Snyk Python-3.6 Action
This page provides examples of using the Snyk GitHub Action for Python (3.6). For instructions on using the action and further information see GitHub Actions integration.
Using the Snyk Python (3.6) Action to check for vulnerabilities
The examples that follow show how you can use a Snyk Python GitHub Action.
Snyk requires that Python download the dependencies before running or triggering the Snyk checks.
The Python image checks and installs dependencies only if the manifest files are present in the current path, that is, the path from where the action is being triggered.
- If pip is present on the current path , and Snyk finds a - requirements.txtfile, then Snyk runs- pip install -r requirements.txt.
- If pipenv is present on the current path, and Snyk finds a - Pipfilewithout a- Pipfile.lock, then Snyk runs- pipenv update.
- If - pyproject.tomlis present in the current path and Snyk does not find- poetry.lockthen Snyk runs- pip install poetry.
If manifest files are present under any location other root then they must be installed prior to running Snyk.
You can use the Snyk Python (3.6) Action to check for vulnerabilities as follows:
name: Example workflow for Python-3.6 using Snyk
on: push
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@master
      - name: Run Snyk to check for vulnerabilities
        uses: snyk/actions/python-3.6@master
        env:
          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}You can use the Snyk Python (3.6) Action to check for only high severity vulnerabilities as follows:
name: Example workflow for Python-3.6 using Snyk
on: push
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@master
      - name: Run Snyk to check for vulnerabilities
        uses: snyk/actions/python-3.6@master
        env:
          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
        with:
          args: --severity-threshold=highUsing the Snyk Python (3.6) Action to run snyk monitor
For an example of running snyk monitor, see Snyk monitor example on the GitHub Actions integration page.
Uploading Snyk scan results to GitHub Code Scanning using the Snyk Python (3.6) Action
Using --sarif-file-output Snyk CLI option and the GitHub SARIF upload action, you can upload Snyk scan results to GitHub Code Scanning as shown in the example that follows.
The Snyk Action fails when vulnerabilities are found. This would prevent the SARIF upload action from running. Thus you must use a continue-on-error option as shown in this example:
name: Example workflow for Python-3.6 using Snyk
on: push
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@master
      - name: Run Snyk to check for vulnerabilities
        uses: snyk/actions/python-3.6@master
        continue-on-error: true # To make sure that SARIF upload gets called
        env:
          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
        with:
          args: --sarif-file-output=snyk.sarif
      - name: Upload result to GitHub Code Scanning
        uses: github/codeql-action/upload-sarif@v2
        with:
          sarif_file: snyk.sarifLast updated
Was this helpful?

