snyk is determining which [default user roles](/platform-administration/user-management/pre-defined-roles) align with your needs.

The Team plan has the following fixed roles in Snyk, each with a fixed set of permissions. These permissions cannot be changed on the Team plan.

The following are the default roles:

* **Org Admin**: Typically assigned to team leads. Users with this role can add/delete Projects, override Snyk checks, and provision users. It is common to assign this to team leads, admins, and security team users.
* **Org Collaborator**: This is the default role in Snyk used for developers. This role is ideal for small teams or for a very developer-first organizational approach.

{% hint style="info" %}
If you need more granularity in roles/permissions, consider upgrading to Snyk Enterprise Plan to access Custom Roles and SSO functionality.
{% endhint %}


# Plan for success

How to define success metrics and KPIs to measure the impact of your Snyk implementation

## Determine success metrics with Snyk

Implementing Snyk provides an opportunity to enhance your application security. But how do you know if you're getting the most out of it? Key Performance Indicators (KPIs) are essential measurements that track Snyk's impact and help guide your security journey.

KPIs give you valuable insights by monitoring key metrics at each adoption phase - from raising awareness to preventing new issues. They help you:

* Assess progress toward security goals
* Identify areas needing improvement
* Demonstrate Snyk's value to stakeholders

Tracking metrics aligned to each stage provides tangible insights into what's working well and where improvements may be needed. KPIs help optimize your use of Snyk and progress your application security program.

## Example metrics

These are just some potential examples of success metrics to consider. Analyzing relevant data points at each stage can provide insight into what's working well and identify areas for improvement.

### Gain visibility

* Percentage of Projects that have been successfully scanned for vulnerabilities
* The number of critical and high-severity vulnerabilities identified
* Mean time to complete the initial scan for a Project
* Progress in prioritizing vulnerabilities by severity level

### Prevent new issues

* Percentage of pull requests or builds that are failing based on Snyk automation
* Reduction in new vulnerabilities introduced after automation is turned on
* Time taken to address blocked pull requests and resolve them

### Build awareness

* Number of developers who have been introduced to Snyk
* Percentage of Projects that have been tested with Snyk during this phase

### Fix backlog

* Percentage of existing vulnerabilities that have been resolved
* Mean time to fix vulnerabilities from the backlog
* Number of auto-fix pull requests raised and successfully merged
* Progress in using Jira integration for managing vulnerabilities and tracking fixes


# Choose rollout integrations

How to choose which Snyk integrations to roll out across the SDLC, from automated scans to developer tools

## **SDLC integration points**

Snyk offers many integrations that seamlessly integrate into every stage of the SDLC.

Many businesses typically roll out automated solutions first, then slowly introduce tools to enable the developers. In addition, gating features are gradually turned on over a period of time to minimize disruption.

{% hint style="info" %}
As using multiple integrations can result in duplicate reporting of issues, you do not initially need to implement more than one integration type. For example, you can start by importing everything with Git repositories, then later use the CI/CD view for fine-grained detail (potentially removing the source control integration if both views are not desired).
{% endhint %}

## Integration types

Below are typical early integrations.

### Source Code Management (SCM) integrations

Integrations with popular version control platforms like GitHub, GitLab, Azure Repos, and Bitbucket seamlessly integrate Snyk security checks into the code review process. This ensures that potential vulnerabilities are identified and addressed before the code is merged into the main branch. Important features include:

* Daily testing/monitoring of a specified branch (typically "development" branch),
* (optional) Pull Request/Merge Request checks against any branch of the repository.
* (optional) Automated dependency upgrades and automated security fix upgrades using pull requests.

Advantages:

* Visibility into repository security posture
* Automatic Scan on code change
* Immediate feedback on issues for the developer
* Onboarding of repositories can be configured using the UI
* Supports Cloud Repositories on the Team plan

For more details, see [Git repositories (SCMs)](/developer-tools/integrations/scm-integrations/organization-level-integrations).

{% hint style="info" %}
If you have a non-cloud-facing or your own instance of a Git SCM:

* Consider deploying a [Snyk Broker](/platform-administration/snyk-broker/snyk-broker) for Snyk to communicate with your repositories, which would also require a Snyk Enterprise Plan.
* Enterprise customers can enable and manage Snyk Broker using the API.

[Paid services](/snyk-data-and-governance/snyk-terms-of-support-and-services-glossary) can be engaged to assist in Broker deployments.
{% endhint %}

### Continuous Integration/Continuous Deployment (CI/CD) pipeline integrations

Integrating Snyk into CI/CD pipelines, such as Jenkins, Travis CI, or CircleCI, automates security checks during the build and deployment process. This ensures that vulnerabilities are detected early in the software development lifecycle and prevents their propagation into production. Typical features include:

* (Optional) Ability to passively monitor results during build and view results in Snyk
* (Optional) Ability to test and potentially break the build based on criteria you specified
* Integration can be achieved with specific Marketplace plugins or more generally, with the CLI as part of your pipeline script.

Advantages:

* Assess local code vulnerabilities
* Full control over testing (which tests to run, where in the build script)
* Can automate using CI/CD

For more details, see [Snyk CI/CD integrations](/developer-tools/integrations/snyk-ci-cd-integrations).

### Integrated Development Environment (IDE) integrations

IDE integrations like Visual Studio Code, IntelliJ IDEA, and Eclipse allow developers to access Snyk's security features directly within their coding environment. This enables real-time scanning and issue remediation as developers write code at the earliest possible stages.

For more details, see [Use Snyk in your IDE](/developer-tools/integrations/snyk-ide-plugins-and-extensions).

## Considerations for import strategies

<table><thead><tr><th width="200">Project Import Strategy</th><th>Considerations</th><th>Advantages</th><th>Disadvantages</th></tr></thead><tbody><tr><td>CLI (automated CI/CD)</td><td>Must be configured for each application within CI/CD.</td><td><ul><li>Can select what to test and when (i.e. which package managers, where in the process, which language to analyze.</li><li>May need development effort for integration.</li></ul></td><td>It requires configuration per application.</td></tr><tr><td>CLI (Run locally by user)</td><td>User can use CLI to perform testing locally while working on an application, very configurable per scan type.</td><td>Local use case</td><td>Not meant for visibility or automation. Can require buildable code or dependencies to be installed (For example Gradle without Lockfile, Scala).</td></tr><tr><td>Git Code Repository Integration</td><td>Onboarding and daily monitoring: rapid vulnerability assessment across application portfolio.</td><td><ul><li>Continuous monitoring of repositories (even when you are not working on it).</li><li>Centralized visibility for teams.</li><li>Monitors specified branch</li><li>Code does not need to be built.</li></ul></td><td><ul><li>Can be initiated via UI</li><li>Some languages/package managers have better resolution utilizing the CLI (Gradle without lockfile, Scala).</li></ul></td></tr><tr><td></td><td>Pull request (PR)/merge request (MR) scanning</td><td>Immediate feedback on introduced issues on the PR/MR against any branch on repository.</td><td>Configurable rules for pass/fail</td></tr></tbody></table>

## Additional considerations

### Infrastructure as Code

For Snyk Infrastructure as Code, it is common that your Terraform or YAML configuration files are held in your SCM, but they may be in a separate area or repository. As a result, consider if there are other areas you need to import. You may also want to integrate with Terraform Cloud (if applicable) to enable Snyk tests as part of your "Terraform run" processes.

For complex environments, modules, and highly templated implementations, utilizing the CLI on your Terraform Plan file may provide the best results.

### CR (Container Registries)

Snyk also integrates with various [Container Registries](/scan-fix-and-prevent/scan-with-snyk/snyk-container/container-registry-integrations) to enable you to import and monitor your containers for vulnerabilities. Snyk tests the containers you have imported for any known security vulnerabilities found at a frequency you control.


# Create rollout plan

How to create a Snyk rollout plan paced to the security maturity and compliance needs of your team

Every business is different. If your teams have already used security tools and are in a heavily compliance-focused industry, controls may be turned on relatively more quickly. However, if security as part of development is new, rolling out tools and controls in phases is strongly suggested.

## Suggested onboarding approach

When you are introducing Snyk to your business, Snyk suggests the following phased rollout after configuring integrations.

### 1. Kick off with a pilot team

Start by selecting a small group of engaged pilot users from:

* Application security teams (if applicable)
* Project teams building new applications
* Developers of business-critical applications.

This allows you to:

* Thoroughly onboard initial users
* Gather feedback to refine processes
* Identify issues before the broader rollout
* Build success stories to promote Snyk.

Typically, importing everything using a repository integration for visibility and working through the rollout with a small pilot team allows you to identify the best processes and ways to implement Snyk within your environment.

### 2. Gain visibility with Git repository integration

Next, set up Snyk integrations across your Git repositories to gain broad visibility into your security posture.

{% hint style="info" %}
To reduce noise, disable notifications before import if you have onboarded all your users.
{% endhint %}

The key advantages of using this process are:

* Widespread scanning across your codebase
* Automatic scanning triggered on code changes
* A convenient way to gain coverage.

### 3. Prioritize key applications

Have your pilot team focus on securing priority applications using targeted Snyk CLI scans.

The key advantages of using this process are:

* Enhanced visibility into critical apps
* Fine-tuned CLI testing for precision
* Removing repo noise for a focused view.

### 4. Expand access

With priorities addressed and processes refined, start expanding access more broadly across teams.

This phased approach allows thoughtful onboarding while rapidly gaining visibility and control.

### 5. Turn on gating

After the first month, gradually turn on gating measures.

* Pull Request/Merge Request Checks using criteria such as `severity` and `is fixable`.
* Fail builds based on criteria such as `High` or `Critical`, `CVSS`, `Mature Exploit` for Open Source and other criteria using the [Snyk Filter](https://github.com/snyk-labs/snyk-filter) plugin.

It's recommended to start with a few applications, especially during the pilot team phase, work through the processes then roll out more widely.

## Exception handling

Ensure there is an exception process in place and users are aware. For example:

* If a pull request/merge request is failed by Snyk, let the users know who is the Snyk admin who can override it.
* Similarly, if Snyk fails in CI/CD, let users know who can create an ignore rule, authorize it to progress, or configure CI/CD to run without the Snyk `test` or set it to `monitor` only.


# Phase 2: Configure your Organization

Phase 2 of the Snyk team implementation: name and configure your Organization and its integrations

## Name your Organization

This step is easiest performed prior to purchasing the license. If you did not, Snyk support can assist you.

### Changing the name prior to purchase

Click the arrows next to your Organization name, click **Create New Organization**. From the **Settings-Plans and Billing** page, purchase a team plan.

### Changing the name after purchase

After determining the name of your Organization in phase 1, navigate to **Settings** in the Snyk web UI and update your **Organization** **name**.

{% hint style="info" %}
You must contact Snyk support and submit a ticket to update the url slug. This can impact any existing CI/CD scripts that your team has previously created, so this step should be performed as early as possible and be communicated to your team if CLI has been in use for a while.
{% endhint %}

## Additional settings to consider

* Enable Snyk Code, if purchased, under **Settings-Snyk Code**.
* Require reason to ignore issues in **Settings**.
* Disable notifications at the Organization level under **Settings**. You can re-enable notifications after importing in the later step. This reduces noise during early testing/importing and is more appropriate for a steady state of the implementation.

### License policy (optional)

Snyk comes with a default policy. You can find this under **Settings-Licenses** if your team wants to add custom text when an issue is found or change severities for specific licenses.

Administrators can set license policies to define Snyk behavior for treating license issues. For example, you can allow or disallow packages with certain license types to avoid using packages containing incompatible licenses.

By default, Snyk determines the severity of licenses as follows:

* High severity - licenses that present issues for commercial software.
* Medium severity - licenses that have clauses that may be of concern and should be reviewed.

Configure policies to match your requirements.

For details, see [Getting Started with Snyk License Compliance Management](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/snyk-license-compliance-management).


# Configure integrations

How to configure Snyk SCM and CI/CD integrations for your Organization, including recommended settings

Integrate Git or CI/CD integrations as identified in the previous phase.

## Git repositories

For Git integration, Snyk suggests the following settings:

To disable gating initially, use the daily monitoring that is automatically configured when a Project is onboarded in Snyk, and disable the following PR/MR Checks in the configuration settings:

* Automatic fixes Snyk can position
  * Automatic fix PRs
  * Automatic dependency upgrade PRs
  * Snyk vulnerability patches.
* Pull request status checks for
  * Open Source security and licenses
  * Code analysis

## CI/CD (Build pipelines)

Keep your applications secure by preventing deployment of vulnerable applications or components (registries), adding Snyk in the build as a step of the pipeline.

The CLI provides:

* Better resolution of dependencies for a number of specific package managers (such as Scala, Gradle, and GO).
* Supports private packages without having to configure an additional integration, providing that your build environment will have access to your private packages.
* Give visibility to components that are pushed to production by either breaking builds and reporting to Snyk or only reporting to Snyk.

There are several [CI/CD integrations](/developer-tools/integrations/snyk-ci-cd-integrations) available, or you can use the [Snyk CLI](/developer-tools/snyk-cli/snyk-cli) as part of your pipeline, in order to have more flexibility in the tests you are running.

In the initial phase, Snyk recommends using the “monitor” feature to import information into Snyk so you can see any discovered issues (unless you are already importing your repos using a source control integration to achieve this). Later, when you want to start gating/blocking new vulnerabilities from being added, you can introduce “test” features - initially failing builds on critical issues and then gradually adapting the fail criteria over time.

{% hint style="info" %}
For `snyk iac test --report`, finding issues will result in the build possibly stopping with a non-zero response code.\
\
If you want to test passively, the inclusion of the `--report` argument requires either setting the build step to always continue or an alternative like concatenating logic equating to "or true" (for example `snyk iac test --report || true`). The exact syntax depends on the ecosystem the CLI is run in.
{% endhint %}

When configuring pipelines, you can use popular plugins like [`snyk-filter`](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter) for advanced filtering.

{% hint style="info" %}
Some plugins that require API access may not be usable on the Team plan, as API access is available on the Snyk Enterprise plan.
{% endhint %}

To see demonstrations of pipeline integrations, see [Snyk-Labs](https://github.com/snyk-labs/snyk-cicd-integration-examples).


# Phase 3: Gain visibility

Phase 3 of the Snyk team implementation: import repositories to create Projects and gain visibility into your applications

After the [Account configuration](/implementation-guides/team-implementation-guide/phase-2-configure-your-organization) phase is complete, you can import your repositories to scan your applications.

When importing your repositories, Snyk scans the contents to find all supported files and creates them in Snyk as Projects (for example, open-source manifest files, code files, IaC configuration files). For details, see [Import Projects](/implementation-guides/team-implementation-guide/phase-3-gain-visibility/import-projects).

You can optionally add Project Attributes, which can be useful to filter and organize your Projects when creating collections.


# Import Projects

How to import Projects into Snyk using an SCM integration or the Snyk CLI with CI/CD

Depending on the integrations you have configured, and the language / package managers in your tech stack, you can import Projects into Snyk using:

* A source control integration with your Git repositories
* The Snyk CLI with CI/CD.

The best import route varies based on the languages and package managers in your tech stack.

Here are some key points to determine the best starting point.

## Getting started with Snyk

{% hint style="info" %}
For details, see [Getting started](/getting-started-guides/getting-started) and [Start scanning](/getting-started-guides/start-scanning).
{% endhint %}

Depending on your needs, Snyk offers various integration methods:

### Git Integration

For details, see [Git repositories (SCMs) integrations with Snyk](/developer-tools/integrations/scm-integrations/organization-level-integrations).

Connect your repositories for automatic scanning.

For a small number of applications, typically under a hundred:

1. From the Snyk Web UI, connect to Git code repositories from the **Settings-Integrations** page.
2. In the integration settings:
   1. Disable the automatic fixes and PR/Merge checks when first onboarding Projects.
   2. Enable them once a steady state is reached and blocking is desired.
3. From the **Projects** page, add the Projects.
4. Monitor results in Git code repositories.

For hundreds or thousands of repositories:

* At scale, Snyk recommends using the API. APIs are available with the Snyk Enterprise plan.
  * Use the [Snyk API](/developer-tools/snyk-api/snyk-api) to import your Projects. This leverages an existing source control integration and can be used to automate processes.
  * The [API-import](/developer-tools/snyk-apps/tool-snyk-api-import) tool uses the API to manage onboarding at scale for large enterprises and is the suggested tool to use at scale. The source control structure will need to be mirrored.

## Snyk CLI

For details, see [Snyk CLI](/developer-tools/snyk-cli/snyk-cli).

The CLI allows granular scanning of individual Projects.

{% hint style="info" %}
A command must be formulated for each type of test to perform (open source, code, infrastructure as code, and container).
{% endhint %}

To use the Snyk CLI:

1. [Install the CLI](/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli) using one of the appropriate methods as part of the build script.
2. [Authenticate to use the CLI](/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli) by using the `snyk auth` command or an environment variable.
3. In the script, navigate to the Project folder.
4. Run the appropriate `snyk test` or `snyk monitor` commands and options for the type of scan you want to run.\
   \
   Where to implement testing in your scripts is generally flexible but most commonly prior to deployment. Use the monitor command alone for Snyk Open Source and Snyk Container to passively report. When you are using gating through the `test` command, the purpose is to break the build if issues are found that meet particular criteria like `--severity-threshold` or any number of options in the CLI or the `snyk-filter` plugin.\
   \
   In general, Snyk Open source is typically run in `test` and/or `monitor` after the dependencies are installed on the build system.\
   \
   A typical command can look as follows:
   * Code: `snyk code test --org=[org-id]`
   * Open source:
     * `snyk test --all-projects --org=[org-id]`
     * `snyk monitor --all-projects --org=[org-id]`\
       Replace `[org-id]` with the ID of your Organization.
   * For Container and Infrastructure as Code scans, see [Container](/scan-fix-and-prevent/scan-with-snyk/snyk-container/scan-container-images) and [Infrastructure as Code](/scan-fix-and-prevent/scan-with-snyk/snyk-iac), as this will vary based on the type being scanned.
5. Review results either locally when running `snyk test`, or on the Snyk Web UI when using `monitor` or report.

For demonstrations of various pipeline integrations, see [Snyk-Labs](https://github.com/snyk-labs/snyk-cicd-integration-examples).


# Add project attributes

How to add Project Attributes as metadata to filter and report on subsets of your Organization

After importing your projects, you can add metadata to your Projects using [Project Attributes](/scan-fix-and-prevent/scan-with-snyk/snyk-projects/project-attributes). This allows you to filter and report on specific subsets of your Organization.

For example, if you add Project Attributes to all of your Projects, you can easily filter Projects to those that are "frontend critical vulnerabilities in production" from the Projects page.


# Invite Users

How to invite members to your Snyk Organization and apply the roles planned in Phase 1

Click **Members** and invite your team members, applying the role alignments decided in Phase 1 for each member.

{% hint style="info" %}
Inviting members is generally suggested after importing your Projects. You may bring in a few initial members to start and then do a wider rollout. This can be done at any time as part of stages four and five. It is strongly recommended to communicate what is expected prior to the actual invitation and then communicate throughout the various stages as pull request checks are turned on, pipelines enabled, and as policies/practices change.
{% endhint %}


# Phase 4: Create a fix strategy

Phase 4 of the Snyk team implementation: prioritize your vulnerability backlog and define focus areas for fixes

After setting up your integrations, creating your Organization, and importing your Projects, you now have visibility into your business's current vulnerability backlog.

## Decide important focus areas

Before diving into specific vulnerabilities, consider your Organizations and repositories (Targets in Snyk) to consider any areas of specific importance. The discovery of business-critical applications you did in Phase 1 can help inform and prioritize during this phase. For example, if your Organizations match different products, you can initially focus on the one product with the most users or where security matters most.

In your Organization, you can then consider the repositories that make up the application's different parts. Areas that handle sensitive data or are public-facing may be more important to secure, so this could be another way to narrow down your initial list of Projects to review.

{% hint style="info" %}
If you have used **Attributes** to add metadata to your Projects, these can be a great way to filter down the number of Projects that you are considering.
{% endhint %}

## Group work by development teams

After you have your reduced set of Projects to prioritize, you may want to split these between different development teams. For example, you may have one Development team fixing issues with your open-source and first-party code and a separate DevOps team responsible for Containers and base image vulnerabilities.

## Prioritization method

Filters are available to help prioritize what issues need to be fixed more urgently. The following search criteria are most commonly used when building a prioritization plan and can be used iteratively or in combination as you analyze results.

* Severity (Start with **High** and **Critical**). It is common to filter by critical severity. However, Snyk Code, Snyk code only goes up to High, so if you are using Snyk Code, start there for Code Analysis results.
* [Exploit Maturity](https://snyk.io/blog/whats-so-wild-about-exploits-in-the-wild-and-how-can-we-prioritize-accordingly/) (Issues with **Mature** or **Proof of Concept** are more exploitable). By choosing this filter, you implicitly only filter the results to Open Source.
* Fixable (if there’s a fix available by upgrading a package, it’s much faster to fix).
* CVSS Score for Open Source Vulnerabilities
* [Priority Score](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/priority-score) (The above values are used to calculate this score). One strategy is to eliminate the vulnerabilities with a score of 900-1000, and then move to vulnerabilities with a score of 800-900, and so on.

Decide which metrics will be used when planning your fix strategy, and get specific with your timeline. If you choose to fix by severity, for example, estimate the time it will take to resolve a vulnerability per severity. It’s recommended to be specific with your fix strategy.

**Example**

If there are fifty critical-severity issues and one hundred high-severity issues, you may plan on two weeks to fix critical vulnerabilities and then four weeks to fix high-severity, based on the size of your team and workload.

Alternatively, you can fix by issue type.

## Fix by issue type

It is also common to initially focus on specific issue types (for example, open source vulnerabilities), as then you can more easily compare issues across different Projects.

Here are examples of processes based on whether fixes are led by different types of teams.

### Example: Developer-led priorities

Developer-led implementation, with instruction from executives to minimize license risk:

1. Resolve all License issues identified by Snyk Open Source.
2. Address all fixable Critical or High vulnerabilities in Snyk Open Source.
3. Shift focus to Code Analysis Projects (using Snyk Code), starting with High severity issues.
4. Scan the Containers and IaC files they are using to run their applications/environments.

### **Example: DevSecOps-led priorities**

DevSecOps-led implementation, focusing on securing your custom images and environment:

1. Scan and secure any custom base images that your development teams pull from.
2. Integrate with your Container Registry and scan the images you provide to your development teams.
   1. Scan the image you have chosen and built after adding common internal tools and standardizing image parameters.
   2. Ensure developers also scan their containers after adding their custom tools/packages to ensure that the container remains secure before deployment. This scan will also detect application vulnerabilities.
3. After you have secured your Containers, start actively scanning your IaC files and cloud environments for misconfigurations that could lead to security breaches.
4. Introduce Snyk to development teams to scan their Open Source and Code to reduce application vulnerabilities.

## Targeted Vulnerabilities Campaigns

As you operationalize security testing in your development process, another option for your fix strategy is to have campaigns to eliminate vulnerability types, for example, SQL injection. Using CWE in your search filters can be very useful in reporting to identify and log issues.

## Update your timeline

Once you have created your fix strategy, update the timeline for Phase 7.


# Phase 5: Rolling out the prevention stage

Phase 5 of the Snyk team implementation: roll out prevention and gating to stop new vulnerabilities entering your applications

After you gain visibility on your security issues, you can now start to implement a prevention/gating system, to stop new vulnerabilities being added to your applications.

## Common prevention methods

Below are the two common areas that allow you to "prevent new issues":

* Snyk tests on pull request (PR)/merge checks (MR), currently available for Open Source.
* Adding "Snyk test" to your CI/CD pipelines (you may have already implemented "Snyk monitor" to import your Projects as part of the pipeline).
  * Additionally, open source, code, infrastructure as code, and container vulnerabilities can all be gated.

In either case, Snyk suggests that you communicate these changes clearly to your developers before implementing any form of gating.

## Tips

### Block the differences

If you are not already blocking vulnerabilities, start by blocking the difference.

This eases developers into the process, as they only take responsibility for vulnerabilities directly related to their changes.

To block new issues, you can use PR checks. For details, see [Run PR Checks](/scan-fix-and-prevent/prevent/pull-request-checks).

### Communicate exception processes

It is important to ensure the teams know the exception processes and how to address if a PR is blocked or a build fails.

For example:

* Let the team know who has the authority to override a PR check if a pass is mandatory.
* If a build fails, can the issue be ignored and the test rerun? Who can run it? Or can a script be run allowing that step to pass? Who can make that determination?


# Enable and configure Snyk on PRs

How to enable and configure Snyk PR and MR Checks to block new vulnerabilities in code changes

## Use PR Checks to introduce gating

[Snyk Pull Request(PR)/Merge Request (MR) Checks](/scan-fix-and-prevent/prevent/pull-request-checks) allow you to prevent new security issues from entering your codebase, by automatically scanning code changes when you submit a pull request (PR). PR Checks are available for open-source vulnerabilities, license compliance issues, and your own code issues.

If you import Projects through a source control integration, then Snyk Open Source and Snyk Code PR Checks is a good place to start introducing gating.

{% hint style="info" %}
Snyk recommendes announcing the changes prior to rolling out the changes. See [Announce prevention measures](/implementation-guides/enterprise-implementation-guide/automate-prevention-measures#announce-prevention-measures) for examples of how to message your developers.
{% endhint %}

### Implementing Open Source PR Checks

There are a number of different features available that can be used to help you gradually introduce the feature to avoid friction with your development teams:

* Fail conditions: You can control whether the test will "fail" if the PR itself is adding a dependency with issues (most common) or if the repository as a whole has any issues.

The criteria of what constitutes a "failed test" can also be customized. By default, the test does not filter based on severity or fixability, which can mean that PR tests will regularly fail. For Snyk Open Source you can customize what the criteria are to fail the test:

* **Only fail for high or critical severity issues**
* **Only fail when the issues found have a fix available**

When you first enable this feature, Snyk suggests ticking both of these boxes so that a test would fail if a **High or Critical** and **fixable** issue is found. In this case, you would want to encourage to developer to fix the issue before proceeding.

These PR tests are optional by default, meaning that even if the test fails, the developer may be able to continue and merge the PR. Controlling whether a PR test is optional or blocking is configured within your source control management platform, such as GitHub’s branch protection rules.

### Implementing Code PR Checks

When enabling static analysis of code changes and therefore new vulnerabilities, you can select the fail criteria to be **High** (the highest severity).

When you first enable this feature, Snyk suggests selecting **High** if an issue is found. In this case, you would want to encourage developers to fix the issue before proceeding. As your code base stabilizes and you have worked through the backlog, you can change the fail criteria to lower the severity (to either **Medium** or **Low)** in order to address broader issues or to match your internal policies.

### Using PR Checks for a phased rollout

It is common to have a phased rollout of these features. Using PR checks as an example:

* You may initially run Snyk tests and set, via your source control settings, as optional checks. The results are displayed, but the developer is not blocked from merging the PR.
* Over time, as developers adapt to seeing these results and begin addressing the high issues proactively, you can choose to start blocking PRs from being merged if there are any new highest severity issues or, in the case of Snyk Open Source, if a fix is available.

This phased rollout helps to decrease friction between your security and development teams.


# Add and configure Snyk to your CI/CD pipeline

How to add Snyk to your CI/CD pipeline as a gatekeeper that fails builds on new vulnerabilities

Using Snyk as a gatekeeper in your build pipeline prevents the introduction of new vulnerabilities, based on the "fail" criteria you set.

After your teams understand the vulnerabilities in their applications and develop a process for fixing them early in the development cycle, you can configure Snyk to fail your builds if vulnerabilities are detected, to prevent introducing vulnerabilities into your applications.

## No import requirement

A benefit of adding tests to your pipeline is that you do not need to import the repository to Snyk using the source control integration (which is required for Snyk PR Checks). It can also be used as an additional gate, even if you are testing PRs, to further decrease the chance of new vulnerabilities entering your production builds.

## Pipeline options

When adding Snyk to a build pipeline, there are common options:

* Using the specific [pipeline integration](/developer-tools/integrations/snyk-ci-cd-integrations) for your tool.
* Using the [Snyk CLI](/developer-tools/snyk-cli/snyk-cli) and running the specific commands directly.

Each option has benefits - using an existing pipeline integration may be faster and easier to configure, but using the Snyk CLI will give you a greater range of options and flexibility in your "fail" criteria.

## Pipeline test filters

When running a test in your pipeline, there are filters available to determine what would result in a test passing or failing. The most common of these is "severity threshold", where you can specify to only fail a build if there are High or Critical severity vulnerabilities.

## CLI supporting tools

If you use the Snyk CLI in your pipeline, a range of supporting [Snyk Tools](/developer-tools/snyk-apps/snyk-tools) provide additional functionality, including [`snyk-filter`](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/snyk-filter), which can be used for more complex "fail" criteria, such as “fail if more than three High severity vulnerabilities are found”.

## Also see

Here is a link to a webinar that covers CI/CD checks in more detail and includes an example of how you can gradually introduce this feature: [CI/CD Best Practices](https://www.youtube.com/watch?v=6QS9gRQ0WVU).


# Infrastructure as code

How to roll out Snyk IaC, including Terraform Cloud runs and scanning Terraform and YAML in your repositories

For Snyk IaC, you may choose to integrate with [Terraform Cloud](/developer-tools/integrations/snyk-ci-cd-integrations/terraform-cloud-integration-for-snyk-iac-using-run-tasks/how-to-use-the-terraform-cloud-integration-for-iac) to run snyk iac test as part of a ‘run’ workflow, in addition to scanning Terraform and YAML files that are included as part of your source control repositories.

For instructions on how to implement Snyk per IaC type in the Snyk CLI, see [Snyk CLI for IaC](/developer-tools/snyk-cli/snyk-cli/scan-and-maintain-projects-using-the-cli/snyk-cli-for-iac).


# Phase 6: triages, ignores and fixes

Phase 6 of the Snyk team implementation: triage, prioritize, ignore, and fix vulnerabilities in your backlog

## Tips for deciding on prioritization

After you implement a strategy to prevent new issues from entering your repositories, whether blocking builds or running in a non-blocking/advisory mode, the next step is to prioritize and start fixing issues in your backlog.

* In [Phase 4: Create a Fix strategy](/implementation-guides/team-implementation-guide/phase-4-create-a-fix-strategy), you created a plan for prioritizing your Projects and issues. To implement this, you can schedule regular meetings with development team leads, to assist them with this process.
* If you use Jira Cloud, you can download and install the [Snyk Security in Jira Cloud](https://marketplace.atlassian.com/apps/1230482/snyk-security-in-jira-cloud) plugin from the Atlassian marketplace. This allows you to view information on your Snyk Vulnerabilities directly in Jira, and use Jira Automation to create new tickets when new vulnerabilities are identified.

## When should you ignore an issue?

When deciding your priority for fixing issues, you may see specific packages or vulnerabilities that you do not currently want to fix. This could be for a range of reasons, such as:

* The fix introduces breaking changes, and you don't have time to fix them.
* This vulnerability does not apply to you for an environmental/contextual reason.

## Use the ignore feature

In each case, you can use the "ignore" feature to stop these from appearing each time you run a test.

{% hint style="info" %}
Confirm ignore with an Organization Admin (they may need to complete this step themselves).
{% endhint %}

When adding the ignore:

* Ensure you add a detailed reason, so the ignore reason is clear to others who see this issue.
* Set an expiration date for the ignored rather than having a permanent ignore. This is essential, as whilst the issue may not be fixable/relevant today, it should be reviewed regularly (monthly or quarterly) to see if it is possible to implement a fix.

{% hint style="info" %}
In **Settings-General** it's common to limit access to who can ignore an issue and require a reason.
{% endhint %}

By default, the **Organization Collaborator** role has permission to ignore issues, but this can be controlled per Organization in the **Settings** page (that is, restricted to **Organization admins** only).

See [Ignore issues](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/ignore-issues) for more details.


# Enterprise implementation guide

Guide to rolling out Snyk across a large organization with a consistent, repeatable account configuration

Rolling out a developer security platform across a large organization requires a consistent, repeatable approach to account configuration. In this guide, you will learn how to streamline your enterprise rollout in Snyk by creating a dedicated template Organization and altering settings for each individual Organization created from that original template.

To have a successful Snyk rollout, you need to:

1. [Understand the Snyk hierarchy.](#snyk-hierarchy)
2. [Configure Group settings and policies](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies):
   1. [Structure your account](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/structure-your-account).
   2. [Authentication and access](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/authentication-and-access).
   3. [Define policies](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/define-policies).
3. [Create a template Organization](/implementation-guides/enterprise-implementation-guide/create-a-template-organization):
   1. [Structure your account](/implementation-guides/enterprise-implementation-guide/create-a-template-organization/structure-your-account).
   2. [Authentication and access](/implementation-guides/enterprise-implementation-guide/create-a-template-organization/authentication-and-access).
   3. [Connect your development tools](/implementation-guides/enterprise-implementation-guide/create-a-template-organization/connect-your-development-tools).
4. [Create your Snyk structure](/implementation-guides/enterprise-implementation-guide/create-your-snyk-structure).
5. [Gain issues visibility with Projects](/implementation-guides/enterprise-implementation-guide/phase-3-gain-visibility).
6. [Initial team rollout](/implementation-guides/enterprise-implementation-guide/initial-team-rollout).
7. [Automate prevention measures](/implementation-guides/enterprise-implementation-guide/automate-prevention-measures).

By the end of this guide, you will have successfully configured a baseline template Org, used it to easily copy your global settings and integrations to provision new Organizations, and learned how to customize individual settings in those new environments to support specific team workflows.

{% hint style="info" %}
To understand how AI is used at Snyk and how this may affect your implementation decisions, visit [AI Data and Governance](/snyk-data-and-governance/how-snyk-incorporates-generative-ai-into-the-platform).
{% endhint %}

## Confirm points of contact

{% hint style="success" %}
**Key decision**: Determine which teams manage your identity provider (IdP) and source control management (SCM) systems. Snyk requires permissions that typically live outside your security team. Identifying these stakeholders early on prevents your rollout from stalling mid-configuration.
{% endhint %}

To implement Snyk successfully, you must identify the necessary skills and the internal stakeholders required for the rollout.

For example, identify people who can perform the following tasks:

* Create the required single sign-on (SSO) connections.
* Generate tokens with the necessary permissions for SCM repositories.
* Configure permissions for other integrations, such as container registries or CI/CD pipelines.

## Map business critical applications

{% hint style="success" %}
**Key decision**: Select three to five high-priority applications to serve as initial implementation benchmarks. Starting at a smaller scale enables you to validate the configuration and surface any integration issues before a large-scale rollout.
{% endhint %}

To identify priority applications, categorize them based on:

* **Business impact**: Applications that handle sensitive data or generate high revenue.
* **Exposure**: Public-facing apps or those with high-risk network configurations.
* **Development activity**: Teams with active release cycles that can implement fixes quickly.

## Snyk hierarchy

Plan your Snyk account structure to ensure efficient asset management, precise access control, and accurate reporting. Snyk uses a hierarchical structure to manage all assets and security policies.

Snyk organizes work into four levels:

| Level            | Typical representation | Purpose                                           |
| ---------------- | ---------------------- | ------------------------------------------------- |
| **Tenant**       | Your entire company    | The overarching instance managed by Snyk.         |
| **Group**        | Business entity        | The top level of your administrative control.     |
| **Organization** | Team or product        | The key level for managing Projects and policies. |
| **Project**      | Imported asset         | The individual item Snyk tests and monitors.      |

## Configure Group settings and policies

As a Group Admin or above you need to decide on which settings to enable and what to configure at the Group level. This is so your business entity is represented at the top-level of control and you can cleanly create an Organization template from these configurations.

To learn more, visit [Configure Group settings and policies](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies).

## Create a template Organization

Create a template Organization to clone settings and integrations. This ensures consistency across your Snyk structure and reduces manual configuration.

Snyk does not have a dedicated template feature. Instead, you can create a standard Organization named "Template" and configure its settings.

To learn more, visit [Create a template Organization](/implementation-guides/enterprise-implementation-guide/create-a-template-organization).

## Create your Snyk structure based on the template Organization

{% hint style="success" %}
**Key decision**: Determine how you want to structure your Organizations. Do you want to reflect your business structure by having an Organization per team, per business unit, or by repository? This is important because your chosen Org structure defines how your teams work in Snyk, controls who sees what, and determines how policies and reporting are scoped.
{% endhint %}

You can use an existing Organization as a model to create a new Organization, and apply the settings and integrations.

Use the API templating functionality to ensure consistent settings when creating Organizations at scale. There are two scenarios where you can apply this:

* **Mirroring existing structures**: Use the `snyk-api-import` tool to replicate an existing source, for example, GitHub Organizations.
* **Direct API creation**: Use the `Create a new organization` endpoint and provide a `sourceOrgId` to apply the template.

To learn more, visit [Create your Snyk structure](/implementation-guides/enterprise-implementation-guide/create-your-snyk-structure).

## Gain visibility by importing repositories

Gaining visibility into your organization's security starts with importing your repositories so Snyk can actively monitor your code, dependencies, containers, and infrastructure.

Depending on your tech stack and workflows, you can choose from three primary import methods:

* SCM integrations for automated scanning
* Snyk CLI for granular control within your CI/CD pipelines
* Snyk API for large-scale programmatic automation

Once you import your Projects, you can apply specific tags and attributes to easily categorize, filter, and generate targeted reports across your entire portfolio.

To learn more, visit [Gain visibility by importing repositories](/implementation-guides/enterprise-implementation-guide/phase-3-gain-visibility).

## Initial team rollout

Successfully rolling out Snyk to your development team requires clear communication, targeted education, and seamless workflow integration.

Start by using customizable templates to announce the launch, tailoring your messaging and feature rollout to match your team's comfort level with security automation.

Next, empower your developers with persona-specific training through Snyk Learn to build both foundational security knowledge and Snyk product expertise.

Finally, reinforce a shift-left security strategy by deploying Snyk IDE plugins, equipping developers to find and fix vulnerabilities directly within their preferred coding environment before the code ever reaches the CI/CD pipeline.

To learn more, visit [Initial team rollout](/implementation-guides/enterprise-implementation-guide/initial-team-rollout).

## Automate prevention measures

Drive user adoption and secure coding practices by thoughtfully introducing Snyk to your development teams.

By combining clear communication, tailored training through Snyk Learn, and the deployment of IDE plugins, you can empower your developers to actively find and fix vulnerabilities directly within their daily workflows.

To learn more, visit [Automate prevention measures](/implementation-guides/enterprise-implementation-guide/automate-prevention-measures).


# Configure Group settings and policies

How to plan Snyk account structure and policies at the Group level for asset management, access control, and reporting

This page is designed to help you plan your Snyk account structure and policies at Group-level to ensure efficient asset management, precise access control, and accurate reporting.

## Confirm points of contact

{% hint style="success" %}
**Key decision**: Determine which teams manage your identity provider (IdP) and source control management (SCM) systems. Snyk requires permissions that typically live outside your security team. Identifying these stakeholders early on prevents your rollout from stalling mid-configuration.
{% endhint %}

To implement Snyk successfully, you must identify the necessary skills and the internal stakeholders required for the rollout.

For example, identify people who can perform the following tasks:

* Create the required single sign-on (SSO) connections.
* Generate tokens with the necessary permissions for SCM repositories.
* Configure permissions for other integrations, such as container registries or CI/CD pipelines.

## Map business critical applications

{% hint style="success" %}
**Key decision**: Select three to five high-priority applications to serve as initial implementation benchmarks. Starting at a smaller scale enables you to validate the configuration and surface any integration issues before a large-scale rollout.
{% endhint %}

To identify priority applications, categorize them based on:

* **Business impact**: Applications that handle sensitive data or generate high revenue.
* **Exposure**: Public-facing apps or those with high-risk network configurations.
* **Development activity**: Teams with active release cycles that can implement fixes quickly.

## Structure your account

{% hint style="success" %}
**Key decisions:**

* Select the structure (team, product, or SCM-based) that best supports how you want to manage policies, report vulnerabilities, and define user access.
* Define who can provision users and grant Snyk access to external platforms, such as Git repositories.
  {% endhint %}

Snyk uses a hierarchical structure to manage all assets and security policies. This section will help you map your business to the Snyk architecture.

* **Understanding the hierarchy:** Learn the purpose of the Tenant, Group, Organization, and Project levels.
* **Group structure:** Decide how many top-level Group accounts your company requires.

To learn more, visit [Structure your account](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/structure-your-account).

## Authentication and access: set up SSO

Implement Single Sign-On (SSO) at the Group level before rolling Snyk out to your organization. While pilot teams often start with personal authentication, transitioning to SSO is required for broad adoption, consistent login access, and centralized control.

Choose a provisioning strategy that defines the user experience and access level for new users.

| Option                | Description                                                               | Recommended for                                             |
| --------------------- | ------------------------------------------------------------------------- | ----------------------------------------------------------- |
| **Open to all**       | Any user with a valid company email domain can join the Snyk Group.       | Rapid, frictionless onboarding.                             |
| **Require an invite** | Users must receive an email invitation to join the Group or Organization. | Strict control over license seats and access.               |
| **API provisioning**  | Use Snyk API endpoints to grant access and roles before a user logs in.   | Pre-defining custom roles and specific Organization access. |

To learn more, visit [Authentication and access](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/authentication-and-access).

## Authentication and access: role management

{% hint style="success" %}
**Key decisions:**

* Determine if your team leads can operate with the fixed permissions of an **Organization Admin** or if they require a restricted custom role.
* Identify if you need a "middle-ground" role, such as a Senior Developer who can, for example, override checks but cannot delete Projects.
* Decide who is responsible for provisioning new users as your Snyk footprint grows.
  {% endhint %}

Snyk provides both pre-defined and custom roles to ensure users have the exact permissions they need.

* **Tenant-level roles:** Determine if you need centralized oversight roles (Tenant Admin, Viewer, or Member) for cross-group reporting and user management.
* **Group roles:** Review fixed pre-defined roles.
* **Custom roles:** Evaluate whether you need roles with highly granular, customized permissions.

To learn more, visit [Authentication and access.](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/authentication-and-access)

## Define policies

{% hint style="success" %}
**Key decisions:**

* Decide which conditions automatically increase or decrease the priority or severity of an issue to match your risk appetite.
* Decide which specific issues or types of issues are automatically ignored to reduce "noise" and save development time.
* Decide which specific license types to explicitly allow or disallow to avoid using packages with incompatible or problematic licenses.
* Use severity types to decide how to configure policies to match your specific legal and compliance requirements.
* Decide how to automate the governance, tracking, and remediation workflows for your assets to ensure continuous security visibility and compliance
  {% endhint %}

Policies allow you to automate business context, compliance checks, and notification workflows.

* **License policies:** Decide which specific license types to explicitly allow or disallow to match your specific legal and compliance requirements.
* **License severity:** Understand and configure how Snyk assigns High or Medium severity to problematic commercial licenses.
* **Asset governance:** Decide how to automate the governance, tracking, and remediation workflows for your assets.
* **Policy creation:** Learn how to build asset policies using specific filters (like Name, Asset Type, or Tags) and actions (like assigning classification or triggering Slack notifications).

To learn more, visit [Define policies](/implementation-guides/enterprise-implementation-guide/configure-group-settings-and-policies/define-policies).


# Structure your account

How to plan your Snyk Group structure, the highest administrative level, for enterprise account management

## Plan your Group structure

{% hint style="success" %}
**Key decision:** Determine how many top-level accounts your company requires. Most organizations need only one.
{% endhint %}

The Snyk Group is the highest administrative level you manage.

* **Default:** Most customers use one Snyk Group representing their company name.
* **Large enterprises:** Use multiple Groups only if you must keep business units or subsidiaries completely isolated.


# Authentication and access

How to configure SSO and access at the Snyk Group level, including Self-Serve Single Sign-On options

## Set up SSO

{% stepper %}
{% step %}

#### Configure SSO settings at the Group level

{% hint style="success" %}
**Key decision:** Choose between **Open to all** or **Require an invite** based on your security policy and license management needs.
{% endhint %}

Snyk recommends using Self-Serve Single Sign-On to establish a SAML connection with your identity provider (IdP). To do this:

1. In the Snyk web UI, navigate to Group **Settings** > **SSO**. If the SSO option is missing, verify your license or contact Snyk Support.
2. Configure your SAML connection, valid email domains, and default permissions.
3. Contact Snyk Support if you want to use other protocols such as OIDC and ADFS.

{% hint style="info" %}
Any identity provider is supported, including tools such as Entra ID, OKTA, and Google Workspace.
{% endhint %}
{% endstep %}

{% step %}

#### Manage user accounts

{% hint style="success" %}
**Key decision**: Identify which administrators require Group Admin status and ensure they transition from personal accounts to SSO accounts before the general rollout.
{% endhint %}

To ensure a clean transition to Enterprise authentication, manage your administrative accounts before the wider rollout:

1. **Promote SSO accounts:** Create SSO-linked accounts for your Snyk administrators and grant them the Administrator role.
2. **Remove personal accounts**: Remove any non-SSO or personal accounts used during the pilot phase to ensure all access is governed by your IdP.
3. **Map custom roles**: If you use custom roles, configure your IdP to pass these roles to Snyk.

{% hint style="info" %}
Custom mapping requires Snyk professional services. Contact your account team for assistance.
{% endhint %}
{% endstep %}

{% step %}

#### (Optional) Provision users with the API

{% hint style="success" %}
**Key decision**: Determine if you need to pre-allocate users to specific Organizations and roles before their first login to prevent broad default access.
{% endhint %}

If you need to define specific permissions before users first log in, use the Snyk API. This allows you to:

* Assign a specific role to each user.
* Grant access to specific Organizations automatically.
* Control the user footprint from day one.
  {% endstep %}
  {% endstepper %}

## Set pre-defined user roles

Determine if Snyk pre-defined roles meet your requirements or if you must create custom roles. Snyk uses role-based access control (RBAC) to manage permissions across the Tenant, Group, and Organization levels.

{% stepper %}
{% step %}

#### Review Tenant-level roles

{% hint style="success" %}
**Key decision:** Determine if you need centralized oversight across multiple Groups to manage analytics and global user membership.
{% endhint %}

The Tenant is the highest level of the Snyk hierarchy, and it encompasses all Groups and Organizations. Tenant-level roles are essential for large enterprises that require cross-group reporting and user management.

* **Tenant Admin:** Can manage users across the entire Tenant, assign roles, and remove members.
* **Tenant Viewer:** Provides read-only access to Tenant-level features like Snyk Analytics.
* **Tenant Member**: Allows access to the Tenant level but requires specific Group or Organization permissions to take action.

{% hint style="info" %}
Features like Snyk Analytics are available only on Enterprise plans. You can switch between Tenants by selecting the Tenant name in the navigation menu.
{% endhint %}
{% endstep %}

{% step %}

#### Review Group-level roles

{% hint style="success" %}
**Key decision:** Determine if your team leads can operate with the fixed permissions of an Organization Admin or if they require a restricted custom role.
{% endhint %}

Pre-defined roles at these levels have fixed permissions that cannot be modified.

**Group-level roles**

* **Group Admin**: Provides full permissions at the Group and Organization levels. Assign this role to Snyk administrators.
* **Group Member**: Allows access to the Group but requires specific Organization-level permissions to interact with Projects.
* **Group Viewer**: Provides read-only access to the Group level. Use this to audit Group settings without making changes.
  {% endstep %}
  {% endstepper %}

### Set custom roles

{% hint style="success" %}
**Key decision**: Identify if you need a "middle-ground" role, such as a Senior Developer who can, for example, override checks but cannot delete Projects.
{% endhint %}

Large enterprises often require more granular control. Because you cannot change permissions for pre-defined roles, use custom roles to limit or expand specific actions and gain:

* **Customization**: Assign a specific set of permissions to a role name you define.
* **Flexibility**: Update permissions for a custom role at any time. Changes apply immediately to all assigned users.
* **Efficiency**: Use custom role templates provided by Snyk to jumpstart your configuration.


# Define policies

How Snyk policies automate identifying, prioritizing, and triaging findings to save development time

Policies define how Snyk behaves when identifying issues. Policies give you a quick and automated way to identify, prioritize, and triage issues. This saves valuable development time and allows developers to take more responsibility and ownership for security, reducing the “noise” level.

## Security policies

{% hint style="success" %}
**Key decision:** Decide which conditions automatically increase or decrease the priority or severity of an issue to match your risk appetite, and which specific issues or types of issues are automatically ignored to reduce "noise" and save development time.
{% endhint %}

Group administrators can define security policies, thus providing an automated way to identify certain issues or types of issues, and apply actions like changing the severity or ignoring the issue based on your conditions.

* Configure policies to increase priority or decrease it as needed.
* Create ignores where needed

## License policies <a href="#license-policies" id="license-policies"></a>

{% hint style="success" %}
**Key decision:** Decide which specific license types to explicitly allow or disallow to avoid using packages with incompatible or problematic licenses, and use severity types to decide how to configure these policies to match your specific legal and compliance requirements.
{% endhint %}

Group administrators can set license policies to define Snyk behavior for treating license issues. For example, you can allow or disallow packages with certain license types, to avoid using packages containing incompatible licenses.

By default, Snyk determines the severity of licenses as follows:

* **High severity**: licenses that definitely present issues for commercial software.
* **Medium severity**: licenses that have clauses that may be of concern and should be reviewed.

Configure policies to match your requirements.

## Asset policies <a href="#asset-policies" id="asset-policies"></a>

{% hint style="success" %}
**Key decision:** Decide how to automate the governance, tracking, and remediation workflows for your assets to ensure continuous security visibility and compliance
{% endhint %}

Asset policies in Snyk Essentials automate business context and notification workflows. Use policies to identify coverage gaps and manage assets at scale.

## About policies

### Policy components

A policy consists of the following elements:

* Filters: Define criteria (for example tags or asset names) to group specific assets.
* Actions: Define what happens to filtered assets, for example, assigning a classification or sending a Slack notification.

### Key filter types

Use the following filters to refine your asset groups:

* **Name**: Match assets based on naming conventions.
* **Asset Type**: Target specific assets like repositories or packages.
* **Class**: Focus on business-critical assets (for example, Class A) to reduce noise.
* **Tags**: Use system or custom-defined tags to identify assets.

### **Policy execution**

* Automatic: Policies run every three hours.
* Manual: Click **Run** in the Policy view to apply changes immediately.

## **Creating a policy**

To create a policy:

1. In the Snyk web UI, navigate to **Policies** > **New policy**.
2. Enter a **Name** and a **Description**, then click **Next**.
3. In the policy builder, define your **Filters** and click **Apply**.
4. Click the **+** icon to **Set actions**.
   * Trigger an action: Apply a change or notification to filtered assets.
   * Logic node: Combine multiple filters before triggering an action.
5. Click **Save**.

## **Common use cases**

* **Coverage control**: Define where specific security controls must be active.
* **Classification**: Categorize assets by business importance.
* **Tagging**: Apply consistent metadata to matched assets.
* **Notification**: Alert teams through email or Slack when asset states change.


# Create a template Organization

How to create a template Snyk Organization to standardize account structure, access control, and reporting

This guide section is designed to help you plan your Snyk account structure at the Organization-level to ensure efficient asset management, precise access control, and accurate reporting. This Organization will be the template you copy to create additional Organizations from which have standards settings for all your Orgs.

{% embed url="<https://res.cloudinary.com/snyk/video/upload/v1775661970/4._Creating_your_Template_Organization_vf1x0b.mp4>" %}
Create a template Organization video guide
{% endembed %}

Below is an outline of the key topics and decisions covered in this guide.

## Structure your account

{% hint style="success" %}
**Key decisions:**

* Select the structure (team, product, or SCM-based) that best supports how you want to manage policies, report vulnerabilities, and define user access.
* Define who can provision users and grant Snyk access to external platforms, such as Git repositories.
  {% endhint %}

Snyk uses a hierarchical structure to manage all assets and security policies. This section will help you map your business to the Snyk architecture.

* **Organization structure:** Determine if your Organization structure should be team-based, product-based, or SCM organization-based to best support your policy and access needs.

To learn more, visit [Structure your account](/implementation-guides/enterprise-implementation-guide/create-a-template-organization/structure-your-account).

## Authentication and access

{% hint style="success" %}
**Key decisions:**

* Determine if your team leads can operate with the fixed permissions of an **Organization Admin** or if they require a restricted custom role.
* Identify if you need a "middle-ground" role, such as a Senior Developer who can, for example, override checks but cannot delete Projects.
* Decide who is responsible for provisioning new users as your Snyk footprint grows.
  {% endhint %}

Snyk provides both pre-defined and custom roles to ensure users have the exact permissions they need.

* **Organization roles:** Review fixed pre-defined roles.
* **Role alignment:** Learn how to assign roles based on your chosen Organization structure.

To learn more, visit [Authentication and access](/implementation-guides/enterprise-implementation-guide/create-a-template-organization/authentication-and-access).

## Connect your development tools

{% hint style="success" %}
**Key decisions:**

* **Architecture and connectivity:** Select your primary SCM platform and identify where your production container registries (for example, Docker Hub, Amazon ECR) reside. Determine if you need to deploy Snyk Broker (using Docker or Kubernetes) to securely bypass firewalls, segment network traffic, or if you require custom proxy/CA configurations.
* **Authentication and access management:** Commit to using dedicated, least-privilege service accounts rather than personal tokens (OAuth/PAT) to guarantee stable connections. Decide whether to use broad, centralized Group-level credentials for global asset discovery or require unique tokens at the Organization level. Verify you have the correct administrative roles to manage this inventory.
* **Developer workflow & remediation:** Define your PR check behaviors and automated fix strategies to match specific team workflows. Establish a monitoring frequency that provides adequate security visibility without overwhelming your developers' capacity to remediate.
* **Snyk Code enablement:** Decide whether to roll out Snyk Code globally or phase it in for high-priority teams. It's crucial to enable Snyk Code before importing your first Projects. If managing at a massive scale, plan to use the Snyk API rather than the UI for this step.
* **Project import strategy:** Choose the import method that provides the best dependency resolution for your specific programming languages to ensure accurate scanning.
  {% endhint %}

By configuring your core tools, source control integrations, and default security behaviors now, you establish a standardized baseline that can be easily cloned: either manually or using the API, across your entire business.


# Structure your account

How to structure a Snyk Organization by team, product, or SCM to manage policies, reporting, and access

## Plan your Organization structure

{% hint style="success" %}
**Key decision:** Select the structure (team, product, or SCM-based) that best supports how you want to manage policies, report vulnerabilities, and define user access.
{% endhint %}

Snyk Organizations (Orgs) are the primary level for managing Projects and user access. Align your Org structure with your business, development, or security reporting needs.

| Structure                  | Description                                                                                               | Recommended for                                                                               | Avoid if                                                                            |
| -------------------------- | --------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- |
| **Team-based**             | Linked to a specific developer or security team.                                                          | Strict security ownership and reporting by team.                                              | Multiple teams need access to the exact same set of projects (leads to complexity). |
| **Product-based**          | Set up for distinct applications or product lines (for example, product a front-end, product a back-end). | Product-centric reporting and access control.                                                 | You have hundreds of small, unrelated products.                                     |
| **SCM Organization-based** | Mimics your SCM hosting platform structure (for example Github orgs, Gitlab groups).                      | Automated onboarding using the Snyk API, when you have more than 10 SCM-related integrations. | Your SCM organization names are not intuitive or don't align with business units.   |


# Authentication and access

How to set Snyk roles and access at the Organization level using role-based access control

## Set pre-defined user roles

Determine if Snyk pre-defined roles meet your requirements or if you must create custom roles. Snyk uses role-based access control (RBAC) to manage permissions across the Organization level.

## Review Organization-level roles

{% hint style="success" %}
**Key decision:** Determine if your team leads can operate with the fixed permissions of an Organization Admin or if they require a restricted custom role.
{% endhint %}

Pre-defined roles at these levels have fixed permissions that cannot be modified.

* **Organization Admin**: Allows users to add or delete Projects, override Snyk checks, and provision users. Assign this role to Team Leads.
* **Organization Collaborator**: Grants standard developer access. Use this for small teams or a developer-first rollout.

## Align roles with your Organization structure

{% hint style="success" %}
**Key decision**: Decide who is responsible for provisioning new users as your Snyk footprint grows.
{% endhint %}

Your choice of roles depends on how you structured your Snyk Organizations in the previous steps.

| Structure                 | Typical role assignment                                                          |
| ------------------------- | -------------------------------------------------------------------------------- |
| **Team-based**            | Assign **Organization Admin** to the specific Team Lead for that Organization.   |
| **Product-based**         | Assign developers as **Collaborators** across multiple product Orgs.             |
| **SCM integration-based** | Use custom roles and the Snyk API to automate role assignment during SCM import. |

{% embed url="<https://res.cloudinary.com/snyk/video/upload/v1775661961/2._Setting_Up_Roles_and_Permissions_h69yve.mp4>" %}
Setting up roles and permissions video guide
{% endembed %}


# Connect your development tools

How to connect development tools in a Snyk template Organization to roll out consistently at scale

To roll out Snyk efficiently at scale, your first major milestone is configuring a Template Organization. Rather than setting up every new team from scratch, this template acts as your master blueprint. By configuring your core tools, source control integrations, and default security behaviors here first, you establish a standardized baseline that can be easily cloned, either manually or using the API, across your entire business.

As you work through this page, you will:

1. [Configure SCM integrations for Groups.](#configure-scm-integrations-for-groups)
2. [Configure SCM integrations for Organizations.](#configure-scm-integrations-for-organizations)
3. [Set up Container registries.](#set-up-container-registry-integrations)
4. [Set up additional integrations.](#set-up-additional-integrations)
5. [Configure Universal Broker.](#configure-the-universal-broker-connection)
6. [Enable Snyk Code.](#enable-snyk-code)

## Set up your SCM integrations

When implementing your SCM integrations, you must configure connections at two Snyk levels: **Group** and **Organization**.

The following table outlines the difference between these two implementation levels.

| Category                 |                         Group level SCM                        |                            Organization level SCM                            |
| ------------------------ | :------------------------------------------------------------: | :--------------------------------------------------------------------------: |
| **Description**          |               Monitors your entire SCM landscape               |     Created so specific teams can actively find and fix vulnerabilities.     |
| **Primary purpose**      |                     Global asset discovery                     |   Running Snyk security tests and automatically raising Fix Pull Requests.   |
| **Required permissions** |                            Read only                           |                                Read and write                                |
| **Scope**                | Access to all repositories in your SCM, both new and existing. | Restrict access to repositories owned by that specific Organization or team. |

### Configure SCM integrations for Groups

Configure your Source Control Manager (SCM) at the Group level to centralize authentication. This allows Snyk to access your repositories across multiple Organizations without requiring individual configuration for each one.

{% embed url="<https://res.cloudinary.com/snyk/video/upload/v1775661962/3._Group-Level_Repository_Discovery_jvicn7.mp4>" %}
Group level repository discovery video guide
{% endembed %}

{% stepper %}
{% step %}
**Select your SCM platform**

{% hint style="success" %}
**Key decision:** Choose the SCM platform that hosts your primary development work and determine if you require **Snyk Broker** for an on-premise connection.
{% endhint %}

1. In the Snyk web UI, navigate to **Group Settings** > **Integrations**.
2. Select your SCM platform (for example, GitHub, GitLab, or Azure Repos).

If your SCM is behind a firewall, you must install and configure Snyk Broker to establish a secure, outbound-only connection.
{% endstep %}

{% step %}
**Authenticate the integration**

{% hint style="success" %}
**Key decision:** Determine which service account or administrative user will provide the initial OAuth or Personal Access Token (PAT) to ensure the connection remains stable.
{% endhint %}

1. Follow the prompts to authorize Snyk to access your SCM organization.
2. Use a service account: Snyk recommends using a dedicated service account rather than a personal user account to prevent integration failure if an individual leaves the company.
3. Grant the required permissions for Snyk to read manifest files and, if desired, create pull requests (PRs) for security fixes later in your rollout.
   {% endstep %}

{% step %}
**Align with your Organization structure**

{% hint style="success" %}
**Key decision:** Decide if you will use a single Group-level integration or if specific Organizations require separate credentials based on your established hierarchy.
{% endhint %}

Your integration approach should match the structure you selected during the planning phase:

* **SCM organization-based structure**: If you have 10+ SCM organizations and are using the `snyk-api-import` tool, ensure your Group-level integration has the scope to access all relevant repositories.
* **Team-based structure**: Use Group-level authentication to ensure consistency across different developer teams while maintaining isolated Organizations.
* **Product-based structure**: Centralizing at the Group level allows developers to seamlessly access Projects across multiple product Organizations.

| Structure type    | Integration strategy                                                        |
| ----------------- | --------------------------------------------------------------------------- |
| **SCM-based**     | Use one Group integration to discover and import all SCM organizations.     |
| **Team-based**    | Use Group-level authentication for centralized credential management.       |
| **Product-based** | Centralize at the Group level to simplify access for full-stack developers. |
| {% endstep %}     |                                                                             |
| {% endstepper %}  |                                                                             |

### Configure SCM integrations for Organizations

Configure SCM integrations at the Organization level to establish granular connections for specific teams, products, or business units. While Group-level integrations provide a global baseline, Organization-level settings allow for isolated credentials and team-specific automation.

{% hint style="info" %}
If you are using multiple SCMs, Snyk recommends using separate Organizations for each SCM integration.
{% endhint %}

{% stepper %}
{% step %}

#### Establish granular authentication

{% hint style="success" %}
**Key decision:** Determine if this specific Organization requires a unique access token or a different service account than the one used at the Group level.
{% endhint %}

Unlike Group-level setup, Organization-level integrations allow you to:

* **Isolate access:** Use a unique Personal Access Token (PAT) or OAuth connection that only has access to a specific team's repositories.
* **Override Group defaults:** If a specific business unit uses a different SCM instance (for example, a separate GitHub Org or GitLab Group), you can configure it here without affecting the rest of the company.

Set up your Org-level integrations by navigating to your Organization **Integrations** page and selecting the relevant SCM tile.
{% endstep %}

{% step %}

#### Consider specific Snyk Broker tokens

{% hint style="success" %}
**Key decision:** Identify if this Organization requires a dedicated Snyk Broker token to segment network traffic or satisfy distinct security requirements.
{% endhint %}

When configuring at the Organization level, consider:

* **Token segmentation:** You can assign a unique Broker token to an Organization. This is useful if different teams operate in different VPCs or data centers.
* **Granular troubleshooting:** Dedicated tokens allow you to monitor and troubleshoot connectivity issues for a specific team without impacting the entire Group.

{% hint style="info" %}
If you are using Azure Repos, Snyk recommends using Universal Broker to avoid Azure limitations on organization mapping.
{% endhint %}
{% endstep %}

{% step %}

#### Define team-specific automation

{% hint style="success" %}
**Key decision:** Decide which PR check behaviors and fix strategies apply to this team’s specific development workflow.
{% endhint %}

While the Group integration provides the connection, the Organization level is where you define how Snyk interacts with your code, through:

* **Targeted PR checks:** Enable or disable PR checks for specific Organizations based on the team's maturity level.
* **Customized fix PRs:** Configure whether Snyk should automatically open fix PRs for this Organization's Projects, allowing for a phased rollout of "prevention" features.

| Feature             | Organization-level specific benefit                                    |
| ------------------- | ---------------------------------------------------------------------- |
| Access control      | Limits repository visibility to only the members of that Organization. |
| Snyk Broker mapping | Maps specific SCM instances to specific internal network segments.     |
| Customized rollout  | Allows for different "prevention" settings (PR checks) per team.       |
| {% endstep %}       |                                                                        |
| {% endstepper %}    |                                                                        |

## Set up Container registry integrations

Integrate Snyk with your container registries to import and monitor images for known vulnerabilities. This ensures that the base images and layers used in your deployments are continuously scanned against the Snyk vulnerability database.

{% stepper %}
{% step %}

#### Select your registry provider

{% hint style="success" %}
**Key decision:** Identify which container registries (for example, Docker Hub, Amazon ECR, Google Artifact Registry) host your production-ready images and determine if they reside behind a firewall.
{% endhint %}

1. In the Snyk web UI, navigate to **Integrations** > **Container Registries**.
2. Select your specific registry provider.

If your registry is on-premise or behind a firewall, you must use Snyk Broker to establish a secure connection.
{% endstep %}

{% step %}

#### Authenticate and authorize

{% hint style="success" %}
**Key decision:** Use a dedicated service account with read-only permissions to the registry to maintain a stable connection and follow the principle of least privilege.
{% endhint %}

1. Provide the required credentials (for example, Access Keys, Role ARNs, or JSON keys) as specified by your registry provider.
2. Ensure the account has sufficient permissions to list and pull images for scanning.

{% hint style="info" %}
For Amazon ECR, Snyk recommends using Cross-Account Role authentication for enhanced security.
{% endhint %}
{% endstep %}

{% step %}

#### Configure scan frequency and visibility

{% hint style="success" %}
**Key decision:** Decide on a monitoring frequency that balances security visibility with your team's remediation capacity.
{% endhint %}

Once integrated, Snyk allows you to manage how often images are re-tested:

* **Continuous monitoring**: Snyk automatically rescans imported images daily to detect new vulnerabilities.
* **Avoid duplication**: If you already scan images in your CI/CD pipeline using the Snyk CLI, decide if you also need registry-level monitoring. Registry integration provides a last line of defense for images currently in storage.

As with SCM integrations, ensure email notifications are disabled at the Organization level during the initial bulk import of images to prevent alert fatigue.

| Integration level  | Recommended for    | Advantage                                                          |
| ------------------ | ------------------ | ------------------------------------------------------------------ |
| Container registry | Security teams     | Visibility into all stored images and production snapshots.        |
| CI/CD pipeline     | DevOps/Developers  | Catching vulnerabilities before the image is pushed to a registry. |
| Kubernetes         | Platform engineers | Monitoring vulnerabilities in active, running workloads.           |
| {% endstep %}      |                    |                                                                    |
| {% endstepper %}   |                    |                                                                    |

### Use cases for direct registry integration

Snyk strongly recommends integrating your container registry if your organization fits any of the following profiles:

* **Empowering AppSec autonomy**: This solution enables Application Security (AppSec) teams to manage and scan container images independently. It allows security teams to maintain oversight without bottlenecking developers or requiring them to change existing workflows.
* **Scanning legacy and offline images:** If you have a large number of older images or multiple legacy tags that no longer have an active build pipeline, registry integration is the most efficient way to ensure they are still scanned for vulnerabilities.
* **Small-scale repositories:** Direct integration and UI management work best for smaller volumes of images (under 1,000). A smaller inventory makes the import process seamless and keeps the user interface fast and responsive.
* **Limited developer bandwidth:** If your development team lacks the availability to update build pipelines or integrate new security tools into their current processes, direct registry scanning provides a frictionless alternative.

### Use cases for CI/CD or CLI

Direct registry integration is not a one-size-fits-all solution. Consider pivoting to pipeline or command-line testing under the following conditions:

* **High-volume registries:** If your repository exceeds 1,000 images, manually selecting and managing images using the UI can become slow over time.
* **Active, high-velocity workflows:** In practice, many teams skip direct registry integration for their active builds. Instead, they integrate security scanning directly into their CI/CD pipelines or use CLI testing. This "shift-left" approach is often preferred for actively developed applications because it catches vulnerabilities during the build process rather than after the image has been pushed to the registry.

## Set up additional integrations

Configure additional integrations to build a complete inventory of your code-based assets. By connecting Snyk to your broader ecosystem, you can identify coverage gaps and ensure all repositories have the necessary security controls in place.<br>

{% stepper %}
{% step %}

#### Access the inventory

{% hint style="success" %}
**Key decision**: Determine if you have the necessary Group Administrator or **Edit Essentials** permissions to manage the global asset inventory.
{% endhint %}

To start building your inventory:

1. In the Snyk web UI, navigate to your Group.
2. Select **Inventory** from the side menu.
3. Navigate to **Integrations** to view your existing connections or add new ones.
   {% endstep %}

{% step %}

#### Configure SCM integrations for asset discovery

{% hint style="success" %}
**Key decision**: Decide whether to use a broad-access service account token to ensure Snyk can discover all repositories across your development teams.
{% endhint %}

This configuration is specific to asset management and is separate from the Organization-level integrations used for security scanning.

1. Click **Add integration** and choose your SCM provider (GitHub, GitLab, Azure DevOps, or Bitbucket).
2. Apply Group-level tokens: Snyk recommends setting tokens at the Group level. This provides a comprehensive view of all repositories and ensures alignment between security and development teams.
3. Handle large environments: If you have more than 1,000 repositories or encounter API rate limits, deploy a dedicated Snyk Broker instance for asset management.
   {% endstep %}

{% step %}

#### Define application context and tags

{% hint style="success" %}
**Key decision**: Choose which metadata (tags) and application structures are most critical for your risk assessment and reporting.
{% endhint %}

Once assets are imported, use the following features to organize your inventory:

* **Automatic tags**: Snyk automatically adds tags for detected technologies (for example, Python, Terraform).

{% hint style="info" %}
Bitbucket users must add language tags manually.
{% endhint %}

* **Coverage cap filters**: Use the **Coverage** and **Coverage Gap** filters to identify which repositories are missing security products like Snyk Code or Snyk Open Source.
* **Asset hierarchy**: View your assets in a nested structure to see how packages relate to their parent repositories.

| Feature             | Purpose                                                                             |
| ------------------- | ----------------------------------------------------------------------------------- |
| Asset dashboard     | Provides a high-level view of issue trends and control coverage.                    |
| Technology grouping | Organizes assets by the programming languages or tools detected.                    |
| Team mapping        | Groups repositories based on your SCM team structure for easier ownership tracking. |
| {% endstep %}       |                                                                                     |
| {% endstepper %}    |                                                                                     |

## Configure brokered connections

Snyk Universal Broker improves the management of Broker deployments by supporting multiple connections of any type with a single running client (or replica group). Credentials remain in your network and are securely referenced without being transmitted to Snyk. Use Universal Broker to enable Snyk to scan repositories, container registries, or other assets hosted behind your firewall without exposing your internal network.

{% hint style="info" %}
If you prefer to use helm charts for Broker configuration or are configuring a CR agent, Snyk recommends you use [Classic Broker](/platform-administration/snyk-broker/classic-broker).
{% endhint %}

{% stepper %}
{% step %}

#### Determine deployment requirements

{% hint style="success" %}
**Key decision**: Determine your redundancy strategy. While a single Universal Broker instance can manage multiple integrations, Snyk recommends configuring at least two replicas of the client for high availability.
{% endhint %}

Before installation, verify your environment:

* You can run Universal Broker as a Docker container or a Kubernetes pod using Helm. This requires at least 1 CPU and 256 MB RAM.
* Ensure the Broker has outbound HTTPS access (port 443) to [https://broker.snyk.io](https://broker.snyk.io/). No inbound ports need to be opened on your firewall.
* You must have Node.js (version 20 or higher) installed to run the setup CLI, a personal Snyk API token, and **Snyk Tenant Admin** permissions.
  {% endstep %}

{% step %}

#### Configure the Universal Broker connection

{% hint style="success" %}
**Key decision**: Choose whether to link the Broker token to the Group level for broad asset discovery or to a specific Organization for isolated team access. Universal Broker uses a CLI tool to dynamically configure connections rather than generating a static Broker token in the UI.
{% endhint %}

1. Install the setup CLI tool: `npm install -g snyk-broker-config`
2. Start the interactive creation workflow: `snyk-broker-config workflows connections create`
3. Follow the on-screen prompts to input your Snyk Token, Tenant or Org ID, and select the specific integration type you want to connect (for example, GitHub Enterprise, GitLab, or Artifactory).
4. The CLI will generate your `DEPLOYMENT_ID`, `CLIENT_ID`, and `CLIENT_SECRET`. It will also prompt you to create a credential reference name (for example, `MY_GITHUB_TOKEN`) that maps to your actual secret. Keep these values secure for the next step.

{% hint style="info" %}
If you are setting up Snyk Essentials for asset management with over 1,000 repositories, Snyk recommends a dedicated Broker and Organization.
{% endhint %}
{% endstep %}

{% step %}

#### Deploy the Broker instance

{% hint style="success" %}
**Key decision**: Decide on the deployment method (Docker or Kubernetes) that best fits your internal DevOps standards.
{% endhint %}

**Docker deployment**

Run the Docker command using the unified `snyk/broker:universal` image and your specific environment variables:

```
docker run --restart always \
  -p 8000:8000 \
  -e DEPLOYMENT_ID=<YOUR_DEPLOYMENT_ID> \
  -e CLIENT_ID=<YOUR_CLIENT_ID> \
  -e CLIENT_SECRET=<YOUR_CLIENT_SECRET> \
  -e PORT=8000 \
  -e <YOUR_CREDENTIALS_REFERENCE>=<secret_value> \
  snyk/broker:universal
```

**Kubernetes deployment**

Deploy using the official Snyk Universal Broker Helm chart. Ensure your secrets are stored securely as Kubernetes secrets.

```
helm pull oci://registry-1.docker.io/snyk/snyk-universal-broker helm install my-snyk-broker oci://registry-1.docker.io/snyk/snyk-universal-broker
--set deploymentId='YOUR_DEPLOYMENT_ID'
--set clientId='YOUR_CLIENT_ID'
--set clientSecret='YOUR_CLIENT_SECRET'
--set credentialReferences.<YOUR_CREDENTIALS_REFERENCE>='<secret_value>'

```

{% endstep %}

{% step %}

#### Verify the connection

{% hint style="success" %}
**Key decision**: Determine if you need to configure additional environment variables for a proxy server (`HTTPS_PROXY`) or a custom certificate authority (`NODE_EXTRA_CA_CERTS`) to establish the connection out to Snyk.
{% endhint %}

1. If your connection is not fully mapped to an Organization, run `snyk-broker-config workflows connections integrate` in the CLI and select your deployment.
2. Check the Broker client container or pod logs to confirm the connection is established without any missing credentials reference errors.
3. Return to the Snyk web UI and navigate to your Organization **Settings** > **Integrations** page. Confirm the integration tile is marked as **Configured**.
4. Test the integration by importing a Project from your on-premise repository.

| Environment                       | Variable requirement                                                          |
| --------------------------------- | ----------------------------------------------------------------------------- |
| Standard                          | `DEPLOYMENT_ID`, `CLIENT_ID`, `CLIENT_SECRET`, `<YOUR_CREDENTIALS_REFERENCE>` |
| Proxy server                      | `HTTPS_PROXY`                                                                 |
| Custom CA (Certificate Authority) | `NODE_EXTRA_CA_CERTS`                                                         |
| {% endstep %}                     |                                                                               |
| {% endstepper %}                  |                                                                               |

## Enable Snyk Code

{% hint style="info" %}
Snyk Code is disabled for Organizations by default.
{% endhint %}

Enable Snyk Code to activate static application security testing (SAST) for your Organizations. Snyk Code analyzes your source code in real time to identify vulnerabilities and provides developer-friendly remediation advice.

{% stepper %}
{% step %}

#### Verify Snyk Code availability

{% hint style="success" %}
**Key decision**: Determine if Snyk Code should be enabled globally for all Organizations or phased in for specific high-priority development teams.
{% endhint %}

Before enabling Snyk Code, ensure your Snyk license includes SAST capabilities. Snyk Code supports most major programming languages and integrates directly with your existing SCM and IDE setups.
{% endstep %}

{% step %}

#### Enable Snyk Code in Settings

{% hint style="success" %}
**Key decision**: You must enable Snyk Code before importing your first Projects to ensure Snyk performs a code analysis scan during the initial onboarding.
{% endhint %}

Snyk Code is disabled by default in new Organizations. If you enable it after you have already imported a Project, Snyk does not automatically detect the code files. You must re-import the Project to trigger the scan.

1. In the Snyk web UI, navigate to **Settings** > **Snyk Code**.
2. Toggle the switch to **Enabled**.
3. Click **Save changes**.
   {% endstep %}

{% step %}

#### (Optional) Enable Snyk Code at scale using the API

{% hint style="success" %}
**Key decision**: If you are managing dozens or hundreds of Organizations, use the Snyk API to enable Snyk Code programmatically rather than using the web UI.
{% endhint %}

To enable Snyk Code for multiple Organizations:

* Use the `Enable/Disable the Snyk Code` settings API endpoint.
* Incorporate this call into your automated Organization provisioning script (refer to your Organization Template logic).
  {% endstep %}

{% step %}

#### Align with your import strategy

{% hint style="success" %}
**Key decision**: Choose the import method that provides the best resolution for your specific programming languages.
{% endhint %}

While SCM integration is the fastest way to gain visibility, some environments benefit from additional CLI scanning.

| Import strategy   | Benefit of Snyk Code (SAST)                                                      |
| ----------------- | -------------------------------------------------------------------------------- |
| SCM repository    | Provides continuous monitoring and centralized visibility without building code. |
| Snyk CLI          | Best for complex builds or local testing before a developer commits code.        |
| PR or MR scanning | Delivers immediate feedback on new code changes during the review process.       |
| {% endstep %}     |                                                                                  |
| {% endstepper %}  |                                                                                  |


# Create your Snyk structure

How to clone your template Organization to build a Snyk structure that mirrors your business

To create your ideal Snyk structure, reflecting the way your business is structured, you need to clone the template Organization created in the previous phase of this guide. This enables you to create multiple Organizations that cover your critical business units.

{% embed url="<https://res.cloudinary.com/snyk/video/upload/v1775661958/5._Creating_your_Organization_Structure_pheaur.mp4>" %}
Create your Organization structure video guide
{% endembed %}

## Clone the template Organization

{% hint style="success" %}
**Key decision**: Choose between using the Snyk web UI for manual creation or the API for automated, bulk Organization provisioning.
{% endhint %}

After your template is ready, use it to build your structure:

* **Through the web UI**: Select **Template** in the Copy settings from dropdown when you create a new Organization.
* **Through the** [**API**](/developer-tools/snyk-apps/tool-snyk-api-import): Use the `sourceOrgId` parameter in the `Create a new organization` endpoint.

{% hint style="info" %}
Snyk recommends using multiple template Orgs for different regions or business units that use the same SCM. This is because different teams or business units may have different risk profiles, legal requirements, and ways of working with the chosen SCM.
{% endhint %}

Use the following table to understand which configurations transfer to the new Organization.

| Settings cloned                                        | Settings not cloned                                 |
| ------------------------------------------------------ | --------------------------------------------------- |
| All integrations and settings                          | Members and Service Accounts                        |
| SCM and Container settings                             | Existing Projects                                   |
| Notification integrations (for example Slack, or Jira) | Custom policies and ignore settings                 |
| PaaS and serverless integrations                       | Infrastructure as Code (IaC) and Snyk Code settings |

## Configure scan and notification behavior

{% hint style="success" %}
**Key decision**: Decide at what stage of the rollout developers should start receiving automated alerts and PR feedback.
{% endhint %}

Snyk recommends a "quiet" start to avoid notification fatigue during the initial import:

* **Disable PR checks**: In your SCM integration settings, turn off automatic PR tests and fix PRs. Enable these only when you reach the Prevention stage of your rollout.
* **Silence notifications**: Disable email notifications at both the Group and Organization levels during the initial setup.


# Gain visibility by importing repositories

How to gain visibility by importing Projects so Snyk monitors your code, dependencies, containers, and infrastructure

Gaining visibility over your Organization security begins with importing Projects. This process allows Snyk to monitor your code, dependencies, containers, and infrastructure.

There are several ways you can import Projects, depending on your tech stack and package managers:

* **SCM integration:** Recommended for automatic scanning and developer workflows.
* **Snyk CLI:** Recommended for granular control in CI/CD pipelines.
* **Snyk API:** Recommended for large-scale, programmatic automation.

{% embed url="<https://res.cloudinary.com/snyk/video/upload/v1775661957/6._Importing_Your_First_Projects_xn4ncf.mp4>" %}
Import your first Projects video guide
{% endembed %}

## Import Projects using an SCM integration

Use this method to connect repositories for automatic scanning. This is the preferred way for teams who prioritize ease of use.

{% hint style="success" %}
**Key decision**: Determine the scale of your import. Use the web UI for under 100 repositories; use the `snyk-api-import` tool for hundreds or thousands of repositories to mirror your source control structure.
{% endhint %}

To do this:

1. In the Snyk web UI, navigate to **Settings** > **Integrations**.
2. Connect to your SCM code repositories using the specific tile.
3. Configure the integration settings:
   * Disable automatic fixes and PR/Merge checks during initial onboarding.
   * Enable these features after reaching a steady state.
4. Add Projects from the Projects listing in the web UI.
5. Monitor results directly in your SCM repositories.

{% hint style="info" %}
Snyk recommends that any monorepos are imported into separate individual Organizations, rather than being split or imported between multiple Orgs.
{% endhint %}

## Import Projects using Snyk CLI

The Snyk CLI provides granular scanning and is typically implemented in build scripts before deployment.

{% hint style="success" %}
**Key decision**: Decide whether to use `test` to break builds based on severity thresholds or `monitor` to report vulnerabilities passively.
{% endhint %}

1. Install the CLI as part of your build script.
2. Navigate to the Project directory.
3. Run the scan command for your Project type:
   * Code: `snyk code test --org=org-id`
   * Open Source: `snyk test --all-projects --org=org-id`
4. Review results locally or in the Snyk web UI.

## Import Projects using Snyk API

Use the API to trigger scans and handle results programmatically across a large portfolio.

{% hint style="success" %}
**Key decision**: Identify which pipelines require real-time issue identification at scale.
{% endhint %}

1. In the Snyk web UI, navigate to **Settings** > **Service Accounts** and generate an API token.
2. Call the Snyk API in your pipelines.
3. Handle the results programmatically to trigger downstream actions.

## Add Projects tags and attributes

After importing Projects, use Project attributes and tags to categorize your data. This metadata allows you to filter and report on specific subsets of your Organization.

For example, apply the `frontend` attribute and a `Team:Unicorn` tag to your Projects. You can then generate a report specifically for critical frontend vulnerabilities in production owned by Team Unicorn.

Attributes and tags also allow you to:

* Group related Projects for easier management.
* Customize how you view and access Project data.


# Initial team rollout

How to run an initial Snyk team rollout, inviting stakeholders and integrating security into their workflows

Invite your stakeholders to explore Snyk features and integrate security into their workflows. After this step, your teams can fix issues, monitor pipelines, and manage vulnerabilities using integrations like Jira.

Follow these steps to roll out Snyk to your teams:

1. [Configure notifications:](#configure-notifications) Set up email alerts to ensure users receive relevant information without being overwhelmed.
2. [Announce Snyk:](#announce-snyk-to-your-teams) Communicate the rollout to developers using standardized templates.
3. [Provide training:](#provide-developer-training) Direct users to Snyk Learn for product and security education.
4. [Deploy IDE plugins:](#engage-development-with-ide-plugins) Enable developers to find and fix issues locally before they commit code.

## Configure notifications

{% hint style="success" %}
**Key decision**: Determine the notification volume. Snyk recommends disabling all email notifications during the initial import to prevent alert fatigue.
{% endhint %}

Managing notifications ensures that developers only see high-priority issues that require action.

* Instruct administrators to manually enable the critical alerts through their personal settings if they need to monitor progress.
* Once the environment is stable, enable notifications in bulk for **High** and **Critical** severities only.
* Disable all email notifications for new Organizations.

Navigate to **Group** > **Settings** to view the notification defaults overview.

## Announce Snyk to your teams

{% hint style="success" %}
**Key decision**: Assess the current comfort level of your development team. If they are new to security automation, disable intrusive features like Automatic PRs until they have completed initial training.
{% endhint %}

Use these templates to introduce Snyk. Replace the bracketed text with your specific details.

### Email template

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><em>To: Developers</em></p><p><em>Subject: Launching Snyk at \[Company name]</em></p><p><em>Hi all,</em></p><p><em>I’m excited to announce that we’re implementing Snyk at \[Company name]</em></p><p><em>\[optional: add personalized video, if desired]</em></p><p><em>Snyk will help us \[enter your goal(s)].</em></p><p><em>As part of the launch process, we’ll invite you to a short “Intro to Snyk” and Q\&A session to learn more about Snyk and the products we’re implementing. You’ll also have the opportunity to attend a developer training session and get access to Snyk Learn for self-paced tutorials to help you get started.</em></p><p><em>We’re looking forward to building secure applications together, with less frustration and interruption to your workflows for addressing security issues.</em></p><p><em>More info can be found at \[hyperlink to your internal resource page/wiki with more info].</em></p><p><em>Regards,</em></p><p><em>\_\_\_\_\_ \[Sender]</em></p> |

### Instant message template

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><em>To: Developers</em></p><p><em>Subject: Launching Snyk at \[Company name]</em></p><p><em>Hi all,</em></p><p><em>I’m excited to announce that we’re implementing Snyk at \[Company name]</em></p><p><em>\[optional: add personalized video, if desired]</em></p><p><em>Snyk will help us \[enter your goal(s)].</em></p><p><em>As part of the launch process, we’ll invite you to a short “Intro to Snyk” and Q\&A session to learn more about Snyk and the products we’re implementing. You’ll also have the opportunity to attend a developer training session and get access to Snyk Learn for self-paced tutorials to help you get started.</em></p><p><em>We’re looking forward to building secure applications together, with less frustration and interruption to your workflows for addressing security issues.</em></p><p><em>More info can be found at \[hyperlink to your internal resource page/wiki with more info].</em></p><p><em>Regards,</em></p><p><br></p><p><em>\_\_\_\_\_ \[Sender]</em></p> |

## Provide developer training

{% hint style="success" %}
**Key decision**: Match the training to the user persona. Use security education for novices and product training for those needing to master Snyk-specific workflows.
{% endhint %}

* [Snyk Learn security education](https://learn.snyk.io/catalog/security-education/?type=security-education): Teaches general security concepts, such as NoSQL injection and server-side request forgery.
* [Snyk Learn product training](https://learn.snyk.io/catalog/product-training/?type=product-training): Provides role-based learning paths for developers and administrators on the Snyk platform.

## Engage development with IDE plugins

{% hint style="success" %}
**Key decision**: Evaluate the maturity of your AppSec program. For new programs, introduce plugins as a tool to validate fixes for prioritized issues. For mature programs, provide immediate access to prevent new issues from entering the codebase.
{% endhint %}

Snyk IDE plugins allow developers to find and fix vulnerabilities before they reach the CI/CD pipeline. This shift-left approach reduces the time spent on security reviews.

1. Identify the primary IDEs used by your teams (VS Code, JetBrains, Visual Studio, or Eclipse).
2. Provide installation guides for the relevant Snyk IDE extension.
3. Configure regional hosting: If your application is on the EU or AU data center, specify the regional URL in the plugin settings.


# Automate prevention measures

How to automate Snyk prevention and gating to stop new vulnerabilities from entering your applications

Once you have visibility into your existing security posture, implement prevention and gating systems to stop new vulnerabilities from entering your applications. By automating these checks, you empower developers to take responsibility for the security of their specific changes without manually triaging every issue.

Implementing prevention measures involves the following key stages:

1. [Define prevention methods:](#define-prevention-methods) Choose between Pull Request (PR) checks and CI/CD pipeline gating.
2. [Establish exception processes:](#establish-exception-processes) Create clear workflows for handling blocked builds or PRs.
3. [Configure PR/MR checks:](#configure-pr-mr-checks) Set up automated scanning for code changes in your source control manager (SCM).
4. [Integrate with CI/CD pipelines:](#integrate-with-ci-cd-pipelines) Add Snyk tests to your build process as a final gate.
5. [Secure custom images and IaC:](#secure-custom-images-and-iac) Apply prevention to containers and infrastructure as code.
6. [Announce changes:](#announce-prevention-measures) Use templates to inform developers about upcoming gating.

## Define prevention methods

{% hint style="success" %}
**Key decision**: Choose a primary prevention point. Use PR checks for early developer feedback or CI/CD gating for a final check before deployment.
{% endhint %}

You can prevent new issues using two main functions:

* **PR/MR checks**: Available for Snyk Open Source and Snyk Code. These test code changes are immediately upon submission.
* **CI/CD pipelines**: Integrate Snyk into your build pipeline to gate Open Source, Code, IaC, and Container vulnerabilities.

## Establish exception processes

{% hint style="success" %}
**Key decision**: Define who can override security gates. Clear authority prevents development bottlenecks during urgent releases.:
{% endhint %}

Ensure teams understand how to address blocked PRs or failed builds:

* Identify who can override a PR check if a pass is mandatory.
* Determine if an issue can be ignored or if a script can bypass a specific step.

## Configure PR/MR checks

{% hint style="success" %}
**Key decision**: Use a phased rollout. Start with optional checks that show results, then move to blocking checks once developers are familiar with the workflow.
{% endhint %}

PR checks prevent issues from entering the codebase.

* Configure tests to fail only under specific criteria, such as High or Critical severity issues.
* For Snyk Open Source, you can set tests to fail only when a fix is available.

## Integrate with CI/CD pipelines

{% hint style="success" %}
**Key decision**: Choose between native integrations or the Snyk CLI. The CLI offers more flexibility for complex fail criteria, such as using `snyk-filter` to set specific thresholds.
{% endhint %}

Adding Snyk to your pipeline acts as a gatekeeper:

* **No import is required**: Unlike PR checks, pipeline tests do not require repositories to be imported via SCM integration.
* **Use CLI tools**: Use `snyk-delta` to identify only the new vulnerabilities introduced in a specific build.

## Secure custom images and IaC

{% hint style="success" %}
**Key decision**: Move security upstream. Test base images before developers use them to ensure all derived containers start from a secure foundation.
{% endhint %}

* **Container registry**: Run Snyk container tests when creating custom base images. Snyk Container (**Detect Dockerfiles**) is enabled for Organizations by default. To disable it, navigate to the Dockerfile tile under your Org-level SCM integration **Settings**.
* **IaC**: Integrate with workflows like Terraform Cloud to scan configuration files before deployment. IaC is enabled for Organizations by default. To disable it, navigate to Organization **Settings** > **Snyk IaC**.

## Announce prevention measures

{% hint style="success" %}
**Key decision**: Move security upstream. Test base images before developers use them to ensure all derived containers start from a secure foundation.
{% endhint %}

### Email template

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><em>To: Developers</em></p><p><em>Subject: Introducing Snyk tests to PRs \[Company name]</em></p><p><em>Hi all,</em></p><p><em>As part of our ongoing aim to improve our application security at \[Company name], we are preparing to start running Snyk tests against all new pull requests for any repository that has been imported into Snyk.</em></p><p><em>\[optional: add personalized video, if desired]</em></p><p><em>These checks will identify any new High or Critical severity issues that are part of the PR, with the aim of preventing any new significant issues from entering our repositories. At first, these checks will be optional, meaning you are not blocked from merging a PR if one of these vulnerabilities is detected.</em></p><p><em>In the future, this will be changing to a blocking check, so we would recommend you start remediating any new High or Critical issues that are detected in your PRs, so that you aren’t affected when the test is no longer optional.</em></p><p><em>This change will make a huge difference in improving our application security, and by gradually introducing this feature, we hope to avoid any interruptions to your workflow.</em></p><p><em>More info can be found at \[hyperlink to your internal resource page/wiki with more info].</em></p><p><em>Regards,</em></p><p><em>\_\_\_\_\_ \[Sender]</em></p> |

### Instant message template

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| *Snyk tests being introduced to our PRs: From \[date] we’ll be enabling a feature in Snyk so that all new PRs on repositories that have been imported to Snyk will be tested for new vulnerabilities. You’ll see the test will fail if any new High or Critical severity issues are found. Please fix these before merging if possible! For now, the tests are optional, so you can merge the PR even if the test fails, but in the future, we’ll be setting this to be a required check. Get in touch if you have any questions!* |


# Manage and remediate issues

How to manage and remediate your Snyk vulnerability backlog by prioritizing on risk and operationalizing fixes

After establishing visibility and prevention measures, focus on managing your existing vulnerability backlog. This stage involves defining a fix strategy, prioritizing issues based on risk, and operationalizing the remediation process in your development teams. Effective management ensures that your security posture improves over time rather than just maintaining the status quo.

To manage and remediate issues, follow these stages:

1. [Define a fix strategy:](#define-a-fix-strategy) Identify focus areas and group work by team responsibilities.
2. [Apply prioritization filters:](#prioritize-issues) Use Snyk metrics to identify the most critical issues.
3. [Establish remediation workflows:](#establish-remediation-workflows) Integrate with ticket systems like Jira and manage exceptions using the ignore feature.
4. [Monitor adoption and progress:](#monitor-adoption-and-progress) Use Snyk Reports to track resolution trends and team engagement.

## Define a fix strategy

{% hint style="success" %}
Key decision: Select a focus area based on business impact. Start with one high-traffic Organization or public-facing application to demonstrate success before scaling.
{% endhint %}

Analyze your imported Projects to determine where to start:

* **Identify critical assets**: Use discovery data obtained from configuring global settings to prioritize business-critical applications.
* **Group by team**: Assign Open Source and Snyk Code issues to development teams, and Container or IaC issues to DevOps teams.
* **Use metadata**: Filter Projects using attributes or tags to focus on specific business units or application types.

## Prioritize issues

{% hint style="success" %}
Key decision: Choose a primary metric for triage. Use **Priority Score** (900+) for a risk-based approach, or **Severity** (Critical/High) for a policy-based approach.
{% endhint %}

Use Snyk filters iteratively to build your plan:

* **Risk and priority scores**: Start with scores of 900–1000 and work downward.
* **Severity**: filter for **Critical** and **High** issues.

{% hint style="info" %}
For Snyk Open Source, prioritize critical issues with a **Fixable** filter to identify quick wins.
{% endhint %}

* **Exploit maturity**: Focus on issues with **Mature** or **Proof of Concept** exploit code to address the most reachable threats.
* **Issue type**: Run targeted vulnerability campaigns to eliminate specific types of flaws across all Projects, such as SQL injection (using CWE filters).

## Establish remediation workflows

{% hint style="success" %}
**Key decision**: Automate ticket creation. Use the `jira-tickets-for-new-vulns` tool or the Snyk Security in Jira Cloud plugin to ensure visibility in developer backlogs.
{% endhint %}

Operationalize the fix process using:

* **Jira integration**: Automatically create tickets for vulnerabilities that meet your priority criteria.
* **Ignore policy**: Use the **Ignore** feature for issues that cannot be fixed immediately due to environmental context or breaking changes.

{% hint style="info" %}
Ensure to always include a detailed reason and always set an expiration date (monthly or quarterly) for review.
{% endhint %}

* **Permissions**: Restrict ignore permissions to Organization admins in the general settings to maintain oversight.

## Monitor adoption and progress

{% hint style="success" %}
**Key decision**: Track **Resolved** versus **New** issues. A healthy program shows a downward trend in the total backlog over time.
{% endhint %}

Use the **Reports** tab to audit your progress using:

* **Issues summary**: View the **Risk Breakdown** to see open, new, and resolved issues.
* **Adoption tracking**: Identify which Organizations are most active in resolving issues to recognize successful teams or provide extra support where needed.
* **Organization reports**: Allow local admins to identify recurring vulnerabilities common across their specific repositories.


# Trial limitations

Snyk trial and Free plan limitations, including the 14-day trial and full Enterprise pilot options

You can try out Snyk functionalities in several ways:

* Using the limited Free plan
* Using a self-serve 14-day trial
* By piloting the full product with the Enterprise plan

The Snyk 14-day trial offers a sample of the features available in the paid Enterprise plan. However, certain features will have limited functionality or be entirely unavailable in order to provide a seamless experience when the trial concludes.

{% hint style="info" %}
After implementing Snyk Essentials, you must access the Inventory page to ensure it is populated with all the necessary information. Depending on the number of repositories you have imported, the update may take up to several hours.
{% endhint %}

If you consider purchasing the Team plan, remember that the trial offers features beyond those included in the Team plan.

The following Enterprise features are limited or unavailable during the trial:

* [**Single Sign-On (SSO)**](/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk): Not available.
* [**Service Accounts**](/platform-administration/service-accounts/service-accounts): Not available.
* [**Group / Multiple Orgs**](/platform-administration/snyk-hierarchy/groups-and-organizations): Limited to one Group and one Organization
* [**Custom Project Tags**](/scan-fix-and-prevent/scan-with-snyk/snyk-projects/project-tags): Not available.
* [**Custom User Roles**](/platform-administration/user-management/user-role-management): Not available.
* [**Audit Logging**](/platform-administration/user-management/user-management-with-the-api/retrieve-audit-logs-of-user-initiated-activity-by-api-for-an-org-or-group): Not available.
* [**Broker**](/platform-administration/snyk-broker/snyk-broker): Not available.
* [**Self-hosted Git**](/developer-tools/integrations/scm-integrations/organization-level-integrations/github-enterprise): Not available.
* [**Private Registry Integrations**](/scan-fix-and-prevent/scan-with-snyk/snyk-open-source/package-repository-integrations): Not available.
* [**Snyk Essentials Inventory**](/scan-fix-and-prevent/fix/manage-assets): Not available
* [**Snyk Essentials Issue page**](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing/prioritization-for-snyk-essentials): Limited capabilities, the Funnel view, Risk factors, and evidence graph, will not be available.


# Developer security education and Snyk product training with Snyk Learn

Snyk Learn provides interactive developer security education and Snyk product training through lessons and learning paths

[Snyk Learn](https://learn.snyk.io) offers lessons for developer [security education](#security-education) and Snyk [product training](#product-training) with short and interactive content. Snyk Learn also has[ learning paths](https://learn.snyk.io/catalog/?format=learning_path\&type=security-education) for learners to take a predefined set of lessons following a structured flow. These lessons and learning plans are designed to help you start using Snyk, implement a [DevSecOps](/glossary#devsecops) framework, and also to help you implement an ongoing security education and training program.

Snyk Learn is one component of learning available for users and customers. The Snyk [customer resource page](https://snyk.io/customer-resources/) will help you learn the best practices for implementing Snyk in your Organization.

Snyk Learn is integrated into the Snyk Platform, giving learners the ability to [track their progress](/developer-education-with-snyk-learn/snyk-learn/your-learning) and Organizations the ability to manage users through Snyk.

## Feature availability

The following table shows the features available for each plan. For more information about plans, see [Plans and pricing](https://snyk.io/plans/).

<table><thead><tr><th width="294">Plan</th><th>Features</th></tr></thead><tbody><tr><td>Free and Team</td><td><ul><li><a href="/pages/ArzZQlXK7uYv0OL9NwuD">Individual progress tracking</a></li><li><a href="/pages/ArzZQlXK7uYv0OL9NwuD">Lessons and learning paths</a></li></ul></td></tr><tr><td>Snyk Enterprise Plan</td><td><ul><li><a href="/pages/Pxs1eDWzFHm5h98uWLo4">Access Controls</a></li><li><a href="/pages/p93wHK1PcR1b1xX4GNeP">API Access (Beta)</a></li><li><a href="/pages/FBknhMlPLUpet1J0HuQX">Org Level Usage Reports</a></li></ul></td></tr><tr><td>Learning Management add-on</td><td><ul><li><a href="/pages/27L3UFkasLgoneAYksTJ">Assignments</a></li><li><a href="/pages/p93wHK1PcR1b1xX4GNeP">Extended API Access</a></li><li><a href="/pages/LAirOzZv5M91UwynFEBG">Learning programs</a></li><li><a href="/pages/RdA1rRqtkmbPDHvm6exh">Program Reporting</a></li><li><a href="/pages/9xCOHU4azquwjMHxJPNU">Snyk Assist (AI Learning Assistant)</a></li><li><a href="/pages/ArzZQlXK7uYv0OL9NwuD">Vulnerabilities in your code</a></li></ul></td></tr></tbody></table>

### Learning Management add-on

The Snyk Learning Management add-on allows AppSec and compliance teams to easily [assign](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-assignments) lessons, track progress, and download reports for proof of completion. These capabilities are also supported through the [Snyk Learn API](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-api).

For more information and to add this capability to your Snyk plan, contact your Snyk account team.

## Regional hosting

Snyk Learn also allows for regional hosting and data residency. Multi-tenant support enables seamless operation across multiple deployment environments, specifically tailored to meet the needs of Snyk users in the US, AU, and EU.

Snyk customers have access to Snyk Learn resources according to their region in the Snyk application. There is no need to create an additional user. For more information, see [Regional hosting and data residency](/snyk-data-and-governance/regional-hosting-and-data-residency).

## Security education

Snyk[ security education](https://learn.snyk.io/catalog/?type=security-education) provides in-depth resources on developer security. Using resources on Snyk Learn, developers learn how to stay secure with interactive lessons exploring vulnerabilities across various languages and ecosystems.

Security education lessons address the needs of developers who want to learn more about general security best practices or specific vulnerabilities and how to mitigate them. Snyk Learn is also helpful for developers, team leads, and managers who want to enhance the general security knowledge of their team.

The lessons on Snyk Learn are aligned with the[ NIST NICE Framework](https://www.nist.gov/itl/applied-cybersecurity/nice) Work Role Categories and Competency Areas.

Security education lessons cover many languages, including JavaScript, Java, C#, Python, PHP, Go, Rust, Ruby, and C++. Snyk Learn also has lessons in general security, Kubernetes, artificial intelligence, and LLMs.

Snyk offers multiple security education learning paths, including OWASP Top 10, Snyk Top 10, and Security for Developers, built in partnership with [NYU](https://engineering.nyu.edu/academics/programs/cybersecurity-ms-online/nyu-cyber-fellows/badges/snyk).

## Product training

Snyk[ product training](https://learn.snyk.io/catalog/?type=product-training) provides videos and self-paced courses for learning how to use Snyk, including:

* How to implement Snyk
* How to configure and manage Snyk organizations
* How to use Snyk to find and fix issues

The platform provides an easy way for teams to get an introduction to Snyk tools and user best practices. Most courses take between three and ten minutes.

Snyk offers product training[ learning paths](https://learn.snyk.io/catalog/?type=product-training\&format=learning_path), including Implementing Snyk, Managing application security with Snyk, and Developing using Snyk.


# Your learning

How to find and take Snyk Learn lessons and learning paths from the catalog based on your interests and needs

## Finding learning opportunities

You can see all of the lessons and learning paths available at <https://learn.snyk.io/catalog/>. You can search or use the filters to help find learning opportunities that are relevant to your interests and needs. The catalog covers common application security topics and product training for Snyk. For developers, we recommend getting started with the [OWASP Top 10 Learning Path](https://learn.snyk.io/learning-paths/owasp-top-10/).

{% hint style="info" %}
Issue details in the Snyk Web UI, in IDE integrations, and in pull requests, may include a link to Snyk Learn education when there is a lesson related to the issue.
{% endhint %}

When you are logged in to Snyk Learn, you can also filter by status to see learning that is in progress or already complete.

You can specify categories of learning on your profile to improve learning recommendations.

## Your profile

In your profile, you can set your learning preferences, including the preferred language.

<figure><img src="/files/R2YLpaJS6Jefz0Wpwt3U" alt=""><figcaption><p>Snyk Learn My Profile</p></figcaption></figure>

## In progress learning

The [Learning Progress](https://learn.snyk.io/user/learning-progress/) area lets you see your in-progress learning and start where you left off. You will also receive recommendations for what to learn next.

## Vulnerabilities in your code

{% hint style="info" %}
**Feature availability**

"Vulnerabilities in your code" is available in the Learning Management add-on offering. For more information, contact your Snyk account team.
{% endhint %}

When viewing a security education lesson, authenticated users can see a **Do I have this vulnerability in my code??** section. This shows real Snyk Code vulnerabilities from your preferred Organization that match the lesson topic, based on CWE identifiers.

For each matching project, you can see:

* The project name, origin, and branch
* Issue counts by severity (critical, high, medium, low)
* Up to three matching issues with direct links to fix them in the Snyk Platform

This requires active Snyk Code projects in your preferred Organization.

<figure><img src="/files/NNGOFn86C1QK2hO8CbvL" alt=""><figcaption></figcaption></figure>

## Assigned learning

{% hint style="info" %}
**Feature availability**

Assignments are available in the Snyk Learning Management add-on offering. For more information, contact your Snyk account team.
{% endhint %}

Any learning that is assigned to you appears on the [Learning Progress](https://learn.snyk.io/user/learning-progress/) page and, if set, includes the due date.

## Assessments

Some Snyk Learn lessons include a quiz at the end to test your knowledge. You must be logged in and complete the quiz to mark the course as completed.

## Certificates of completion

For all Snyk Learn security learning paths, you will be awarded a Certificate of Completion upon completion. The certificate recognizes your time and effort to improve your security skills and knowledge. You can download a PDF of the certificate from the Learning Path page.


# Claiming CPE Credits with Snyk Learn

How to claim Continuing Professional Education (CPE) credits for completing Snyk Learn lessons and learning paths

Snyk Learn offers a range of security education lessons and learning paths designed to enhance your application security skills. While these lessons provide valuable knowledge, they do not automatically grant Continuing Professional Education (CPE) credits. To claim CPE credits for your participation in Snyk Learn lessons and learning paths, follow these steps.

{% hint style="info" %}
The specific process for claiming CPE credits may vary depending on your certifying organization.
{% endhint %}

1. Complete a Snyk Learn module.
   1. Log in to your Snyk Learn account and finish a lesson or learning path.
   2. Ensure you meet all completion criteria, such as passing the quiz and engaging with interactive content.
2. Document your learning activity. Record essential details of the completed module, including:
   * Course title
   * Provider name: Snyk
   * Completion date
   * Duration: Time spent on the module
3. Submit to your certification body.
   1. Access the CPE submission portal of your certifying organization, such as ISC2 or ISACA.
   2. Enter the recorded details and provide any required documentation, such as completion certificates (available for Learning Paths) or screenshots of the completed lesson in your Learning Progress dashboard or the lesson page, see examples below.
4. Provide additional information if requested. You may be asked to supply further details or respond to inquiries from your certifying body to verify your CPE claim.

### Examples

#### Learning path certificate

Navigate to the page for the Learning Path that you completed and click the **Download certificate** button.

<figure><img src="/files/fDUbRiTBSqM9jkQxOzF5" alt=""><figcaption><p>A completed Learning Path with certificate</p></figcaption></figure>

#### Lesson completion example

<figure><img src="/files/DtLL4n4vFqRuAbWGFGKK" alt=""><figcaption></figcaption></figure>


# Snyk Learn reporting

Overview of Snyk Learn reporting, including organization, assignment, and program reports and their plan requirements

{% hint style="info" %}
**Feature availability**

Snyk Learn organization reports are available only with Enterprise plans. Snyk Learn assignment reports and program reports are available only in the Learning Management add-on offering.

For more information, see [plans and pricing](https://snyk.io/plans/).
{% endhint %}

Snyk Learn offers reports to help you track learning progress across your Snyk tenant.

Snyk Learn offers [organization-level reports](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-reports/organization-reports) to understand on an org by org basis how your teams are engaging with the Snyk Learn content. This is useful for team leads or security champions to track the progress of their teams.

You can use the [assignments report](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-reports/assignment-reports) to track individual [Snyk Learn assignments](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-assignments).

For insights into your overall security education and training program performance and engagement, we have [program reporting](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-reports/program-reporting) available in the Snyk app.


# Organization reports

How to view and export Snyk Learn organization reports, available on Enterprise plans to Org and Group admins

{% hint style="info" %}
**Feature availability**

Snyk Learn organization reports are available only with Enterprise plans. For more information, see [plans and pricing](https://snyk.io/plans/).
{% endhint %}

By default, only Snyk Org or Group admins can view and export reports. Group admins can create custom roles by using the standard Snyk workflow. Learn more about the access controls for reports at [Snyk Learn Access Controls](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-access-controls).

{% hint style="info" %}
Snyk Learn organization reports support Organizations with up to 5000 members.
{% endhint %}

## Organization Overview report

The Overview report provides a high-level view of progress across your Organization. This report shows how many users in your Organization have started and completed each lesson or learning path.

<figure><img src="/files/jPZepSvbapTvfIlXwoFQ" alt=""><figcaption><p>Snyk Learn Overview report</p></figcaption></figure>

### Organization Detailed report

The Detailed report provides individual user-level progress tracking within your Organization. This report includes the following progress data for specific lessons or learning paths:

* completion status
* when the lesson or learning path was completed
* when the lesson was previously completed, if lesson progress was reset after the user completed it

<figure><img src="/files/OiqXb8z0sxRI7Tzd6ebp" alt=""><figcaption><p>Snyk Learn Detailed report</p></figcaption></figure>

### Exporting Organization reports

All reports are available as interactive table views and downloadable CSV reports.

User progress is associated with individual users, meaning that if they are members of multiple Organizations, their lesson progress is the same across all Organizations.

The report CSV contains the historical completions and current progress. The learning path overview report CSV contains the current learning path progress and the last completion date.

Progress reporting is also available through the Snyk Learn API (beta), offering two endpoints:

* [Org catalog progress](https://apidocs.snyk.io/?version=2024-10-15#get-/orgs/-org_id-/learn/progress/catalog): progress mapped to the Snyk Learn catalog
* [Org user progress](https://apidocs.snyk.io/?version=2024-10-15#get-/orgs/-org_id-/learn/progress/users): progress mapped to the Snyk user


# Assignment reports

How to track training progress with Snyk Learn assignment reports, available in the Learning Management add-on

{% hint style="info" %}
Snyk Learn assignment reporting is available only in the Learning Management add-on offering. For more information, contact your Snyk account team.
{% endhint %}

After you have created your first [Assignments](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-assignments) with Snyk Learn, you can use the Assignment reporting to track progress at an organization level. This is useful for team managers, security champions, AppSec engineers, and compliance team members to follow up on detailed progress and to extract reports for compliance usage.

## Assignment report

By navigating to your [assignment](https://learn.snyk.io/admin/assignments/) dashboard, you can find reports showing your organizational progress against assignments.

You can also use the filter to drill down further, and the buttons below the filter allow you to change the due date, delete assignments, and also trigger email reminders for your users.

<figure><img src="/files/w3uNYNxbEtyks8qmi3Vc" alt=""><figcaption></figcaption></figure>

### Changing the due date

First, select the assignments you would like to change the due date for, and then press the icon highlighted in the image below. You will then be asked to pick a new date. This updates the due date, and also updates the user's Learning Progress dashboard.

<figure><img src="/files/J5lxGyY38PoMKuo1D4va" alt=""><figcaption></figcaption></figure>

### Sending a reminder email

By selecting an assignment and then pressing the button highlighted you can trigger a reminder email to be sent. You will be offered the chance to add a custom message before the reminder is sent.

<figure><img src="/files/lSOlZ4kdSPcWaJYIWqXK" alt=""><figcaption></figcaption></figure>


# Program reporting

How to gain insights into your security training program with Snyk Learn program reporting in the Learning Management add-on

{% hint style="info" %}
Snyk Learn program reporting is available only in the Learning Management add-on offering. For more information, contact your Snyk account team.
{% endhint %}

Snyk Learn provides a Snyk in-app reporting powered report to give you insights into your security training and education program.

## Learn engagement report

The goal of the engagement report is to provide insights into the overall progress of your security education and training programs, and give you insights into which parts of your Organization are engaging with Snyk Learn content. You can use the data and insights to better optimize your program, find security champions, generate reports for compliance, and show progress to your executive sponsors. This report is available at the Group level.

Read more about this report [here](/scan-fix-and-prevent/prevent/analytics/reports-tab/education-reports#learn-engagement).

{% hint style="info" %}
[Learning Programs](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-learning-programs) are not included in the Engagement Report
{% endhint %}

<figure><img src="/files/W2eWFUJXzGbXm6Ybd5eE" alt=""><figcaption></figcaption></figure>

## Learning Impact & Opportunities report

{% hint style="info" %}
The Learning Impact & Opportunities report is available in Early Access.
{% endhint %}

The goal of the Impact and Opportunities report is to provide insights into the impact your security education and training programs have on code issue remediation and prevention. In addition, the report gives recommendations for future training based on your code issue backlog and issues that were introduced during the selected time period of the report. This report is available at the Group level.

Read more about this report [here](/scan-fix-and-prevent/prevent/analytics/reports-tab/education-reports#learning-impact-and-opportunities).

<figure><img src="/files/6oIhjeaexi4cvNlYjKl5" alt=""><figcaption></figcaption></figure>

<div><figure><img src="/files/8ZsNfdnO8Rd7aMhgU7zX" alt=""><figcaption></figcaption></figure> <figure><img src="/files/nvG6OZs4dpQCXuzP8M2h" alt=""><figcaption></figcaption></figure></div>


# Snyk Assist for Learn

Snyk Assist for Learn, an AI-powered assistant that answers Snyk product and security questions in the Learning Management add-on

{% hint style="info" %}
Snyk Assist is available only in the Learning Management add-on offering. For more information, contact your Snyk account team.
{% endhint %}

Snyk Assist for Learn is an AI-powered learning assistant integrated into the Snyk Learn platform. It is designed to answer your Snyk product and application security questions instantly, helping you learn faster and resolve queries efficiently directly within your learning environment.

Snyk Assist enhances your learning experience within the Snyk Learn platform by:

* Providing immediate answers to questions about Snyk products, features, and general application security concepts.
* Delivering context-aware replies based on Snyk's extensive knowledge base.
* Suggesting relevant follow-on learning opportunities available within Snyk Learn, Snyk Docs and the Snyk Blog.

<figure><img src="/files/yGXf34DuiTz12nmFq9JC" alt=""><figcaption><p>Snyk Assist on Snyk Learn</p></figcaption></figure>

## How Snyk Assist works

Snyk Assist utilizes Generative AI to respond to questions based on information retrieved from trusted Snyk sources:

* [Snyk Learn lessons](https://learn.snyk.io/catalog/?format=lesson)
* [Snyk Documentation](/)

Snyk Assist **does not** have access to your Snyk tenant data, such as issue and asset information, or Snyk Learn learning history. While interacting with Snyk Assist, we collect and process your queries and conversation history to provide responses and improve our service.

The technology leverages Snyk-managed services and selected third-party Large Language Model (LLM) providers to respond with helpful and informative answers.

{% hint style="info" %}
**Capabilities and Limitations**

* Snyk Assist **is designed** to answer questions regarding Snyk functionality and security concepts based on its knowledge base derived from Snyk Learn and Snyk Docs.
* Snyk Assist **does not** perform security analysis, check your code for vulnerabilities, comment on code quality, or provide specific code samples. For code scanning and analysis, continue using the Snyk CLI, Snyk IDE extensions, or recurring SCM tests integrated with your repositories.
* Snyk Assist provides information from its body of knowledge, but responses should not be considered legal, security, or compliance advice. While we strive for accuracy, Snyk is not liable for decisions made based on information provided by Snyk Assist. Always verify critical security information through official Snyk documentation and tools.

See the usage disclaimer [here](https://snyk.io/policies/snyk-assist-disclaimer).
{% endhint %}

## Using Snyk Assist

Snyk Assist is accessible directly within the Snyk Learn interface for users with access to the platform, and where your Snyk admin has enabled the functionality.

1. Navigate to [Snyk Learn](https://learn.snyk.io).
2. Click the **Snyk Assist** icon <img src="/files/uV5pknIyTJxEIfMma6Fm" alt="" data-size="line"> to open the chat window. This is found in the bottom right of the page.
3. Type your questions about Snyk products or application security concepts into the chat prompt.

Snyk Assist will answer based on its knowledge base, potentially including links to relevant documentation, Learn lessons, and Snyk blogs.

{% hint style="info" %}
If you do not see the chat icon, your Snyk admin may not have enabled this functionality for your Group. Additionally, ensure that the default Org in your Snyk settings is set to your company's Snyk Org and not a personal Snyk Org.
{% endhint %}

## Enabling Snyk Assist

Snyk Group Admins can control the availability of Snyk Assist for users within their scope.

To enable Snyk Assist for your Group:

1. Log in to the Snyk Web UI.
2. Navigate to the Group settings page for the Group you wish to manage.
3. Toggle on **Snyk Assist** to enable Snyk Assist for users within that Group.

After Snyk Assist is enabled, it is visible and accessible on Snyk Learn for the users belonging to that specific Group.

<figure><img src="/files/GteLq2GSgkBzrZtlvxQt" alt=""><figcaption><p>Snyk Assist settings page</p></figcaption></figure>

## Data Handling and Safeguards

See [How Snyk handles your data](/snyk-data-and-governance/how-snyk-handles-your-data#snyk-learn) for more information on this topic.


# Snyk Learn assignments

How Snyk Learn assignments let admins assign, track, and manage developer training in the Learning Management add-on

{% hint style="info" %}
**Feature availability**

Assignments are available in the Snyk Learning Management add-on offering. For more information, contact your Snyk account team.
{% endhint %}

Assignments streamline training management by empowering admins to assign, track, and manage learning efficiently. The Assignments feature enhances accountability by allowing customers to set due dates for completion and seamlessly integrate with organizational goals, for example, compliance timelines, ensuring alignment across training initiatives.

Using Assignments, your company can gain:

* Efficiency: Save time and effort in managing and tracking training assignments.
* Clarity: Set clear expectations with start and due dates for completion.
* Security: Equip developers with the knowledge to write more secure code, mitigating risks and vulnerabilities.
* Engagement: Promote active participation by providing personalized learning paths.
* Compliance: Get help with meeting regulatory requirements through the timely completion of mandatory training.

{% hint style="info" %}
Snyk Learn Assignments support Organizations with up to 5000 members.
{% endhint %}

## Use cases for assignments

### Onboarding new employees

Ensure new employees complete their onboarding training within a designated timeframe. Assignments can include mandatory onboarding training content. The progress reset feature allows re-onboarding by clearing previous progress.

### Annual secure coding training

Mandate annual secure coding training for all employees. Assignments can span a specific year period and include relevant security education content. The admin can use the progress reset feature to reset last year’s progress for the new cycle.

### Product update training for the development team

Ensure developers are trained on new product features. Admins can create assignments that include product training content on new features. If significant updates require retraining, the admin can use the progress reset feature.

### Compliance training

Ensure employees complete training for compliance requirements, such as PCI DSS, SOX, SOC-2, HIPAA, and ISO 27001 certification. Admins can create assignments that cover the effective period of new regulations, including content required by compliance. The admin can use the progress reset feature to reset previous progress and mandate updated training.

## Who can be assigned Snyk Learn lessons?

Snyk Learn requires users to have a Snyk Account. After a user has joined Snyk, they are available in the Snyk Learn UI for assignments.

Assignments are linked to the individual user and can be tracked from any Organization they are a member of.

{% hint style="warning" %}
Snyk requires users to log in to the platform before they become active users and are available for assignments.
{% endhint %}

## Who can create assignments?

By default, only Snyk Org or Group admins can create assignments. Group admins can create custom roles by using the standard Snyk workflow. Learn more about the access controls for assignments at [Snyk Learn Access Controls](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-access-controls).

## Creating new assignments

1. Log in to Snyk Learn and click **Assignments** in the account panel dropdown.

<div align="left"><figure><img src="/files/dfbVnY0xqiEUXtL1rDAG" alt=""><figcaption><p>Assignments section on Snyk Learn home page</p></figcaption></figure></div>

2. Select an Organization.

<figure><img src="/files/WL6ysmcYUNu9nsugxchx" alt=""><figcaption><p>Select an Organization in the Assignments Dashboard page</p></figcaption></figure>

3. Click **Create new assignments**.

<figure><img src="/files/JWPlRxgOi1kPg1ZreTKo" alt=""><figcaption><p>Creating new assignments button on the Assignments Dashboard page</p></figcaption></figure>

The **New Assignments** page opens, which allows you to create assignments for Snyk Organization users. On the **New Assignments** page:

1. Verify that the selected Organization is correct.

<figure><img src="/files/ZAiFLz7gBI1o9jFwyryp" alt=""><figcaption><p>Select an Organization</p></figcaption></figure>

2. Select users

<figure><img src="/files/S4icJmsWPgGiNphZ6p2D" alt=""><figcaption><p>Select users to create assignments for</p></figcaption></figure>

3. Select assignment type.

<figure><img src="/files/NJXAg8MladjrEhvTyS5A" alt=""><figcaption><p>Select the assignment type</p></figcaption></figure>

4. Select the content to assign.

<figure><img src="/files/NAf52rpnLBAwzAvPy8kt" alt=""><figcaption><p>Select content to assign</p></figcaption></figure>

5. Optionally set the assignment due date. This date defines the date by which the assignment needs to be completed.

<figure><img src="/files/aziw3XhAbC9YHHya1X8a" alt=""><figcaption></figcaption></figure>

6. Optionally reset user learning progress. If selected this forces users to retake lessons that have already been completed.

<figure><img src="/files/qMlqNtU1x6nsFV3lfSOT" alt=""><figcaption><p>Optionally reset user learning progress</p></figcaption></figure>

7. Optionally send customizable email notifications to assignees. The assigned users are notified of their assignment details through their registered email address.

<figure><img src="/files/SDPdogf05eluzPI1lWL9" alt=""><figcaption><p>Send custom notification emails</p></figcaption></figure>

8. Review the assignment details and click **Submit**.

<figure><img src="/files/MUcvVaxOnhxeOUAzaKJB" alt=""><figcaption><p>Review and submit assignments</p></figcaption></figure>


# Snyk Learn learning programs

How Snyk administrators curate security learning paths with Snyk Learn learning programs, available in Early Access

{% hint style="info" %}
**Feature availability**

This feature is available in Early Access as part of the Snyk Learning Management add-on offering.

Send feedback to your Snyk account team, or email <support@snyk.io>.
{% endhint %}

Learning programs allow Snyk administrators to curate specific paths of security education and Snyk product training, and assign them to groups of developers or Snyk users. By grouping lessons into programs and setting deadlines, organizations can automate security onboarding, meet compliance requirements, and drive targeted remediation.

## Prerequisites

To create and manage learning programs, you must must be a [Tenant Admin](/platform-administration/snyk-hierarchy/tenant) or have a custom role with the `tenant.learning_program.edit` and `tenant.learning_program.read` permissions.

### Example: Creating a custom role

Use the following API call to create a role called Tenant Training Manager specifically for managing learning programs. Replace `{tenant_id}` with your tenant ID from the Snyk app (`https://app.snyk.io/tenant/{tenant_id}`) and `{snyk_api_token}` with your [API token](/developer-tools/snyk-api/authentication-for-api/snyk-api-token-permissions-users-can-control). Also, update the Snyk API URL to your correct [regional API URL](/snyk-data-and-governance/regional-hosting-and-data-residency#api-urls).

```bash
curl --location --globoff --request POST "https://api.snyk.io/rest/tenants/{tenant_id}/roles?version=2024-10-15" \
  --header "Authorization: token {snyk_api_token}" \
  --header "Content-Type: application/vnd.api+json" \
  --data '{
    "data": {
      "type": "tenant_role",
      "attributes": {
        "name": "Tenant Training Manager",
        "description": "This role allows you to create and manage learning programs on Snyk Learn",
        "permissions": [
          "tenant.read",
          "tenant.feature.read",
          "tenant.group.list",
          "tenant.org.list",
          "tenant.pat.create",
          "tenant.membership.read",
          "tenant.user.read",
          "tenant.sso.read",
          "tenant.report.read",
          "tenant.billing.read",
          "tenant.roles.read",
          "tenant.support.case.create",
          "tenant.learning_program.edit",
          "tenant.learning_program.read"
        ]
      }
    }
  }'
```

## Creating a new learning program

{% hint style="info" %}
Programs cannot be edited once they have started. Ensure your lesson list and participant list are final before the start date of the program.

During Early Access, there is a limit to 300 participants per program.
{% endhint %}

Follow these steps to build and launch a new training initiative:

1. Navigate to [Learning Programs](https://learn.snyk.io/admin/management/).
2. Click **Create new learning program**. Enter a unique name (for example, `New Joiners 2026`) and a description.
3. Browse the available Snyk Learn catalog and select the modules you wish to include in the learning program.
4. Download the participants `.csv` template provided in the UI, add the email addresses of your learners, and upload the file.
5. Set the start date and duration for your learning program, and choose whether to send reminders to your users.
6. If needed, you can reset progress for lessons to have your users retake those lessons.
7. Click **Launch program**.

The program appears on the [Learning Progress](https://learn.snyk.io/user/learning-progress/) page for each user in the program, where they can see their progress and the modules required to complete the program.

## Cloning an existing learning program

You can clone an existing learning program to create a new learning program with the same content.

1. Navigate to [Learning Programs](https://learn.snyk.io/admin/management/).
2. Select the learning program you want to clone.
3. Click **Clone**.
4. Enter a unique name (for example, `New Joiners 2026`) and a description.
5. Edit the participants list.
6. Set the start date and duration for your learning program, and choose whether to send reminders to your users.
7. If needed, you can reset progress for lessons to have your users retake those lessons.
8. Click **Launch program**.

## Tracking progress

You can monitor the completion rates of your learning programs.

1. Navigate to [Learning Programs](https://learn.snyk.io/admin/management/).
2. Select the learning program you want to monitor.

The progress state for each user is displayed:

* **Not Started**: The user has been assigned but has not opened any modules.
* **In Progress**: The user has started at least one lesson.
* **Completed**: The user has finished all assigned modules in the program.

## Completing a learning program

Learning programs complete automatically once the scheduled end date is reached.

If needed, you can click **Mark as Completed** on the program details page to end the program early.


# Snyk Learn access controls

How to manage Snyk Learn access controls for assignment and report permissions across your Organization

{% hint style="info" %}
**Feature availability**

Assignment permissions are available in the Snyk Learning Management add-on offering. Report permissions are available to Snyk Enterprise plan customers. For more information, contact your Snyk account team.
{% endhint %}

**Snyk Learn Access Controls** functionality enables you to manage user permissions for Snyk Learn using the same [access control model](/platform-administration/user-management/user-role-management) as the Snyk Platform. A Group Admin can create custom roles with a set of permissions related to Snyk Learn Assignments. These roles can reflect users and functions in the Organization. For example, you can limit permissions for education and training management functionality for Snyk Learn to the user who is the education and training manager at your organization.

{% hint style="info" %}
Group and Organization Admins have access to Snyk Learn Reports and Assignments by default without extra permissions.
{% endhint %}

#### Assignments

To grant permissions for access to Assignments beyond the default Organization and Group Admin roles, you must create a [custom role](/platform-administration/user-management/custom-role-templates/snyk-learn-learning-admin) with a set of permissions for assignments. The custom role must have the View Users permission in order for managing assignments to work. The following lists the permissions for managing assignments:

* View Organization assignments
* Edit Organization assignments
* Create Organization assignments
* Delete Organization assignments

After the role is created, a Group or Organization administrator can give this role to users of Snyk.

For more information, see [Snyk Learn Assignments](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-assignments).

#### Reports

To grant permissions for access to Reports beyond the default Organization and Group Admin roles, you must create a [custom role](/platform-administration/user-management/custom-role-templates/snyk-learn-learning-admin) with a set of permissions for reports. The custom role must have the View Reports permission for viewing and exporting reports to work. The following lists the permissions for viewing and exporting reports:

* View Organization reports

After the role is created, a Group or Organization administrator can give this role to users of Snyk.

For more information, see [Snyk Learn Reports](/developer-education-with-snyk-learn/snyk-learn/snyk-learn-reports).


# Snyk Learn API

How to interact with Snyk Learn programmatically through the Beta Snyk Learn API endpoints in the Snyk REST API

{% hint style="info" %}
**Release status**

The Snyk Learn API endpoints are [Beta](/developer-tools/snyk-api/rest-api/about-the-rest-api#versioning) endpoints.
{% endhint %}

The Snyk Learn API endpoints are part of the [Snyk REST API](/developer-tools/snyk-api/rest-api/about-the-rest-api) and allow for programmatic interaction with Snyk Learn.

The Snyk REST API requires authentication. For information about authentication, see [Authentication for API](/developer-tools/snyk-api/authentication-for-api).

The following table shows the Snyk Learn API endpoints available for each plan. For more information about plans, see [Plans and pricing](https://snyk.io/plans/).

<table><thead><tr><th width="294">Plan</th><th>Features</th></tr></thead><tbody><tr><td>Free and Team</td><td><ul><li>View the <a href="https://apidocs.snyk.io/?version=2024-10-15#get-/learn/catalog">content catalog</a>.</li></ul></td></tr><tr><td>Enterprise</td><td><ul><li>Track learning progress for <a href="https://apidocs.snyk.io/?version=2024-10-15#get-/orgs/-org_id-/learn/progress/users">individuals</a> in an Organization.</li><li>Track overall learning progress for your <a href="https://apidocs.snyk.io/?version=2024-10-15#get-/orgs/-org_id-/learn/progress/catalog">Organization</a>.</li></ul></td></tr><tr><td>Learning Management add-on</td><td><ul><li><a href="https://apidocs.snyk.io/?version=2024-10-15#get-/orgs/-org_id-/learn/assignments">Manage assignments</a>.</li></ul></td></tr></tbody></table>


# Overview

Overview of Snyk platform administration, including managing Tenants, Groups, Organizations, users, roles, and Snyk Broker

{% hint style="info" %}
**Feature availability**

Some functions, such as Custom roles, are available only on certain plans. For more information, visit [plans and pricing](https://snyk.io/plans/).
{% endhint %}

Administration encompasses the following functions:

* [Manage Tenants, Groups and Organizations](#manage-tenant-groups-and-organizations)
* [Manage and use Snyk Projects](/scan-fix-and-prevent/scan-with-snyk/snyk-projects)
* [Manage users in Organizations](/platform-administration/snyk-hierarchy/organizations/manage-users-in-organizations) and [Groups](/platform-administration/snyk-hierarchy/groups/manage-users-in-a-group)
* [Manage user roles](/platform-administration/user-management/user-roles)
* [Manage notifications](/platform-administration/snyk-hierarchy/manage-notifications)
* [Manage settings](/platform-administration/snyk-hierarchy/group-and-organization-settings)

This page covers the following topics:

* [The Snyk workspace](#the-snyk-workspace)
* [User types](#user-types)
* [Snyk Admin tools](#admin-tools)

## The Snyk workspace

Snyk has a hierarchy that controls access to scanning and other Snyk features in the Snyk workspace. This hierarchy changes depending on your Snyk plan level. This includes:

* Tenant
* Groups
* Organizations
* Targets
* Projects

For a detailed view of how Snyk encompasses all your work items in the Snyk workspace, visit [The Snyk hierarchy](/platform-administration/snyk-hierarchy/groups-and-organizations#the-snyk-hierarchy).

## User types

Snyk has the following types of pre-defined users:

* Organization Admin
* Organization Collaborator
* Group Admin
* Group Viewer
* Group Member
* Tenant Admin
* Tenant Viewer
* Tenant Member

Visit the [Pre-defined roles](/platform-administration/user-management/pre-defined-roles) page for more details, including the permissions associated with each role.

## Admin tools

Snyk provides tools to manage Groups, Organizations, user roles and permissions, notifications, and settings.

### Manage users and permissions

You can manage users and permissions in your Groups. For details, see [Manage users and permissions](/platform-administration/user-management/user-role-management).

<figure><img src="/files/z698iVQbNlwUrsngaIuQ" alt="Manage members interface"><figcaption><p>Manage members interface</p></figcaption></figure>

### Manage Tenant, Groups, and Organizations

Snyk groups and organizations help to maintain collaboration across teams. For details, see [Tenant, Groups, and Organizations](/platform-administration/snyk-hierarchy/groups-and-organizations).

### Define notifications

You can manage email notifications for yourself and your Organization. For details, see [Manage notifications](/platform-administration/snyk-hierarchy/manage-notifications).

<figure><img src="/files/nc9OlXdHPp4MpQi4iBOV" alt="Manage email notifications interface"><figcaption><p>Manage email notifications interface</p></figcaption></figure>

### Manage settings

You can customize your Snyk account to suit your work process. For details, see [Manage settings](/platform-administration/snyk-hierarchy/group-and-organization-settings).


# Tenant, Groups, and Organizations

The Snyk hierarchy of Tenant, Groups, and Organizations, and how it controls access to Snyk scanning and features

## The Snyk hierarchy

Snyk has a hierarchy that allows you to control access to Snyk scanning and features.

<figure><img src="/files/aSsZBwLlljH19cddvMqZ" alt=""><figcaption><p>The Snyk hierarchy for Enterprise plans</p></figcaption></figure>

* **Account:** Users must log in to their Snyk account to scan and view or modify any settings and scan
* [**Tenants**](/platform-administration/snyk-hierarchy/tenant): A Tenant encompasses the entire Snyk workspace of your company, team, and individual users. You have one Tenant that encompasses all your Snyk work items: Groups, Organizations, Targets, Projects, and all their adjacent entities, for example, Snyk features, Tags, Collections, and so on.
* [**Groups**](/platform-administration/snyk-hierarchy/groups): A Group encompasses your entire base of Snyk users. You have at least one Snyk Group. Large companies may have multiple Groups with multiple Organizations.
* [**Organizations**](/platform-administration/snyk-hierarchy/organizations): An Organization represents a specific area, such as a team, in your business. Organizations can contain multiple Projects.
* [**Targets**:](/glossary#target) A Target represents the external resource that Snyk scans, like a repository. One Target can relate to multiple Projects. For example, a Target `https://github.com/examplesnyk/example` contains the Projects `package.json` and `Dockerfile.`
* [**Projects**](/scan-fix-and-prevent/scan-with-snyk/snyk-projects)**:** A Project is established based on the item that Snyk scans for issues, such as a manifest file. Each Project shows the results of scans. You can configure your Projects to define how to scan for issues in that Project.

## Snyk features for user management

To manage users in your Tenant, Organizations, and Groups:

* You can use the Snyk API v1 to [provision users to Orgs](/platform-administration/user-management/user-management-with-the-api/provision-users-to-organizations-using-the-api) and [remove members from Groups and Orgs](/platform-administration/user-management/user-management-with-the-api/remove-members-from-groups-and-orgs-using-the-api).
* To find out when a new user was added or to analyze unexpected activity, you can [retrieve audit logs of user-initiated activity](/platform-administration/user-management/user-management-with-the-api/retrieve-audit-logs-of-user-initiated-activity-by-api-for-an-org-or-group) by Organization or Group through the Snyk REST API.
* You can [use Organization access requests](/platform-administration/snyk-hierarchy/organizations/requests-for-access-to-an-organization) to add users and [configure session length for a Snyk Group](/platform-administration/snyk-hierarchy/groups/configure-session-length-for-a-snyk-group).


# Tenants

The Tenant, the top level of the Snyk hierarchy, and the features it manages on Enterprise plans

{% hint style="info" %}
**Feature availability**

Some Tenant features, such as Snyk Analytics, are available only for Enterprise plan customers. For more information, visit [plans and pricing](https://snyk.io/plans/).
{% endhint %}

A Tenant is the top level of the Snyk hierarchy. It encompasses all your Groups and Organizations and all their corresponding Snyk work items. The Tenant is helpful in organizing access and reporting on the platform when you are a large Enterprise with multiple Groups.

At the Tenant level, you can manage access to features that work across your entire Snyk estate, such as [Snyk Analytics](/scan-fix-and-prevent/prevent/analytics) and Members, which allows you to manage users.

Tenant-level roles include **Tenant Admin**, **Tenant Viewer**, and **Tenant Member**. For more information, see [Pre-defined roles](/platform-administration/user-management/pre-defined-roles#role-types).

## Tenant-level options

You can [manage users of a Tenant](/platform-administration/snyk-hierarchy/tenant/manage-users-in-a-tenant) through the **Members** page on the Tenant level.

{% hint style="info" %}
If you are a member of more than one Tenant, you can switch between them by selecting the Tenant name.
{% endhint %}

{% hint style="info" %}
**Snyk 2.0 (Early Access)**

In the Snyk 2.0 UI, you can navigate between different levels of your account (Tenant, Group, and Organization) using the scope selector at the top of the page. When you select a scope, the side menu automatically displays the relevant tools and data for that area.

Snyk 2.0 introduces UI enhancements to the platform navigation and is available in Early Access. This is being rolled out gradually, so not all users see the new navigation at the same time

If you are an existing user, you can switch between the new and classic navigation at any time using the toggle in your user profile menu. For more information, visit [Snyk 2.0 platform improvements](/snyk-2.0-platform-improvements).
{% endhint %}

### Tenant members

To view the users of a Tenant, select **Members**.

Tenant Admins can browse the list of Tenant users, change Tenant level permissions by assigning roles, or remove users.

<figure><img src="/files/0HD3uoX1CfafuqdKhzLl" alt="Tenant member management list with assigned roles"><figcaption><p>Tenant member management list with assigned roles</p></figcaption></figure>

See [Manage users in a Tenant](/platform-administration/snyk-hierarchy/tenant/manage-users-in-a-tenant) for more details.


# Manage users in a Tenant

How to manage members of a Snyk Tenant, available on Enterprise plans

{% hint style="info" %}
**Feature availability**

Tenant functions are available only with Enterprise plans. For more information, see [plans and pricing](https://snyk.io/plans/).
{% endhint %}

Select the name of your Tenant and the **Members** menu option to manage members:

<figure><img src="/files/80akU5Gb4TeTCjY3auGE" alt="Members page option in the Tenant menu" width="201"><figcaption><p>Members page option in the Tenant menu</p></figcaption></figure>

## View Tenant members

<figure><img src="/files/0HD3uoX1CfafuqdKhzLl" alt="Tenant member management list with assigned roles"><figcaption><p>Tenant member management list with assigned roles</p></figcaption></figure>

On the Tenant **Members** page, you can see all the users associated with your Tenant, their authentication type, and their Tenant role. The [pre-defined](/platform-administration/user-management/pre-defined-roles#role-types) Tenant roles are:

* **Tenant Admin**: can access all Tenant products and settings. Reserved for Snyk Admins only.
* **Tenant Viewer:** can see the list of all Tenant users, all the Groups, and all the Organizations of the Tenant.
* **Tenant Member**: the default role of all users of the Tenant with no access to any Tenant level option.

Users with the Tenant Admin or Tenant Viewer roles can navigate the list of users by:

* Reading through the pages of users
* Searching by full name
* Filtering the list by role

## Change Tenant roles

{% hint style="info" %}
Only Tenant Admins can change the roles of Tenant users.
{% endhint %}

You can promote a Tenant Member to a Tenant Viewer or Admin by selecting the role dropdown next to the user's name and choosing the appropriate option.

## Delete Tenant Members

{% hint style="info" %}
Only Tenant Admins can delete Tenant users.
{% endhint %}

To delete a member from the Tenant, click the trash icon next to the user.


# Plan and billing

How to view your Snyk plan and billing details on the Your Plan page, available on Enterprise plans

## Your Plan

{% hint style="info" %}
**Feature availability**<br>

The Your Plan page is available only with Enterprise plans. For more information, visit ([Snyk AI Security Platform plans and pricing](https://snyk.io/plans/)).
{% endhint %}

The **Your Plan** page consolidates your plan information to show your entitlements.

### Plan overview

{% hint style="info" %}
To access the Your Plan page, you must have the Tenant Admin role on an Enterprise plan.
{% endhint %}

Navigate to **Group** **Settings** > **Plan and billing** > **Your Plan** from your Tenant to view your plan, contract details, and included capabilities.

The page header summarizes your plan:

* **Plan**: The name of your current plan, for example, Enterprise.
* **Marketplace**: Snyk displays a badge if your organization purchases through a cloud marketplace, showing whether you transact through the AWS Marketplace or the Google Cloud Marketplace. If you do not purchase through a marketplace, no badge is shown.
* **Term**: Your contract and renewal date. The page shows "Renews" followed by the date, or "Expired" if your contract has ended.
* **Data residency**: The region where Snyk hosts your data.

{% hint style="info" %}
If your account has more than one contract, Snyk displays the earliest renewal date.
{% endhint %}

### Included in your plan

The **Included in your plan** section lists your Snyk capabilities. Snyk does not display capabilities you cannot access.

For each capability, the page displays the contracted metric:

* For capabilities licensed on a fixed-price model, Snyk displays the contracted number, for example, the number of contributing developers.
* For capabilities available on the consumption model, Snyk displays Credits.
* For capabilities you are trialing, Snyk displays a "Pilot" badge and no contracted number.


# Groups

Snyk Groups, which contain Organizations and let teams manage collaborators and Projects together

Snyk Groups make it easier for you to work in teams. Groups can contain many Organizations, and each Organization can contain many collaborators and Projects.

As part of your onboarding, Snyk sets you up with a Group for your company. You can then add your current Organizations to this Group. Enterprise plan customers may have more than one Group. If you think your company will need multiple Groups, submit a request to [Snyk Support](https://support.snyk.io).

{% hint style="info" %}
Visit [Structure your account for high application performance](/getting-started-guides/structure-your-account-for-high-application-performance) for details concerning multiple Groups.
{% endhint %}

## Group-level options

Use Group-level options to view [Organizations](#group-organizations), [reports](#group-reports), [dependencies](#group-dependencies), and [policies](#group-policies) across all of the Organizations in your Group, configure your [Group settings](#group-settings), and view all the [users](#group-members) in a Group.

### Group Organizations

Select **Organizations** to view all the Organizations you have access to and your assigned role inside each one:

If your Group is set up to let its users join Organizations, you also see a list of all the Organizations in the Group and options to join the Organizations where you are not a member.

{% hint style="info" %}
For a detailed breakdown of user roles and their associated access permissions, see [User roles](/platform-administration/user-management/user-roles).
{% endhint %}

### Group reports

Select [**Reports**](/scan-fix-and-prevent/prevent/analytics/reports-tab) to view the vulnerability status of the Organizations in your Group in one place as a report.

### Group inventory

Select [**Inventory**](/scan-fix-and-prevent/fix/manage-assets#inventory-menu) to view, filter, and manage your assets.

### Group issues

Select [**Issues**](/scan-fix-and-prevent/fix/prioritize-issues-for-fixing) to better identify and prioritize your Container, Code, and Open Source issues based on the risk they pose to your application. **Issues** offer a centralized view of all the issues identified by Snyk with additional asset context.

### Group dependencies

You can [view dependencies](/scan-fix-and-prevent/prevent/dependencies-and-licenses/view-dependencies) and [license information](/scan-fix-and-prevent/prevent/dependencies-and-licenses/view-licenses) for all Projects in your Group or Organization using the **Dependencies** option in your Group or Organization menu.

### Group Policies

With Policies, you can easily automate the process of adding business context and receiving notifications.

After a policy is created, it is run in a maximum of 3 hours after creation, then once every 3 hours.

If your policy is set to run daily, then the policy is run 3 hours after the 24-hour period ends. You can always manually run a policy by using the Run button.

### Group integrations

Select **Integrations** to view and configure the available integrations for [SCM integrations](/developer-tools/integrations/scm-integrations/group-level-integrations).

### Group members

Select **Members** to view users in the Group.

Group members are users who have access to all Organizations in the Group. Users of the Organizations are managed in the Settings of each Organization.

<figure><img src="/files/6ZbFZsY0khMWU22kUkF9" alt=""><figcaption><p>Members view for Group users</p></figcaption></figure>

{% hint style="info" %}
See [Manage users in a Group](/platform-administration/snyk-hierarchy/groups/manage-users-in-a-group) for details.
{% endhint %}

### Group Settings

Select **Settings** to view and manage Group settings.

See [Manage settings](/platform-administration/snyk-hierarchy/group-and-organization-settings) for details.


# Manage users in a Group

How to manage members of a Snyk Group, available on Enterprise plans

{% hint style="info" %}
**Feature availability**

Groups are available only for Enterprise plans. For more information, see [plans and pricing](https://snyk.io/plans/).
{% endhint %}

Select the **Group** where you want to manage users and the **Members** menu option to manage your Group members.

As a Group Admin you can do the following:

* [View Group and Organization members](#view-group-and-organization-members)
* [View individual members](#view-individual-members)
* [Promote a Group member to a Group admin](#promote-a-group-member-to-a-group-admin)
* [Delete Group members](#delete-group-members)
* [Filter and sort views](#filter-and-sort-views-of-group-members)

{% hint style="warning" %}
You cannot add external users directly to Groups; you must first add them to an Organization, and then to a Group. For more information, see [Manage users in Organizations](/platform-administration/snyk-hierarchy/organizations/manage-users-in-organizations) for details.
{% endhint %}

## View Group and Organization members

On the Group members page, you can see all the members associated with your Group, their roles and authentication type, the number of Organizations they are members of, and the date they joined.

There are two standard roles available at the Group level, **Group Member** and **Group Admin**.

{% hint style="info" %}
Group Admins have all Snyk permissions; see [Pre-defined user roles](/platform-administration/user-management/pre-defined-roles). However, being a Group Member does not directly grant the user any rights. To have rights, users must be added as Organization members or promoted to Group Admin.
{% endhint %}

<figure><img src="/files/6ZbFZsY0khMWU22kUkF9" alt=""><figcaption><p>View Group members</p></figcaption></figure>

## View individual members

Click the line for each member to view the Group member details for that member.

If the user is a **Group Member**, you can see the user's role in each Organization where that user is a member. You can also see when the user was added and the user's authentication method.

A Group Member can have different roles in different Organizations. You can filter by role. You can also remove a user from a Group or Organization by using the available delete buttons.

<figure><img src="/files/VaSzcD0pd6xpXE2tFVVN" alt=""><figcaption><p>Group member details</p></figcaption></figure>

Users with the Group Admin role have access to all Organizations in that Group, with the same access level as the Organization Admin role in these Organizations. You cannot change the role of a Group admin in a specific Organization, or delete a Group admin from one or more Organizations. However, you can remove a Group Admin from the Group using the **Remove from group** option

## Promote a Group Member to a Group Admin

You can promote a Group Member to a Group Admin by selecting the **role** dropdown next to the user's name and choosing the Group Admin role.

<figure><img src="/files/kabOZT9tOU5HnWcV9Uu0" alt=""><figcaption><p>Promote to Group Admin</p></figcaption></figure>

{% hint style="warning" %}
If the user you want to promote to Group Admin is not already a part of your Group, you must first add that user as a member of at least one Organization; see [Add Members](/platform-administration/snyk-hierarchy/organizations/manage-users-in-organizations#add-users) on the Manage users in Organizations page. The user then appears on the Group members page with the role of Group Member. You can then promote the user to Group Admin.
{% endhint %}

## Delete Group members

To delete a member from the Group:

1. Click the trash icon next to the user.
2. Click **Delete member** from the Group you are managing.

## Filter and sort views of Group members

### Filter views

On the Group members page, click the filter icon to expand the filter sidebar so you can filter the members displayed by role or authentication method:

<figure><img src="/files/RUfiGmr1srjLNBJ4xlV0" alt=""><figcaption><p>Filter by role or authentication method</p></figcaption></figure>

### Sort views

You can sort by name, authentication method, role, and date joined.

You can sort user views by clicking on the column heading:

<figure><img src="/files/7Hok94inMGJYaApdoNj4" alt=""><figcaption><p>Group members column headings</p></figcaption></figure>


# Configure session length for a Snyk Group

How Group admins configure the inactivity session length before Snyk logs users out, by default 24 hours

By default, inactive logged-in users are automatically logged out after 24 hours to protect any account from being exposed inadvertently through user inactivity.

Group admins can change the default session length to any value from five minutes to 30 days.

{% hint style="info" %}
Users who belong to multiple Groups are always logged out automatically after the shortest time configured for any of those Groups.
{% endhint %}

## **Prerequisites for configuring session length**

You must be an administrator of the Group to update the session length.

You must be a customer on a Snyk plan that supports Groups. For more information, see [Plans and pricing](https://snyk.io/plans/).

## **Steps to configure session length**

1. Log in to your Snyk account and navigate to the Group for which you want to configure session length.
2. Navigate to **Settings** to update the Group settings.
3. In the **Session expiration** area, enter values for the session length:

<figure><img src="/files/V3fuSs5L7iAWlKL3vVHP" alt=""><figcaption><p>Session expiration area of Group settings</p></figcaption></figure>

When session length expiration is configured, tracking of session length starts within 60 seconds or when a user logs in, whichever comes first.

{% hint style="info" %}
See the [Group general settings](/platform-administration/snyk-hierarchy/groups/group-general-settings) documentation for more information about Group settings.
{% endhint %}




---

[Next Page](/llms-full.txt/1)

