# Snyk > When you scan a project with the CLI, the`.snyk`policy file may be in a different directory from the manifest file, either because of the structure of the project or because the project has multiple ## Pages - [A .snyk policy file in a different directory from the manifest file](a-snyk-policy-file-in-a-different-directory-from-the-manifest-file.md): When you scan a project with the CLI, the`.snyk`policy file may be in a different directory from the manifest file,... - [About Snyk Apps](about-snyk-apps.md): Snyk Apps are integrations that extend the functionality of the Snyk platform, allowing you to create a Snyk experien... - [About the REST API](about-the-rest-api.md): The Snyk REST API is based on the [JSON:API standard](https://jsonapi.org/), defined in [OpenAPI 3.0.3](https://spec.... - [About webhooks](about-webhooks.md): {% hint style="warning" %} - [Access requirements](access-requirements.md): When you are using Snyk applications like the [CLI](https://docs.snyk.io/developer-tools/snyk-cli/getting-started-wi... - [AccessRequests](accessrequests.md): {% hint style="info" %} - [Add a new connection to your Universal Broker](add-a-new-connection-to-your-universal-broker.md): To add a new connection, run`snyk-broker-config workflows connections create`. If prompted, select the desired deplo... - [Add and configure Snyk in your CI/CD pipeline](add-and-configure-snyk-in-your-ci-cd-pipeline.md): Using Snyk as a gatekeeper in your build pipeline prevents the introduction of new vulnerabilities. based on the fail... - [Add and configure Snyk to your CI/CD pipeline](add-and-configure-snyk-to-your-ci-cd-pipeline.md): Using Snyk as a gatekeeper in your build pipeline prevents the introduction of new vulnerabilities, based on the "fai... - [Add Artifactory images to Snyk](add-artifactory-images-to-snyk.md): Snyk tests and monitors your Artifactory container images by evaluating the tags in your repositories. - [Add images to Snyk from ACR](add-images-to-snyk-from-acr.md): Snyk tests and monitors Microsoft Azure Container Registry (ACR) container images by evaluating root folders and cust... - [Add more Organizations to your AWS IAM role for Snyk authentication](add-more-organizations-to-your-aws-iam-role-for-snyk-authentication.md): After creating an AWS IAM role for Snyk, you can add more Organizations to the same role for repeated use. - [Add project attributes](add-project-attributes.md): After importing your projects, you can add metadata to your Projects using [Project Attributes](https://docs.snyk.io/... - [Add Project tags and attributes](add-project-tags-and-attributes.md): After importing your Projects, you can add metadata using [Project attributes](https://docs.snyk.io/snyk-platform-adm... - [Add the Snyk Security Task to your pipelines](add-the-snyk-security-task-to-your-pipelines.md): * Ensure you have a pipeline within the repository for the code you want to test. - [Advanced configuration for Helm Chart installation](advanced-configuration-for-helm-chart-installation.md): {% hint style="info" %} - [Advanced configuration for Snyk Broker Docker installation](advanced-configuration-for-snyk-broker-docker-installation.md): {% hint style="info" %} - [Advanced use of Snyk Container CLI](advanced-use-of-snyk-container-cli.md): In addition to scanning images from a local Docker daemon or remote registry, Snyk can directly scan or monitor a Doc... - [AI-BOM](aibom.md): **Note**: AI-BOM is an experimental feature and is subject to breaking changes without notice. If you are using AI-BO... - [Amazon Elastic Container Registry (ECR) - add images to Snyk](amazon-elastic-container-registry-ecr-add-images-to-snyk.md): Snyk scans and monitors your Amazon ECR container images by evaluating the tags as they are in your ECR repositories. - [Amazon EventBridge](amazon-eventbridge.md): The [Amazon EventBridge](https://aws.amazon.com/eventbridge/) integration sends Snyk platform events to EventBridge, ... - [Amazon Q guide](amazon-q-guide.md): You can access Snyk Studio, including Snyk's MCP server, in Amazon Q to secure code generated with agentic workflows ... - [Analysis results: Snyk Code](analysis-results-snyk-code.md): Snyk Code analysis shows security vulnerabilities and quality issues in your code with every scan. - [Analysis results: Snyk IaC configuration](analysis-results-snyk-iac-configuration.md): Snyk IaC configuration analysis shows issues in your Terraform, Kubernetes, AWS CloudFormation, and Azure Resource Ma... - [Analysis results: Snyk Open Source](analysis-results-snyk-open-source.md): Snyk Open Source analysis shows vulnerabilities in your code with every scan. The scan runs in the background and is ... - [Analytics](analytics.md): {% hint style="info" %} - [Analyze and fix container images](analyze-and-fix-container-images.md): You can import container Projects into Snyk using the CLI command [`snyk container monitor`](https://docs.snyk.io/dev... - [Analyze PR checks results](analyze-pr-checks-results.md): After you [submit a pull request to fix vulnerabilities](https://docs.snyk.io/scan-with-snyk/snyk-open-source/manage-... - [Announcement templates for initial rollout](announcement-templates-for-initial-rollout.md): You can use these templates to communicate the Snyk rollout to the rest of the developers. Update the text in bracket... - [Announcement templates for prevention](announcement-templates-for-prevention.md): This page provides example email and Slack message templates that you can use to introduce prevention tools to your t... - [Antigravity guide](antigravity-guide.md): Add Snyk Studio to Google Antigravity to secure code generated with agentic workflows through a Large Language Model ... - [Apex rules](apex-rules.md): Each rule includes the following information. - [Apex](apex.md): {% hint style="info" %} - [API End of Life (EOL) process and migration guides](api-end-of-life-eol-process-and-migration-guides.md): This page explains the process, key dates, and milestones associated with the end-of-life (EOL) cycle for all API end... - [API endpoints index and tips](api-endpoints-index-and-tips.md): {% hint style="info" %} - [API EOL endpoints and key dates](api-eol-endpoints-and-key-dates.md): Beginning July 22, 2024, the following endpoints will follow the EOL process: - [API rate limit control for scm-contributors-count](api-rate-limit-control-for-scm-contributors-count.md): Azure DevOps has a unique way of limiting the API call rate with their own "TSTU" concept as described in this [guide... - [Consistent Ignores for Snyk Code API](api.md): You can manage ignores individually through the [Snyk Policies API (REST)](https://docs.snyk.io/snyk-api/reference/po... - [Application analytics](application-analytics.md): The Analytics menu is available at the tenant level, under the Application Analytics tab. Application Analytics is de... - [Application context for SCM integrations](application-context-for-scm-integrations.md): The application context for SCM integrations provides a comprehensive and interconnected overview of application asse... - [Application Security Engineer role template](application-security-engineer-role-template.md): This Organization-level role can add, move, and remove Projects and ignores, and can mark PR checks as successful. - [Application vulnerabilities in Snyk Container and Snyk Open Source](application-vulnerabilities-in-snyk-container-and-snyk-open-source.md): Snyk Container detects application vulnerabilities in your containers and overlaps Snyk Open Source capabilities.\ - [Apply a custom PR template](apply-a-custom-pr-template.md): You can create a custom PR template using the API endpoint [Create or update pull request template for Group](https:/... - [Apply security and license policies](apply-security-and-license-policies.md): Policies define how Snyk behaves when identifying issues. Policies give you a quick and automated way to identify, pr... - [Apps](apps.md): {% hint style="info" %} - [ARM files](arm-files.md): With Snyk Infrastructure as Code, you can test your configuration files using the CLI. - [Artifactory Gatekeeper Plugin](artifactory-gatekeeper-plugin.md): {% hint style="info" %} - [Artifactory package repository connection setup](artifactory-package-repository-connection-setup.md): {% hint style="info" %} - [Artifactory registry for Maven](artifactory-registry-for-maven.md): {% hint style="info" %} - [Artifactory registry for npm](artifactory-registry-for-npm.md): {% hint style="info" %} - [Artifactory Repository - environment variables for Snyk Broker](artifactory-repository-environment-variables-for-snyk-broker.md): The following environment variables are needed to customize the Broker Client for Artifactory Repository: - [Artifactory Repository - prerequisites and steps to install and configure Broker](artifactory-repository-install-and-configure-broker.md): {% hint style="info" %} - [Artifactory Repository - install and configure using Docker](artifactory-repository-install-and-configure-using-docker.md): {% hint style="info" %} - [Artifactory Repository - install and configure using Helm](artifactory-repository-install-and-configure-using-helm.md): {% hint style="info" %} - [Asset](asset.md): {% hint style="info" %} - [Assets and risk factors](assets-and-risk-factors.md): The capabilities of the SnykWeb UI Issues menu rely on understanding your application context to help you better prio... - [Assets inventory components](assets-inventory-components.md): Each inventory layout is presented in a table format, detailing the available key attributes: - [Assets inventory filters](assets-inventory-filters.md): From the **Inventory** > **All Assets** tab, you can use the search bar to look for specific keywords across assets. ... - [Assets inventory tabs](assets-inventory-layouts.md): Snyk defines an asset as a meaningful, real-world component in an application’s SDLC, where meaningful means either c... - [Assets policies](assets-policies.md): With Policies, you can easily automate the process of adding business context and receiving notifications. - [Assign a policy to an Organization](assign-a-policy-to-an-organization.md): When you create a policy, you can apply it to one Organization. You cannot directly apply an Organization to or remov... - [Assign policies to Projects](assign-policies-to-projects.md): After you apply [Project attributes](https://docs.snyk.io/snyk-platform-administration/snyk-projects/project-attribut... - [Assignment reports](assignment-reports.md): {% hint style="info" %} - [Audit Logs](audit-logs.md): {% hint style="info" %} - [Auditor role template](auditor-role-template.md): This is a Group-level read-only role, meaning an Auditor can only view certain areas and functions in Snyk and cannot... - [Augment Code guide](augment-code-guide.md): Add Snyk Studio to Augment Code to secure code generated with agentic workflows through a Large Language Model (LLM).... - [Auth](auth.md): `snyk auth [] []` - [Authenticate to private container registries](authenticate-to-private-container-registries.md): If you are using private container registries, you must create a`dockercfg.json`file that contains the credentials ... - [Authenticate to use the CLI](authenticate-to-use-the-cli.md): To scan your projects, you must authenticate with Snyk. - [Authentication for API](authentication-for-api.md): {% hint style="info" %} - [Authentication for the Eclipse plugin](authentication-for-the-eclipse-plugin.md): To scan your Projects, you must authenticate with Snyk. - [Authentication for the JetBrains plugin](authentication-for-the-jetbrains-plugins.md): To scan your Projects, you must authenticate with Snyk. - [Authentication for third-party tools](authentication-for-third-party-tools.md): When you work with Snyk from within any third-party tool, Snyk requires authentication in order to initiate its proce... - [Authentication for Visual Studio Code extension](authentication-for-visual-studio-code-extension.md): To scan your Projects, you must authenticate with Snyk. - [Authentication for Visual Studio extension](authentication-for-visual-studio-extension.md): To scan your Projects, you must authenticate with Snyk. - [Authentication using API token does not work](authentication-using-api-token-does-not-work.md): If you **get an authentication error after you have seen the message that authentication was successful**, it may hel... - [Auto-provisioning guide](auto-provisioning-guide.md): {% hint style="info" %} - [Automatically created Project collections](automatically-created-project-collections.md): {% hint style="info" %} - [Automatically link your Dockerfile with container images using labels](automatically-link-your-dockerfile-with-container-images-using-labels.md): Snyk allows you to link manually or automatically from a Dockerfile to all container images built from it. You can us... - [Available Snyk reports](available-snyk-reports.md): The following reports are available: - [AWS API Gateway: add the POST method to connect Snyk to Slack](aws-api-gateway-add-the-post-method-to-connect-snyk-to-slack.md): The payload Slack will receive will have a message, so create a POST method that will receive the message, verify it ... - [AWS API Gateway: deploy the POST method](aws-api-gateway-deploy-the-post-method.md): Deploy with configured POST method so the AWS Lambda function can start receiving the information. - [AWS CDK files](aws-cdk-files.md): With Snyk Infrastructure as Code, you can test your configuration files with the CLI. You can scan the [Amazon Web Se... - [AWS CloudTrail Lake](aws-cloudtrail-lake.md): {% hint style="info" %} - [AWS CodePipeline integration with CodeBuild](aws-codepipeline-integration-by-adding-a-snyk-scan-stage.md): This guide outlines the steps for setting up a [Snyk Open Source](https://snyk.io/product/open-source-security-manage... - [AWS Integration: API](aws-integration-api.md): Before you can onboard an AWS account to Snyk via the API, you need access to the AWS account and associated credenti... - [AWS Integration: Web UI](aws-integration-web-ui.md): Before you can onboard an AWS account via the Web UI, you need access to the AWS account and associated credentials w... - [AWS integration](aws-integration.md): Snyk integrates with your [Amazon Web Services (AWS)](https://aws.amazon.com/) account to find issues in your cloud c... - [AWS Lambda setup: add security through an environment variable](aws-lambda-setup-add-security-through-an-environment-variable.md): For security reasons the script that you created uses an environment variable:`hmac_verification`with a shared secr... - [AWS Lambda setup: create Lambda function to connect Snyk to Slack](aws-lambda-setup-create-lambda-function-to-connect-snyk-to-slack.md): AWS Lambda functions are used to connect Snyk to Slack because these functions are an inexpensive and efficient way o... - [AWS Lambda setup: expose a public URL](aws-lambda-setup-set-up-the-trigger.md): For Snyk to be able to send webhooks to the Lambda function you will need a public URL exposing the function. To do t... - [AWS resources](aws-resources.md): Snyk IaC unmanaged resource scanning supports the following resources for AWS: - [AWS Security Hub](aws-security-hub.md): The [AWS Security Hub](https://aws.amazon.com/security-hub/) integration sends Snyk issues to Security Hub, allowing ... - [Entra ID Enterprise application setup](azure-ad-enterprise-application-setup.md): This example shows setting up an Entra ID (formerly Azure AD) Enterprise Application and connecting this to Snyk to f... - [Azure DevOps for Snyk Essentials](azure-devops-for-snyk-essentials.md): The Integrations page shows all active integrations, including data from your existing Snyk Organizations that is aut... - [Azure DevOps](azure-devops.md): * [Flow and Tech](https://docs.snyk.io/developer-tools/snyk-cli/scan-and-maintain-projects-using-the-cli/cli-tools/sn... - [Azure - Examples](azure-examples.md): The following options are available for the`snyk-scm-contributors-count azure devops`command: - [Azure - Flow and Tech](azure-flow-and-tech.md): 1. Fetch the monitored projects from Snyk (if the`skipSnykMonitoredRepos`flag was **not set** and the`SNYK_TOKEN`... - [Azure Integration: API](azure-integration-api.md): To onboard an Azure subscription to Snyk via the API: - [Azure integration for cloud configurations](azure-integration-for-cloud-configurations.md): Snyk integrates with your [Microsoft Azure](https://azure.microsoft.com/en-us/) subscription to find issues in your c... - [Azure Integration: Web UI](azure-integration-web-ui.md): The steps follow to onboard an Azure subscription to Snyk via the API: - [Azure Pipelines integration using the Snyk Security Scan task](azure-pipelines-integration.md): Snyk enables security across the Microsoft Azure ecosystem, including Azure Pipelines, by automatically finding and f... - [Azure Repos - environment variables for Snyk Broker](azure-repos-environment-variables-for-snyk-broker.md): The following environment variables are required to configure the Broker Client for Azure Repos: - [Azure Repos - install and configure and configure using Helm](azure-repos-install-and-configure-and-configure-using-helm.md): {% hint style="info" %} - [Azure Repos - install and configure using Docker](azure-repos-install-and-configure-using-docker.md): {% hint style="info" %} - [Azure Repos - prerequisites and steps to install and configure Broker](azure-repos-prerequisites-and-steps-to-install-and-configure-broker.md): {% hint style="info" %} - [Azure Repositories (TFS)](azure-repositories-tfs.md): {% hint style="info" %} - [Azure resources](azure-resources.md): Snyk IaC unmanaged resource scanning supports the following resources for Azure: - [Backend requests with an internal certificate for Docker](backend-requests-with-an-internal-certificate-for-docker.md): By default, the Broker Client establishes HTTPS connections to the backend system: GitHub, BitBucket, Jira, or other.... - [Backstage file in Asset Inventory - use case](backstage-file-in-asset-inventory-use-case.md): After you finish configuring the [Backstage catalog](https://docs.snyk.io/developer-tools/scm-integrations/applicatio... - [Basic steps to install and configure Universal Broker](basic-steps-to-install-and-configure-universal-broker.md): {% hint style="info" %} - [Bitbucket Cloud App](bitbucket-cloud-app.md): The Bitbucket Cloud App is positioned to be the default Bitbucket Cloud integration - [Bitbucket Cloud - Examples](bitbucket-cloud-examples.md): The following options are available for the`snyk-scm-contributors-count bitbucket-cloud`command: - [Bitbucket Cloud - Flow and Tech](bitbucket-cloud-flow-and-tech.md): 1. Fetch the monitored projects from Snyk (if the`skipSnykMonitoredRepos`flag was **not set** and the`SNYK_TOKEN`... - [Bitbucket Cloud](bitbucket-cloud.md): {% hint style="info" %} - [Bitbucket Data Center/Server](bitbucket-data-center-server.md): The Bitbucket Data Center/Server integration allows you to continuously perform security scanning across all the inte... - [Bitbucket for Snyk Essentials](bitbucket-for-snyk-essentials.md): The Integrations page shows all active integrations, including data from your existing Snyk Organizations that is aut... - [Bitbucket Pipelines integration: how it works](bitbucket-pipelines-integration-how-it-works.md): After you have added the Snyk pipe to the pipeline, each time the pipeline executes (by any trigger type), the Snyk p... - [Bitbucket Pipelines integration using a Snyk pipe](bitbucket-pipelines-integration-using-a-snyk-pipe.md): Snyk integrates with Bitbucket Pipelines using a Snyk pipe, seamlessly scanning your application dependencies and Doc... - [BitBucket Pipelines migration](bitbucket-pipelines-migration.md): `snyk/snyk-scan`\ **General**. - [Group-level integrations](group-level-integrations.md): Group-level SCM integrations provide broader visibility into all the application assets for a given customer and pull... - [Group Projects by branch or version for monitoring](group-projects-by-branch-or-version-for-monitoring.md): {% hint style="info" %} - [Group](group.md): {% hint style="info" %} - [Tenant, Groups, and Organizations](groups-and-organizations.md): {% hint style="info" %} - [Groups (v1)](groups-v1.md): {% hint style="info" %} - [Groups](groups.md): {% hint style="info" %} - [Guidance for Snyk for .NET](guidance-for-snyk-for-net.md): In the .NET ecosystem, there are multiple levels of dependencies, some of which are obvious and some completely hidde... - [Guidance for Snyk for C/C++](guidance-for-snyk-for-c-c.md): This page reviews considerations about languages and package managers, to help you apply Snyk effectively in your tec... - [Guides to migration](guides-to-migration.md): Snyk is migrating V1 API endpoints to REST, and REST experimental endpoints to GA. The guides in this section explain... - [Guides to webhooks](guides-to-webhooks.md): This section includes the following guides: - [Helm charts](helm-charts.md): You scan a Helm chart by rendering the Helm templates into Kubernetes manifest files and then scanning these using th... - [High availability mode](high-availability-mode.md): Snyk Broker can bring high availability capabilities to both servers and clients, thus increasing the scalability of ... - [How Snyk counts assets](how-does-snyk-count-assets.md): Managed Billable Assets are the resources, assets, and configuration files accessed through or managed by the custome... - [How ignores work for Projects imported using an SCM and the CLI](how-ignores-work-for-projects-imported-using-an-scm-and-the-cli.md): When you ignore an issue, you must consider the following factors: - [How Snyk Container works](how-snyk-container-works.md): As defined by the [Open Container Initiative](https://opencontainers.org) (OCI) specifications, container images comp... - [How the Snyk Controller handles your data](how-snyk-controller-handles-your-data.md): After you install the Snyk Controller in your Kubernetes cluster, it pulls images from your container registries: - [How Snyk handles your data](how-snyk-handles-your-data.md): Snyk is a developer security platform designed to place the utmost importance on data security. This document aims to... - [How Snyk incorporates generative AI into the platform](how-snyk-incorporates-generative-ai-into-the-platform.md): Snyk’s AI Security Platform uses generative AI to enhance automation, efficiency, and innovation for developers and s... - [How TeamCity integration works](how-teamcity-integration-works.md): Use the Snyk plugin with your TeamCity Projects to test and monitor your code for vulnerabilities on an ongoing basis... - [How the Snyk Security Scan task works](how-the-snyk-security-scan-task-works.md): After the Snyk Security Scan task is added to a pipeline, each time the pipeline runs, the Snyk task performs the fol... - [How to add a Snyk pipe](how-to-add-a-snyk-pipe.md): Follow these steps to add a Snyk pipe: - [How to select the Organization to use in the CLI](how-to-select-the-organization-to-use-in-the-cli.md): When you run commands with the CLI such as`snyk monitor`and`snyk test`, Snyk uses your`Preferred Organization`, w... - [How to set environment variables by operating system for IDEs and CLI](how-to-set-environment-variables-by-operating-system-for-ides-and-cli.md): * Can be centrally defined in System Settings and should be set there. - [OAuth 2.0 authentication does not work](how-to-set-environment-variables-by-operating-system-os-for-ides-and-cli-1.md): * Copy the provided URL to the clipboard by clicking the corresponding button. - [How to use Snyk Webhooks to connect Snyk to Slack with AWS Lambda](how-to-use-snyk-webhooks-to-connect-snyk-to-slack-with-aws-lambda.md): You can use Snyk Webhooks alongside a Lambda function to receive and filter new vulnerabilities discovered by Snyk in... - [How to use Snyk Webhooks to integrate New Relic with Snyk](how-to-use-snyk-webhooks-to-integrate-new-relic-with-snyk.md): New Relic Security API is the most recent approach to having New Relic send any type of security-related information ... - [How to use the Terraform Cloud integration for IaC](how-to-use-the-terraform-cloud-integration-for-iac.md): After your integration is set up, Snyk scans Terraform plans for each run triggered in your workspace. - [HTTPS for Broker Client with Docker](https-for-broker-client-with-docker.md): The Broker Client runs an HTTP server by default. It can be configured to run an HTTPS server for local connections. ... - [IaC custom rules within a pipeline](iac-custom-rules-within-a-pipeline.md): Using a CI/CD such as [GitHub Actions](https://github.com/features/actions) is ideal for managing, distributing, and ... - [IaC describe command examples](iac-describe-command-examples.md): For a full list of`snyk iac describe`options, see [`snyk iac describe`](https://docs.snyk.io/developer-tools/snyk-c... - [IaC describe](iac-describe.md): **Note:** This feature is available in Snyk CLI version v1.876.0 or greater. - [IaC exclusions using the command line](iac-exclusions-using-the-command-line.md): When you scan directories or a large collection of IaC files using the Snyk CLI`iac test`command, it is easy to inc... - [IaC ignores using the .snyk policy file](iac-ignores-using-the-snyk-policy-file.md): When you scan IaC configuration files using the Snyk CLI`iac test`command, you can ignore issues that are not relev... - [IAC sources usage](iac-sources-usage.md): At this time, the`snyk iac describe`command supports reading Terraform states as follows: - [IaC test](iac-test.md): `snyk iac test [] []` - [IaC update-exclude-policy](iac-update-exclude-policy.md): `snyk iac update-exclude-policy []` - [IaC](iac.md): `snyk iac [] []` - [IacSettings](iacsettings.md): {% hint style="info" %} - [IDE and CLI usage telemetry](ide-and-cli-usage-telemetry.md): Snyk Language Server collects usage telemetry after each successful test, through the Snyk proprietary Analytics serv... - [IDE plugin scan fails on Windows systems with .exe download blocking](ide-plugin-fails-with-scan-failed-on-windows-systems-with-exe-download-blocking.md): When you are using Snyk plugins in an IDE on Windows systems, the Snyk scan may fail. - [Identity Provider (IdP) migration](identity-provider-idp-migration.md): When migrating from a legacy IdP to a new IdP, you must submit new IdP metadata information to Snyk. - [Ignore issues](ignore-issues.md): You can ignore a vulnerability or open-source license issue if you do not need to fix it and want to avoid seeing the... - [Ignore unmanaged resources](ignore-unmanaged-resources.md): The`.snyk`policy file can be used to exclude unmanaged resources from being detected by`snyk iac describe`. See [t... - [Ignore vulnerabilities using the Snyk CLI](ignore-vulnerabilities-using-the-snyk-cli.md): {% hint style="info" %} - [Ignore](ignore.md): `snyk ignore --id= [--expiry=] [--reason=] [--policy-path=] [--path=... - [Ignores (v1)](ignores-v1.md): {% hint style="info" %} - [Ignoring cloud issues](ignoring-cloud-issues.md): You can ignore a cloud [issue](https://docs.snyk.io/scan-with-snyk/snyk-iac/getting-started-with-cloud-scans/manage-c... - [Image repository, tab, and Image Pull Secret](image-repository-tab-and-image-pull-secret.md): You can choose to use your own container registry and tag instead of the public images by customizing the`values.yam... - [Implement policies](implement-policies.md): All policies that you add to a project help you to better monitor your assets and automate the business context by al... - [Overview](implement-snyk.md): Implementing a developer security tool like Snyk is critical to ensuring the security of your applications, from deve... - [Import log](import-log.md): The Import log feature provides a history of all the Git repositories and container registry images imported into an ... - [Import Project repository](import-project-repository.md): After you select repositories on the Snyk Web UI and click **Add selected repositories**, the import starts, and a pr... - [Import Project with Snyk Code](import-project-with-snyk-code.md): Imported Projects are organized under Target folders on the Projects page, named after the Git repository account and... - [Import Projects (v1)](import-projects-v1.md): {% hint style="info" %} - [Import Projects](import-projects.md): Depending on the integrations you have configured, and the language / package managers in your tech stack, you can im... - [Improved .NET scanning](improved-net-scanning.md): {% hint style="info" %} - [Incident Responder role template](incident-responder-role-template.md): This Organization-level role needs quick access to core functionality in Snyk to find issues of a particular type and... - [Infrastructure as code](infrastructure-as-code.md): For Snyk IaC, you may choose to integrate with [Terraform Cloud](https://docs.snyk.io/developer-tools/snyk-ci-cd-inte... - [Ingress options with Snyk Broker Helm installation](ingress-options-with-snyk-broker-helm-installation.md): When you are setting up the Broker using Helm, you may need to configure the`brokerClientUrl`parameter. This parame... - [Insecure downstream mode](insecure-downstream-mode.md): In some situations, you may need to use only`http`for your downstream connection. These cases are infrequent and us... - [Install and configure Broker using Docker](install-and-configure-broker-using-docker.md): {% hint style="info" %} - [Install and configure Broker using Helm](install-and-configure-broker-using-helm.md): {% hint style="info" %} - [Install and configure Snyk Broker](install-and-configure-snyk-broker.md): Snyk Broker is an open-source tool that acts as a proxy between Snyk and special integrations, providing for access b... - [Install Broker for Container Registry Agent using Helm](install-broker-for-container-registry-agent-using-helm.md): Installing the Broker Container Registry Agent using Docker requires the parameter`CR_AGENT_URL`, but it is not requ... - [Install or update the Snyk CLI](install-or-update-the-snyk-cli.md): You can install or update the [Snyk CLI](https://docs.snyk.io/developer-tools/snyk-cli) using the methods explained o... - [Install or upgrade to version of Node.js required for Snyk CLI](install-or-upgrade-to-version-of-nodejs-required-for-snyk-cli.md): Node.js v12 or higher is required for Snyk CLI version 1.853.0 and higher. Snyk recommends running as recent a versio... - [Install the SDK](install-the-sdk.md): ​Install the SDK using one of these options: - [Install the Snyk Controller on Amazon Elastic Kubernetes Service (Amazon EKS)](install-the-snyk-controller-on-amazon-elastic-kubernetes-service-amazon-eks.md): {% hint style="info" %} - [Install the Snyk Controller with Helm (Azure and Google Cloud Platform)](install-the-snyk-controller-with-helm-azure-and-google-cloud-platform.md): {% hint style="info" %} - [Install the Snyk Controller with OpenShift 4 and OperatorHub](install-the-snyk-controller-with-openshift-4-and-operatorhub.md): The Snyk Controller V2 is currently not available in the OpenShift Marketplace nor available as a community version. - [Install the Snyk Controller](install-the-snyk-controller.md): {% hint style="info" %} - [Install the Snyk extension for your Azure pipelines](install-the-snyk-extension-for-your-azure-pipelines.md): To start using the Snyk task as part of your pipeline build, from the [Visual Studio Marketplace](https://marketplace... - [Installing Snyk CLI as a binary using npm](installing-snyk-cli-as-a-binary-using-npm.md): As a part of the [evolution of the Snyk CLI towards an extensible approach](https://snyk.io/blog/evolving-the-snyk-cl... - [Integrate Snyk into your workflow using the CLI](integrate-snyk-into-your-workflow-using-the-cli.md): This page provides an example of integrating Snyk into your GitHub workflow using the [Snyk CLI](https://docs.snyk.io... - [Integrate with Amazon Elastic Container Registry (ECR)](integrate-with-amazon-elastic-container-registry-ecr.md): Snyk integrates with Amazon Elastic Container Registry (ECR) to enable you to import your Projects and monitor your c... - [Integrate with DigitalOcean](integrate-with-digitalocean.md): Snyk integrates with DigitalOcean to enable you to import your container images and monitor them for vulnerabilities. - [Integrate with Docker Hub](integrate-with-docker-hub.md): Snyk integrates with Docker Hub to enable you to import snapshots of your Projects to the Snyk Web UI and then test a... - [Integrate with GitHub Container registry](integrate-with-github-container-registry.md): Snyk integrates with the GitHub Container registry to enable you to import your container images and monitor them for... - [Integrate with GitLab Container Registry](integrate-with-gitlab-container-registry.md): Snyk integrates with GitLab Container Registry to enable you to import your container images and monitor them for vul... - [Integrate with Google Artifact Registry (GAR)](integrate-with-google-artifact-registry-gar.md): Snyk integrates with [Google Artifact Registry (GAR)](https://cloud.google.com/artifact-registry) so you can monitor ... - [Integrate with Google Container Registry (GCR)](integrate-with-google-container-registry-gcr.md): {% hint style="warning" %} - [Integrate with Harbor Container Registry](integrate-with-harbor-container-registry.md): {% hint style="info" %} - [Integrate with JFrog Artifactory](integrate-with-jfrog-artifactory.md): {% hint style="info" %} - [Integrate with Microsoft Azure Container Registry (ACR)](integrate-with-microsoft-azure-container-registry-acr.md): Snyk integrates with Microsoft Azure Container Registry (ACR) so you can import your Projects and monitor your contai... - [Integrate with Nexus Container Registry](integrate-with-nexus-container-registry.md): {% hint style="info" %} - [Integrate with Quay Container Registry](integrate-with-quay-container-registry.md): Snyk integrates with Quay Container Registry to enable you to import your container images and monitor them for vulne... - [Integrate with self-hosted container registries](integrate-with-self-hosted-container-registries-broker.md): {% hint style="info" %} - [Overview](integrate-with-snyk.md): Agentic workflows transform software development by using AI assistants to automate tasks and write code, boosting pr... - [Integrate with Sysdig](integrate-with-sysdig.md): To enhance its capabilities when detecting workload information, Snyk has partnered with Sysdig. The integration enri... - [Integration Editor/Implementor role template](integration-editor-implementor-role-template.md): This is a Group-level role with integration-related permissions to enable and process the integration of multiple thi... - [Integrations (v1)](integrations-v1.md): {% hint style="info" %} - [Invalid string length error when scanning projects](invalid-string-length-error-when-scanning-projects.md): The invalid string length error can occur in the following situations: - [Invite Users](invite-users.md): Click **Members** and invite your team members, applying the role alignments decided in Phase 1 for each member. - [Invites](invites.md): {% hint style="info" %} - [Issue card information](issue-card-information.md): Issue cards appear on the details page for a Project. You can use available options to do the following: - [Issue columns dictionary](issue-columns-dictionary.md): Snyk reporting includes many filters and columns, allowing users to develop refined views of the data and obtain the ... - [Issue IDs in Snyk APIs](issue-ids-in-snyk-apis.md): The`issueid`in the V1 API is the issue identifier from the Snyk Vulnerability Database, for example, SNYK-JS-LODASH... - [Issues analytics](issues-analytics.md): {% hint style="info" %} - [Issues: List issues for a package](issues-list-issues-for-a-package.md): The Snyk REST API endpoint [List issues for a package](https://docs.snyk.io/reference/issues#orgs-org_id-packages-pur... - [Issues](issues.md): {% hint style="info" %} - [Java and Kotlin](java-and-kotlin.md): {% hint style="info" %} - [Java rules](java-rules.md): Each rule includes the following information. - [JavaScript and TypeScript rules](javascript-and-typescript-rules.md): Each rule includes the following information. - [JavaScript](javascript.md): {% hint style="info" %} - [Jenkins plugin integration with Snyk](jenkins-plugin-integration-with-snyk.md): Snyk offers a native plugin for Jenkins that is based on the [Snyk CLI](https://docs.snyk.io/developer-tools/snyk-cli... - [JetBrains AI assistant](jetbrains-ai-assistant.md): You can access Snyk Studio, including Snyk's MCP server, in JetBrains AI Assistant to secure code generated with agen... - [JetBrains Junie](jetbrains-junie.md): You can access Snyk Studio, including Snyk's MCP server, in JetBrains Junie to secure code generated with agentic wor... - [JetBrains plugin folder trust](jetbrains-plugin-folder-trust.md): Snyk Open Source may automatically execute code on your computer to obtain additional data for analysis. This include... - [JetBrains plugin](jetbrains-plugin.md): Integrating security checks early in your development lifecycle helps you pass security reviews seamlessly and avoid ... - [Jira and Slack integrations](jira-and-slack-integrations.md): This section includes the following documentation of Snyk integrations: - [Jira - environment variables for Snyk Broker](jira-environment-variables-for-snyk-broker.md): The following environment variables are needed to configure the Broker Client for Jira: - [Jira - install and configure using Docker](jira-install-and-configure-using-docker.md): Before installing, review the [prerequisites](https://docs.snyk.io/implementation-and-setup/enterprise-setup/snyk-bro... - [Jira - install and configure using Helm](jira-install-and-configure-using-helm.md): Before installing, review the [prerequisites](https://docs.snyk.io/implementation-and-setup/enterprise-setup/snyk-bro... - [Jira integration for Snyk IaC](jira-integration-for-iac.md): Snyk Infrastructure as Code allows users to raise Jira issues for misconfigurations found in their IaC resources. - [Jira integration](jira-integration.md): {% hint style="info" %} - [Jira - prerequisites and steps to install and configure Broker](jira-prerequisites-and-steps-to-install-and-configure-broker.md): Before installing, review the general instructions for the installation method you plan to use, [Helm](https://docs.s... - [Jira (v1)](jira-v1.md): {% hint style="info" %} - [Key concepts for cloud scans](key-concepts-for-cloud-scans.md): Cloud scans have a number of unique concepts that are different from Snyk core concepts, such as [Environments](#envi... - [Kicking off an import](kicking-off-an-import.md): `snyk-api-import`supports the same Project sources that you can import using the Snyk API: Git repositories, Docker ... - [Kiro guide](kiro-guide.md): You can access Snyk Studio, including Snyk's MCP server, in Kiro to secure code generated with agentic workflows thro... - [Kotlin rules](kotlin-rules.md): Each rule includes the following information. - [Kubernetes and the Snyk Priority Score](kubernetes-and-the-snyk-priority-score.md): {% hint style="info" %} - [Kubernetes files](kubernetes-files.md): With Snyk Infrastructure as Code, you can test your configuration files with the CLI. Snyk Infrastructure as Code for... - [Navigate the Kubernetes integration UI](kubernetes-integration-ui-explained.md): This section provides information on how to view and manage Kubernetes Projects details and scan results, as well as ... - [Kubernetes integration](kubernetes-integration.md): This section provides information on how to integrate Snyk with Kubernetes and how to use Snyk capabilities after the... - [Kubernetes secrets and Helm Chart installation](kubernetes-secrets-and-helm-chart-installation.md): Beginning with version`2.8.0`of the Snyk Broker Helm Chart, external secrets are supported. - [Kubernetes Uploader role template](kubernetes-uploader-role-template.md): This Organization-level role can publish Kubernetes Monitor and Insights Collector data to Snyk and is often tied to ... - [Kustomize files](kustomize-files.md): You can scan a Kustomize template by building the Kubernetes manifest file and then scanning it using the Snyk CLI`i... - [Language support for Bitbucket Pipelines integration](language-support-for-bitbucket-pipelines-integration.md): Snyk integration with Bitbucket pipes is supported for the following languages: - [Language support for TeamCity integration](language-support-for-teamcity-integration.md): Snyk supports all TeamCity projects regardless of which Git repo is used. - [Learn](learn.md): {% hint style="info" %} - [Legacy custom mapping](legacy-custom-mapping.md): To configure this option, send the`roles`array within the SAML attributes or OIDC claims to adhere to **one** of th... - [Legacy reports dependencies tab](legacy-reports-dependencies-tab.md): The **Dependencies** tab acts as a Bill Of Materials (BOM) for all the direct dependencies in all of the Projects in ... - [Legacy reports general actions](legacy-reports-general-actions.md): This section describes the actions you can perform on all Reports tabs. - [Legacy reports issues tab](legacy-reports-issues-tab.md): The **Issues** tab displays all known vulnerability and license discrepancies across your Organization, indicating de... - [Legacy reports licenses tab](legacy-reports-licenses-tab.md): The **Licenses** area displays all licenses currently used in your Project, a summary of all dependencies in your Pro... - [Legacy reports overview](legacy-reports-overview.md): The legacy **Reports** area in the Web UI offers data and analytics about Projects, issues, dependencies, and license... - [Legacy reports summary tab](legacy-reports-summary-tab.md): The main dashboard of the **Reports** area displays a birds-eye view of all of the issues (vulnerabilities and licens... - [Legacy reports](legacy-reports.md): {% hint style="info" %} - [Legacy Success Offerings](legacy-success-offerings.md): The following terms apply to legacy support and success offerings that have reached their end-of-sale date and are no... - [Legal Advisor role template](legal-advisor-role-template.md): This Organization-level role can manage security and license policies for the Group and view and export reports, but ... - [License policies](license-policies.md): Group administrators can set license policies to define Snyk behavior for handling license issues. For example, you c... - [License policy results](license-policy-results.md): A newly assigned policy, or modifications to a policy, will apply after the next scheduled test runs for all of the l... - [Licenses (v1)](licenses-v1.md): {% hint style="info" %} - [List all Projects V1 API to REST API migration guide (completed migration)](list-all-projects-v1-api-to-rest-api-migration-guide-completed-migration.md): {% hint style="warning" %} - [List and review the Universal Broker configuration resources](list-and-review-the-universal-broker-configuration-resources.md): The`snyk-broker-config`CLI tool provides resources to guide you in configuring your Universal Broker. The following... - [Log4shell command use](log4shell-command-use.md): `snyk log4shell`is a Snyk CLI command, that helps find traces of the **log4j** library that are affected by the **Lo... - [Log4shell](log4shell.md): `snyk log4shell` - [Malicious packages](malicious-packages.md): Malicious packages are a popular and growing method of carrying out software supply chain attacks. This page explains... - [Manage App details](manage-app-details.md): To view a list of Snyk Apps owned by your Snyk Organization, send a`GET`request to the`apps/creations`endpoint: - [Overview](manage-assets.md): Snyk defines an asset as an identifiable entity that is part of an application and relevant to security and developer... - [Manage cloud environments](manage-cloud-environments.md): This section provides information on how to work with Snyk environments. Environments are used onboard cloud provider... - [Manage cloud issues](manage-cloud-issues.md): When Snyk scans a cloud environment, it tests infrastructure configurations against a comprehensive set of security r... - [Manage code vulnerabilities](manage-code-vulnerabilities.md): Before managing vulnerabilities with Snyk Code, ensure the following: - [Manage notifications](manage-notifications.md): Snyk notifies you automatically when new issues are found in the Projects you are monitoring to alert you to new poss... - [Overview](manage-risk.md): Snyk has several features to help you manage Application Security (AppSec) risk. - [Manage service accounts using the Snyk API](manage-service-accounts-using-the-snyk-api.md): You can manage service accounts using the [Snyk REST API](https://docs.snyk.io/snyk-api/reference/serviceaccounts). - [Manage users in a Group](manage-users-in-a-group.md): {% hint style="info" %} - [Manage users in a Tenant](manage-users-in-a-tenant.md): {% hint style="info" %} - [Manage users in Organizations](manage-users-in-organizations.md): In the **Organization** where you want to manage users, select the **Members** menu option. - [Manage vulnerabilities](manage-vulnerabilities.md): The documentation in this section explains how to fix vulnerabilities and license issues in your Projects. - [Manually import Kubernetes workload Projects](manually-import-kubernetes-workload-projects.md): Using the same integration ID, you can import multiple clusters to one Snyk Organization by giving clusters a unique ... - [Maven plugin integration with Snyk](maven-plugin-integration-with-snyk.md): Snyk offers a [Maven plugin](https://github.com/snyk/snyk-maven-plugin) based on the [Snyk CLI](https://docs.snyk.io/... - [Maven scans with private repositories](maven-scans-with-private-repositories.md): Maven fails due to dependencies that reference private repositories in Ithe IDE plugin or CI/CD pipeline. - [Maximum number of Projects in an Organization](maximum-number-of-projects-in-an-organization.md): The number of Projects you can have in a single Snyk Organization depends on your Snyk [pricing plan](https://snyk.io... - [Migrating to Bitbucket Pipelines v1.0.0](migrating-to-bitbucket-pipelines-v100.md): When you are upgrading from < 1.0.0 to 1.0.0+, make the following changes in your configuration: - [Mirroring Bitbucket Cloud organizations and repos in Snyk](mirroring-bitbucket-cloud-organizations-and-repos-in-snyk.md): You can use four commands in the available utils to import the entirety of Bitbucket Cloud repos into Snyk. You must ... - [Mirroring Bitbucket Server organizations and repos in Snyk](mirroring-bitbucket-server-organizations-and-repos-in-snyk.md): You can use four commands in the available utils to import the entirety of Bitbucket Server repos into Snyk. You must... - [Mirroring GitHub.com and GitHub Enterprise organizations and repos in Snyk](mirroring-githubcom-and-github-enterprise-organizations-and-repos-in-snyk.md): You can use four commands in the available utilities to import the entirety of GitHub and GitHub Enterprise repositor... - [Mirroring GitLab organizations and repos in Snyk](mirroring-gitlab-organizations-and-repos-in-snyk.md): You can use four commands in the available utils to import the entirety of GitLab repos into Snyk. You must configure... - [Misconfiguration scanning results (Snyk Infrastructure as Code)](misconfiguration-scanning-results-snyk-infrastructure-as-code.md): In the Eclipse plugin version 2.0.0 and later, Snyk has enhanced integrations with the native flows of Eclipse: inlin... - [Missing or differing results in Snyk Code](missing-or-differing-results-in-snyk-code.md): * Rename all`.gitignore`and`.dcignore`files to, for example,`.dcignore.bak.` - [Modify the Lambda function](modify-the-lambda-function.md): 1. Open your Lambda function and click on **Configuration**. - [Monitor (v1)](monitor-v1.md): {% hint style="info" %} - [Monitor your Projects at regular intervals](monitor-your-projects-at-regular-intervals.md): By using the`test`command and the`@snyk/protect`[package](https://github.com/snyk/snyk/tree/master/packages/snyk-... - [Monitor](monitor.md): `snyk monitor []` - [Most recent version of the CLI that supports Node.js 4](most-recent-version-of-the-cli-that-supports-nodejs-4.md): The last version of the Snyk CLI that supported node 4 is 1.143.6. You can install it by running`npm i -g snyk@1.143... - [Mounting secrets with Docker](mounting-secrets-with-docker.md): Sometimes it is required to load sensitive configurations, the GitHub or Snyk token, from a file instead of from envi... - [Multi-tenant settings for Helm chart installation](multi-tenant-settings-for-helm-chart-installation.md): To use the Helm chart in different multi-tenant regions, set the`brokerServerUrl`for the region you are using. - [Name your Organization](name-your-organization.md): Organizations contain your scan, setup integrations, and view results. - [Net new issues (delta) scan troubleshooting](net-new-issues-delta-scan-troubleshooting.md): **Net new issues scans fail to find issues on npm-based reference scans.** - [New Relic Curated UI and Snyk Custom Dashboard](new-relic-curated-ui-and-snyk-custom-dashboard.md): Once the Azure Function and the Snyk Webhook are created, you see data coming in for Snyk projects with the configure... - [Nexus Repository - environment variables for Snyk Broker](nexus-repository-environment-variables-for-snyk-broker.md): The following environment variables are needed to customize the Broker client for Nexus 3: - [Nexus Repository - install and configure using Docker](nexus-repository-install-and-configure-using-docker.md): {% hint style="info" %} - [Nexus Repository - install and configure using Helm](nexus-repository-install-and-configure-using-helm.md): {% hint style="info" %} - [Nexus repository manager connection setup](nexus-repository-manager-connection-setup.md): {% hint style="info" %} - [Nexus repository manager for Maven](nexus-repository-manager-for-maven.md): {% hint style="info" %} - [Nexus repository manager for npm](nexus-repository-manager-for-npm.md): {% hint style="info" %} - [Nexus Repository - prerequisites and steps to install and configure Broker](nexus-repository-prerequisites-and-steps-to-install-and-configure-broker.md): {% hint style="info" %} - [Notification policy](notification-policy.md): You can use the **Send Email** and **Send Slack Message** actions to notify you about changes that take place on your... - [Notifying the team](notifying-the-team.md): Snyk can automatically notify you when new issues are found in imported Projects. By default, email notifications are... - [npm Teams and npm Enterprise integration](npm-teams-and-npm-enterprise-integration.md): {% hint style="info" %} - [OAuth2 API](oauth2-api.md): Snyk provides an OAuth2 API, primarily for use with [Snyk Apps](https://docs.snyk.io/snyk-api/using-specific-snyk-api... - [Objective-C rules](objective-c-rules.md): {% hint style="info" %} - [Obtain the tokens required to set up Snyk Broker](obtain-the-tokens-required-to-set-up-snyk-broker.md): {% hint style="info" %} - [Okta SAML application setup](okta-saml-application-setup.md): This example shows setting up an Okta SAML application and connecting this to Snyk to facilitate SSO. To configure yo... - [OneLogin SAML Application setup](onelogin-saml-application-setup.md): This example shows setting up a SAML application in OneLogin and connecting this to Snyk to facilitate SSO. To config... - [Open-source license compliance](open-source-license-compliance.md): Every time you test your code in the Snyk web UI, the [Snyk CLI](https://docs.snyk.io/developer-tools/snyk-cli), or u... - [Open Source Projects that must be built before testing with the Snyk CLI](open-source-projects-that-must-be-built-before-testing-with-the-snyk-cli.md): For some types of Open Source Projects, you must build the Project before testing it with the [Snyk CLI.](https://doc... - [Opening fix and upgrade pull requests from a fixed GitHub account](opening-fix-and-upgrade-pull-requests-from-a-fixed-github-account.md): You can set a specific GitHub account to open, fix, and upgrade PRs, rather than use a GitHub user account picked ran... - [OpenSourceSettings](opensourcesettings.md): {% hint style="info" %} - [Operating system distributions supported by Snyk Container](operating-system-distributions-supported-by-snyk-container.md): Snyk detects vulnerabilities in images based on operating systems listed on this page along with the specific version... - [Optional installation steps for the Snyk Controller with Helm](optional-installation-steps-for-snyk-controller-with-helm.md): The installation steps depend on how you want to configure the Snyk Controller to fit your environment. Follow the ap... - [Organization and Group identification for Projects using the API](organization-and-group-identification-for-projects-using-the-api.md): Using the API, you can do the following: - [Organization general settings](organization-general-settings.md): To view and modify settings for your Organization, be sure you are in your Organization and navigate to **Settings** ... - [Organization-level integrations](organization-level-integrations.md): Snyk provides seamless integrations with various source control management systems such as GitHub, GitLab, Bitbucket,... - [Organization reports](organization-reports.md): {% hint style="info" %} - [Organizations (v1)](organizations-v1.md): {% hint style="info" %} - [Organizations](organizations.md): Organizations represent business areas such as teams, products, or environments. An Organization contains [Snyk Proje... - [Orgs](orgs.md): {% hint style="info" %} - [Output](output.md): The Summary section appears at both the beginning and end of the output, for example: - [Overview of Kubernetes integration](overview-of-kubernetes-integration.md): {% hint style="info" %} - [Overview](overview.md): You can run Snyk locally, in repositories, and in pipelines to scan your code. Select the integration that matches yo... - [Package repository integrations](package-repository-integrations.md): This section provides documentation for the following integrations: - [Package Version](package-version.md): {% hint style="info" %} - [Package](package.md): {% hint style="info" %} - [Parameters for troubleshooting and providing your own certificate with Helm](parameters-for-troubleshooting-and-providing-your-own-certificate-with-helm.md): To troubleshoot SSL inspection issues, you can set the`tlsRejectUnauthorized`parameter to`disable`. - [Parsing an input file](parsing-an-input-file.md): It can be difficult to understand the internal representation of your input files as you write your Rego code. As you... - [Partner integrations](partner-integrations.md): Explore our 17 integration categories for Snyk Partner solutions below. Click on a category to view specific partner ... - [Phase 1: Discovery and planning](phase-1-discovery-and-planning.md): * [Validate your Snyk plan](https://docs.snyk.io/implementation-and-setup/team-implementation-guide/phase-1-discovery... - [Phase 2: Configure account](phase-2-configure-account.md): After you finish [Phase 1: Discovery and planning](https://docs.snyk.io/implementation-and-setup/enterprise-implement... - [Phase 2: Configure your Organization](phase-2-configure-your-organization.md): This step is easiest performed prior to purchasing the license. If you did not, Snyk support can assist you. - [Phase 3: Gain visibility](phase-3-gain-visibility.md): After the [Account configuration](https://docs.snyk.io/implementation-and-setup/team-implementation-guide/phase-2-con... - [Phase 4: Create a fix strategy](phase-4-create-a-fix-strategy.md): After setting up your integrations, creating your Organization, and importing your Projects, you now have visibility ... - [Phase 5: Initial rollout to team](phase-5-initial-rollout-to-team.md): After the initial import of Projects and potentially triaging the initial results, you can invite your initial stakeh... - [Phase 5: Rolling out the prevention stage](phase-5-rolling-out-the-prevention-stage.md): After you gain visibility on your security issues, you can now start to implement a prevention/gating system, to stop... - [Phase 6: Rolling out the prevention stage](phase-6-rolling-out-the-prevention-stage.md): After you gain visibility for your business-wide security issues, you can start to implement a prevention and gating ... - [Phase 6: triages, ignores and fixes](phase-6-triages-ignores-and-fixes.md): After you implement a strategy to prevent new issues from entering your repositories, whether blocking builds or runn... - [Phase 7: Triages, ignores, and fixes](phase-7-triages-ignores-and-fixes.md): After you implement a strategy to prevent new issues from entering your repositories, whether blocking builds or runn... - [PHP rules](php-rules.md): Each rule includes the following information. - [PHP](php.md): {% hint style="info" %} - [Ping Identity setup](ping-identity-setup.md): This page explains how to set up a Ping Identity Application and connect it to Snyk to facilitate SSO. - [Plan for success](plan-for-success.md): Implementing Snyk provides an opportunity to enhance your application security. But how do you know if you're getting... - [Plan Organization structure](plan-organization-structure.md): Snyk uses a hierarchical approach to managing assets, access, and rollup reporting. - [Policies](policies.md): {% hint style="info" %} - [Policy](policy.md): `snyk policy [] []` - [Pre-defined roles](pre-defined-roles.md): {% hint style="info" %} - [Preflight checks for Snyk Broker](preflight-checks-for-snyk-broker.md): The main objective of preflight checks is to catch errors and misconfigurations early, on Broker Client startup, rath... - [Prepare Snyk Broker for deployment](prepare-snyk-broker-for-deployment.md): {% hint style="info" %} - [Preparing for creating Universal Broker deployments](preparing-for-creating-universal-broker-deployments.md): Before creating deployments, ensure you have met the [prerequisites](https://docs.snyk.io/implementation-and-setup/en... - [Prerequisites for Bitbucket Pipelines integration](prerequisites-for-bitbucket-pipelines-integration.md): The following are prerequisites for Bitbucket Pipelines integration: - [Prerequisites for CLI and Jenkins plugin on Alpine Linux operating system](prerequisites-for-cli-and-jenkins-plugin-on-alpine-linux-operating-system.md): Before running Snyk CLI and Snyk Jenkins plugin on the Alpine Linux operating system, follow these steps to establish... - [Prerequisites for Snyk Apps](prerequisites-for-snyk-apps.md): To create a Snyk App, you must have access to the Snyk API. To get started, follow the instructions to [authenticate ... - [Prerequisites for Universal Broker](prerequisites-for-universal-broker.md): {% hint style="info" %} - [Prerequisites: project plan templates](prerequisites-project-plan-templates.md): The templates provided below are the basis of the following sections of this guide.\ - [Prerequisites](prerequisites.md): Provisioning is the first interaction you have with Snyk before getting access to the Snyk platform and features on y... - [Prioritization for Snyk Essentials](prioritization-for-snyk-essentials.md): Snyk uses holistic application intelligence to help you better identify and prioritize your Container, Code, and Open... - [Prioritize issues for fixing](prioritize-issues-for-fixing.md): You can find prioritization within Snyk under several names and with different customizations depending on your Snyk ... - [Priority Score vs Risk Score](priority-score-vs-risk-score.md): The Snyk Risk score and Priority score are keys to security management. Both types of score help Organizations handle... - [Priority Score](priority-score.md): The Snyk Priority Score is a single value assigned to an issue, to help you quickly and easily decide which issues ar... - [Private gem sources for Ruby configuration](private-gem-sources-for-ruby-configuration.md): {% hint style="info" %} - [Program reporting](program-reporting.md): {% hint style="info" %} - [Project attributes](project-attributes.md): Project attributes are static and non-configurable fields that allow you to apply attribute values to a Project by se... - [Project collections groupings](project-collections-groupings.md): {% hint style="info" %} - [Project collections](project-collections.md): On this page you will find information about how to create and use Project collections: - [Project information](project-information.md): The **Projects** page lists imported Projects and information about the Projects, such as vulnerabilities and license... - [Project issue paths API endpoints](project-issue-paths-api-endpoints.md): The following provides information in addition to the information in the API Reference for the endpoints [List all pr... - [Project tags](project-tags.md): {% hint style="info" %} - [Project type responses from the API](project-type-responses-from-the-api.md): The Snyk Project type, defined in the V1 API only as`the package manager of the project`, is returned from the [API ... - [Project views](project-views.md): On this page you will find information about how to create and use Project views: - [Projects (v1)](projects-v1.md): {% hint style="info" %} - [Projects](projects.md): {% hint style="info" %} - [Provision users to Organizations using the API](provision-users-to-organizations-using-the-api.md): The Provision user endpoints allow you to organize and grant permissions to your single sign-on users before the user... - [Proxy configuration for Snyk CLI](proxy-configuration-for-snyk-cli.md): When you use the Snyk CLI behind a proxy, you must provide the proxy configuration by using the following environment... - [Proxy settings for Broker Helm chart installation](proxy-settings-for-broker-helm-chart-installation.md): To use the Helm chart behind a proxy, set the`httpProxy`and`httpsProxy`values. - [Proxy support with Docker](proxy-support-with-docker.md): For proxy configuration, see [Configure Docker to use a proxy server](https://docs.docker.com/network/proxy/). - [Pull Request checks](pull-request-checks.md): The [Snyk PR Checks](https://docs.snyk.io/scan-with-snyk/pull-requests/pull-request-checks/configure-pull-request-che... - [Pull Request experience](pull-request-experience.md): {% hint style="info" %} - [Pull Request Templates](pull-request-templates.md): {% hint style="info" %} - [Pull Requests](pull-requests.md): Fix pull or merge requests are created automatically by Snyk when new issues are identified in Project tests or a ret... - [Pushing a bundle](pushing-a-bundle.md): Optionally, once you have generated your custom rules bundle, you can distribute it automatically to one of our suppo... - [Python code to extract issues from Snyk API](python-code-to-extract-issues-from-snyk-api.md): Snyk has an unsupported Python client that can be used to get issues using the V1 API: < - [Python rules](python-rules.md): Each rule includes the following information. - [Python](python.md): {% hint style="info" %} - [Qodo guide](qodo-guide.md): You can access Snyk Studio, including Snyk's MCP server, in Qodo to secure code generated with agentic workflows thro... - [Quick setup](quick-setup.md): Snyk Apps uses the Authorization code with the Proof Key for Code Exchange (PKCE) OAuth2 flow. The key endpoints are: - [Quickstart guides](quickstart-guides-for-snyk-studio.md): This section lists quickstart guides for common AI agents. Snyk supports any AI agent and ADE that integrates with a ... - [Reachability analysis](reachability-analysis.md): {% hint style="info" %} - [Read-only CLI Tester role template](read-only-cli-tester-role-template.md): This Organization-level role blocks the use of`snyk monitor`. - [Homepage](readme.md): Check out the latest [updates in the Snyk user documentation](https://docs.snyk.io/discover-snyk/whats-new). - [Redesigned Analytics](redesigned-analytics.md): {% hint style="info" %} - [Redteam](redteam.md): **Note**: Redteam is an experimental feature and is subject to breaking changes without notice. The feature is also r... - [Reference](reference.md): V1 API OpenAPI specification - [Regional API endpoints](regional-api-endpoints.md): By default, the task uses the endpoint. To configure Snyk to use a different endpoint set a`SN... - [Regional hosting and data residency](regional-hosting-and-data-residency.md): {% hint style="info" %} - [Register the App and configure user authorization](register-the-app-and-configure-user-authorization.md): In the previous sections of this tutorial, we set up our TypeScript project, added an Express server, and configured ... - [Release and support policy for Snyk IDE plugins](release-and-support-policy-for-snyk-ide-plugins.md): This page details the release policy for Snyk IDE plugins. - [Releases and channels for the Snyk CLI](releases-and-channels-for-the-snyk-cli.md): This page describes Snyk CLI releases and support policy, and also explains how to opt in to different channels and t... - [Remediator role template](remediator-role-template.md): This is an Organization-level role, meaning a Remediator can only view certain areas and functions in Snyk and cannot... - [Remove a cloud environment](remove-a-cloud-environment.md): When you remove an environment, Snyk removes all associated scans, issues, and records of resources. For cloud enviro... - [Remove imported repository from a Project](remove-imported-repository-from-a-project.md): If you do not want Snyk to continue testing one or more of your imported repositories, you can do one of the following: - [Remove members from Groups and Orgs using the API](remove-members-from-groups-and-orgs-using-the-api.md): To remove members from Groups and Organizations programmatically from user accounts, you can use the API as explained... - [Render content for users](render-content-for-users.md): In the previous module, we covered registering our Snyk App, setting up the authorization flow, and handling user aut... - [Reporting and BI integrations: Snowflake Data Share](reporting-and-bi-integrations-snowflake-data-share.md): With the new Snowflake Data Share integration, your data science, BI and AppSec teams can securely access the underly... - [Reporting API (v1)](reporting-api-v1.md): {% hint style="info" %} - [Reporting security issues](reporting-security-issues.md): Snyk requests that vulnerabilities in a Snyk service be reported according to the process explained on this page. - [Reporting](reporting.md): {% hint style="info" %} - [Requests for access to an Organization](requests-for-access-to-an-organization.md): Users who are not members of a Snyk Organization can request access. - [Test an SBOM document for vulnerabilities](rest-api-endpoint-test-an-sbom-document-for-vulnerabilities.md): {% hint style="info" %} - [Get a Project’s SBOM document](rest-api-get-a-projects-sbom-document.md): {% hint style="info" %} - [REST API](rest-api.md): This section provides an [introduction to the REST API](https://docs.snyk.io/snyk-api/rest-api/about-the-rest-api) an... - [REST Issues experimental API to GA API migration guide](rest-issues-experimental-api-to-ga-api-migration-guide.md): {% hint style="info" %} - [Restart your Broker for a new environment variable](restart-your-broker-for-a-new-environment-variable.md): If you change an environment variable, you must restart your Broker, except in Kubernetes deployments. - [Retrieve audit logs of user-initiated activity by API for an Org or Group](retrieve-audit-logs-of-user-initiated-activity-by-api-for-an-org-or-group.md): {% hint style="info" %} - [Retrieve the App Org IDs](retrieve-the-app-org-ids.md): Users may connect with a single Organization or a single Group. Most of the Snyk API endpoints require an`orgid`in ... - [Review the Snyk Open Source CLI results](review-the-snyk-open-source-cli-results.md): After you run the`snyk test`command in the CLI, the Snyk Open Source test results are displayed. The report of resu... - [Revoke and regenerate a Snyk API token](revoke-and-regenerate-a-snyk-api-token.md): {% hint style="warning" %} - [Revoke compromised refresh tokens](revoke-compromised-refresh-tokens.md): If you believe that a refresh token has been compromised then it is recommended that you revoke that token as soon as... - [Risk factor: deployed](risk-factor-deployed.md): Any deployed code increases the risk of exploitation of your application and business. - [Risk factor: OS condition](risk-factor-os-condition.md): Some vulnerabilities have specific constraints that must be met for the problem to be exploitable. One such constrain... - [Risk factor: public facing](risk-factor-public-facing.md): Knowing that code is deployed tells you that there is a possibility that someone can exploit a flaw you are concerned... - [Risk Score](risk-score.md): {% hint style="info" %} - [Ruby rules](ruby-rules.md): Each rule includes the following information. - [Ruby](ruby.md): {% hint style="info" %} - [Run an analysis with the JetBrains plugin](run-an-analysis-with-the-jetbrains-plugin.md): {% hint style="info" %} - [Run an analysis with Visual Studio Code extension](run-an-analysis-with-visual-studio-code-extension.md): {% hint style="info" %} - [Run an analysis with Visual Studio extension](run-an-analysis-with-visual-studio-extension.md): Open your solution and click **Run scan**. Depending on the size of your solution and the time needed to build a depe... - [Running your Universal Broker client](running-your-universal-broker-client.md): Run your Broker deployment on your container engine or Kubernetes cluster. - [Rust rules](rust-rules.md): {% hint style="info" %} - [Rust](rust.md): {% hint style="info" %} - [SAST scanning results (SAST, Snyk Code)](sast-scanning-results-sast-snyk-code.md): In the Eclipse plugin version 2.0.0 and later, Snyk has enhanced integrations with the native flows of Eclipse: inlin... - [SastSettings](sastsettings.md): {% hint style="info" %} - [SBOM APIs](sbom-apis.md): Information about how to use the following API endpoints is provided: - [SBOM test](sbom-test.md): **Feature availability:** This feature is available to customers on Snyk Enterprise plans. - [SBOM](sbom.md): **Feature availability:** This feature is available only to customers on Snyk Enterprise plans. - [Scala rules](scala-rules.md): Each rule includes the following information. - [Scala](scala.md): {% hint style="info" %} - [Scan a cloud environment](scan-a-cloud-environment.md): Snyk automatically runs a scan when a [cloud environment](https://docs.snyk.io/scan-with-snyk/snyk-iac/key-concepts-f... - [Scan all unmanaged JAR files](scan-all-unmanaged-jar-files.md): The Snyk CLI can scan unmanaged JAR files in [Java applications](https://docs.snyk.io/supported-languages/supported-l... - [Scan and fix security issues in Helm Charts](scan-and-fix-security-issues-in-helm-charts-current-iac.md): In addition to scanning Kubernetes configuration files for misconfigurations and security issues, Snyk has support fo... - [Scan and fix security issues in Kubernetes configuration files](scan-and-fix-security-issues-in-kubernetes-configuration-files-current-iac.md): Snyk Infrastructure as Code scans your manifest files for security vulnerabilities and scans your Kubernetes configur... - [Scan and fix security issues in Terraform files](scan-and-fix-security-issues-in-terraform-files-current-iac.md): Snyk scans your Terraform code for misconfigurations and security issues as well. After scanning configuration files,... - [Scan and fix security issues in your CloudFormation files](scan-and-fix-security-issues-in-your-cloudformation-files-current-iac.md): Snyk scans CloudFormation code for misconfigurations and security issues. After configuration files are scanned, Snyk... - [Scan and maintain Projects using the CLI](scan-and-maintain-projects-using-the-cli.md): This group of pages provides detailed "how-to" information for the Snyk CLI. - [Scan and monitor images](scan-and-monitor-images.md): It is common to use both`test`and`monitor`commands with Snyk Container. You can use the`snyk container test`com... - [Scan ARM configuration files](scan-arm-configuration-files.md): Snyk IaC currently supports scanning ARM configurations with the CLI only. - [Scan CloudFormation files](scan-cloudformation-files.md): The following information is provided to help you scan CloudFormation files: - [Scan container images](scan-container-images.md): Snyk Container helps you find and fix vulnerabilities in container images, based on container registry scans. - [Scan Kubernetes configuration files](scan-kubernetes-configuration-files.md): * [Configure integration to find security issues in Kubernetes configuration files](https://docs.snyk.io/scan-with-sn... - [Scan open-source libraries and licenses](scan-open-source-libraries-and-licenses.md): You can scan your open-source libraries using Snyk Open Source: - [Scan Serverless files](scan-serverless-files.md): Snyk IaC supports the scanning of Serverless configuration files only through the CLI. - [Scan source code with Snyk Code using the CLI](scan-source-code-with-snyk-code-using-the-cli.md): When you test your repository source code using the Snyk CLI, you can: - [Scan Terraform files](scan-terraform-files.md): The following information is provided to help you scan Terraform files: - [Scan your Dockerfile](scan-your-dockerfile.md): Snyk Container allows you to analyze your Dockerfile and scan base images from the Dockerfile. - [Scan your IaC source code](scan-your-iac-source-code.md): Using Snyk IaC, you can: - [Scenarios for using the Snyk API](scenarios-for-using-the-snyk-api.md): The Snyk API scenarios identify procedures you can use to accomplish tasks with Snyk applications using the API. The ... - [SCM integration support for Python](scm-integrations-and-python.md): {% hint style="warning" %} - [SCM integrations and Snyk Broker](scm-integrations-and-snyk-broker.md): If your SCM instance is not publicly accessible, you need Snyk Broker. You can install and configure your Snyk Broker... - [SCM integrations for JavaScript](scm-integrations-for-javascript.md): You can import JavaScript repositories from any SCM integration supported by Snyk. See [Organization level integratio... - [SCMs](scm-integrations.md): Snyk supports SCM integrations that allow you to implement security at each point in your workflow: importing a Proje... - [Scopes to request](scopes-to-request.md): Scopes define the permissions your Snyk App has to perform actions in a user’s account. When a user authorizes your S... - [Scripts for SCM contributors count](scripts-for-scm-contributors-count.md): The following scripts are provided: - [SDK reference](sdk-reference.md): `snyk-iac-rules`- SDK to write, debug, test, and bundle custom rules for Snyk IaC - [Search Audit Logs (Group and Org) v1 API to GA REST Audit logs API migration guide](search-audit-logs-group-and-org-v1-api-to-ga-rest-audit-logs-api-migration-guide.md): Based on OpenAPI specifications, the Snyk REST API is designed to provide a consistent, friendly, and easy-to-use API... - [Securing data at rest](securing-data-at-rest.md): The Snyk CLI stores its configuration in a JSON file in the local file system in a user-related path. Because the con... - [Security concept of operations for Snyk](security-concept-of-operations-for-snyk.md): A security concept of operations can be defined as providing a security-focused description of an information system.... - [Security policy conditions](security-policies-conditions.md): A condition is a variable on which to set a rule. - [Security policies](security-policies.md): Group administrators can define Open Source and Container security policies, providing an automated way to identify c... - [Security policy actions](security-policy-actions.md): An action defines what you want to happen when the [security policy conditions](https://docs.snyk.io/manage-risk/poli... - [Security policy results](security-policy-results.md): A newly-assigned policy, or changes to a policy, apply when the Project is re-scanned. This is what Project collabora... - [Server returned HTTP response code 403 for URL](server-returned-http-response-code-403-for-url.md): Check the endpoint URL and the authentication information. - [Serverless files](serverless-files.md): With Snyk Infrastructure as Code, you can test your configuration files using the CLI. - [Service accounts for Helm Chart installation](service-accounts-for-helm-chart-installation.md): To use an existing service account, add the following parameters to the install command: - [Service accounts using OAuth 2.0](service-accounts-using-oauth-20.md): {% hint style="info" %} - [Service accounts](service-accounts.md): {% hint style="info" %} - [ServiceAccounts](serviceaccounts.md): {% hint style="info" %} - [Severity thresholds for CLI tests](set-severity-thresholds-for-cli-tests.md): To improve control over your tests, you can use the`--severity-threshold`option for the`snyk test`command with on... - [Set the Snyk Organization for CLI tests](set-the-snyk-organization-for-the-cli-tests.md): If you have several Organizations in your Snyk account, before you test your code using the CLI, specify which Snyk O... - [Set up a Snyk App using the OAuth2 API](set-up-a-snyk-app-using-the-oauth2-api.md): The following pages explain how to: - [Set up Insights: associating Snyk Open Source, Code, and Container Projects](set-up-insights-associating-snyk-open-source-code-and-container-projects.md): After you have set up insights, Snyk can set up the required linking for the chosen application. - [Set up Insights: image scanning](set-up-insights-image-scanning.md): To determine the risk factors and prioritize your Code, Open Source, and Container issues, you must scan your contain... - [Set up Insights: Kubernetes connector](set-up-insights-kubernetes-connector.md): One of the goals is to identify risk factors for workloads that are publicly accessible through a network configurati... - [Set up Insights: user permissions](set-up-insights-user-permissions.md): Set up Insights is available at the Group level, so [grant relevant users the Group viewer or the Organization Collab... - [Set up Insights](set-up-insights.md): Customize prioritization using the Set up Insights option and an application that scans images using [Snyk Container]... - [Set up Asset Policies](set-up-snyk-apprisk-policies.md): The [asset policies](https://docs.snyk.io/manage-risk/policies/assets-policies), which come with Snyk Essentials, hel... - [Set up Snyk Single Sign-On (SSO)](set-up-snyk-single-sign-on-sso.md): Set up Single Sign-On (SSO) to allow your developers and teams easy access to Snyk through your existing SSO provider. - [Set up the authorization code exchange](set-up-the-authorization-code-exchange.md): After you receive an authorization **code**, you must exchange it for an access token. - [Set up the refresh token exchange](set-up-the-refresh-token-exchange.md): As the`access_token`will expire in a short time, the App will need to frequently request a new one using the`refre... - [Set up the Snyk webhook](set-up-the-snyk-webhook.md): Create the Snyk Webhook using the [Create a webhook API](https://docs.snyk.io/reference/webhooks-v1#org-orgid-webhooks). - [Set up the Terraform Cloud integration for IaC](set-up-the-terraform-cloud-integration-for-iac.md): {% hint style="warning" %} - [Set up to authorize users](set-up-to-authorize-users.md): When users connect their Snyk account to your App, they must authorize access to their chosen Organization or Group a... - [Set visibility and configure an Organization template](set-visibility-and-configure-an-organization-template.md): Whether you want to create a single Organization or build a template to create multiple Organizations, there are some... - [Set your preferred Organization](set-your-preferred-organization.md): If you have several Organizations, one of these Organizations is set by default as your **Preferred Organization** in... - [Setting up and integrating your Universal Broker connections](setting-up-and-integrating-your-universal-broker-connections.md): The following diagram illustrates installing the Snyk Broker App, which facilitates the secure connection and communi... - [Setting up the Container Registry Agent for a brokered ECR integration](setting-up-the-container-registry-agent-for-a-brokered-ecr-integration.md): In Elastic Container Registries the brokered communication is the same as in other container registries. However, ECR... - [Setup.py file failing to scan or finding zero dependencies](setuppy-file-failing-to-scan-or-finding-zero-dependencies.md): When you run the command`snyk test --file=setup.py`, typically there are some Python`setup.py`projects that fail o... - [Severity levels of detected Linux vulnerabilities](severity-levels-of-detected-linux-vulnerabilities.md): When determining the [severity level](https://docs.snyk.io/manage-risk/prioritize-issues-for-fixing/severity-levels) ... - [Severity levels](severity-levels.md): Use severity levels to help you with [vulnerability assessment](https://snyk.io/learn/vulnerability-assessment/) for ... - [Share CLI results with the Snyk Web UI](share-cli-results-with-the-snyk-web-ui.md): You can use the [CLI](https://docs.snyk.io/developer-tools/snyk-cli)`snyk iac test`command to address known configu... - [Simple example of a Snyk task to run a code test](simple-example-of-a-snyk-task-to-run-a-code-test.md): The following is a simple example of a Snyk task to run a Snyk Code test. - [Simple example of a Snyk task to test a container image](simple-example-of-a-snyk-task-to-test-a-container-image.md): The following is a simple example of a Snyk task to test a container image. - [Simple example of a Snyk task to test an application](simple-example-of-a-snyk-task-to-test-an-application.md): The following is a simple example of a Snyk task to test an application's open-source dependencies (SCA). - [Single Sign-On (SSO) for authentication to Snyk](single-sign-on-sso-for-authentication-to-snyk.md): {% hint style="info" %} - [Slack app](slack-app.md): {% hint style="warning" %} - [Slack integration](slack-integration.md): {% hint style="warning" %} - [Slack setup to connect Snyk with AWS Lambda](slack-setup-to-connect-snyk-with-aws-lambda.md): To enable Snyk to communicate with Slack, start by setting up incoming webhooks through Slack Apps. These are provide... - [Slack](slack.md): {% hint style="info" %} - [SlackSettings](slacksettings.md): {% hint style="info" %} - [Snapshots (v1)](snapshots-v1.md): {% hint style="info" %} - [Overview](snyk-admin.md): {% hint style="info" %} - [Snyk API & Web Managed Scans Service Description](snyk-api-and-web-managed-scans-service-description.md): Snyk API & Web Managed Scans is an optional add-on service, designed for organizations seeking to maximize their dyna... - [Snyk API token permissions users can control](snyk-api-token-permissions-users-can-control.md): To set an API token to have read-only permissions so the user is unable to write to the platform, use a service accou... - [Overview](snyk-api.md): {% hint style="info" %} - [Snyk Apps APIs](snyk-apps-apis.md): This section provides an introduction to Snyk Apps and instructions for using the API and the CLI to create an App, f... - [Snyk Assist](snyk-assist.md): {% hint style="info" %} - [Snyk Broker - commit signing](snyk-broker-commit-signing.md): {% hint style="info" %} - [Snyk Broker - Container Registry Agent](snyk-broker-container-registry-agent.md): {% hint style="info" %} - [Snyk Broker - Infrastructure as Code detection](snyk-broker-infrastructure-as-code-detection.md): Beginning with Snyk Broker v4.205.2, the Infrastructure-as-Code (IaC) detection is enabled by default. - [Snyk Broker](snyk-broker.md): {% hint style="info" %} - [Snyk CI/CD Integration deployment and strategies](snyk-ci-cd-integration-deployment-and-strategies.md): When you decide to use a Snyk CI/CD Integration, you typically adopt the integration in specific stages and choose a ... - [Snyk CI/CDs](snyk-ci-cd-integrations.md): {% hint style="info" %} - [Snyk CLI analytics](snyk-cli-analytics.md): To provide a reliable and feature-rich experience, our command-line interface (CLI) utilizes two types of analytics: ... - [Snyk CLI for IaC](snyk-cli-for-iac.md): To use the CLI, you must first [install](https://docs.snyk.io/developer-tools/snyk-cli/install-or-update-the-snyk-cli... - [Snyk CLI for Java and Kotlin](snyk-cli-for-java-and-kotlin.md): To test Maven and Gradle Projects, use the`snyk test`command as follows: - [Snyk CLI for JavaScript](snyk-cli-for-javascript.md): To help generate reports locally or at build time, see the [snyk-to-html plugin](https://docs.snyk.io/developer-tools... - [Snyk CLI for open-source C++ scans](snyk-cli-for-open-source-c-scans.md): To explore the vulnerabilities for C/C++, search the [Snyk Vuln DB](https://security.snyk.io). Snyk tests your code a... - [Snyk CLI for Open Source](snyk-cli-for-open-source.md): Snyk Open Source scans your manifest files. Based on the scan, Snyk creates a hierarchical tree of the structure repr... - [CLI support for Python](snyk-cli-for-python.md): To set the Python version in the CLI, add the following option to`snyk test`or`snyk monitor`with the name of the ... - [Snyk CLI for Snyk Code](snyk-cli-for-snyk-code.md): The [Snyk Command Line Interface](https://docs.snyk.io/developer-tools/snyk-cli) (CLI) enables you to bring the funct... - [Snyk CLI for Snyk Container](snyk-cli-for-snyk-container.md): {% hint style="info" %} - [Snyk CLI](snyk-cli.md): This documentation provides guidance and information for using the Snyk CLI to bring the functionality of Snyk into y... - [Snyk CocoaPods action](snyk-cocoapods-action.md): This page provides examples of using the Snyk GitHub Action for [CocoaPods](https://github.com/snyk/actions/tree/mast... - [Snyk Code appears disabled](snyk-code-appears-disabled.md): Snyk Code is marked as disabled in the IDE plugin. The preferred Organization is set to the one with Snyk Code enabled. - [Snyk Code Local Engine](snyk-code-local-engine.md): {% hint style="warning" %} - [Snyk Code security rules](snyk-code-security-rules.md): {% hint style="info" %} - [Snyk Code](snyk-code.md): Snyk Code is a developer-first static application security testing (SAST) solution. By scanning code in real-time and... - [Snyk Container-specific CI/CD strategies](snyk-container-specific-ci-cd-strategies.md): The best time to implement Snyk Container in your pipeline is after the container image is built, that is, after runn... - [Snyk Container](snyk-container.md): {% hint style="info" %} - [snyk-delta](snyk-delta.md): This tool provides the means to get the delta between two Snyk Open Source snapshots. This is especially useful when ... - [Snyk Docker action](snyk-docker-action.md): This page provides instructions for and examples of using the Snyk GitHub Action for [Docker](https://github.com/snyk... - [Snyk dotNET action](snyk-dotnet-action.md): This page provides examples of using the Snyk GitHub Action for [dotNET](https://github.com/snyk/actions/tree/master/... - [Snyk Essentials](snyk-essentials.md): Snyk Essentials helps AppSec teams better operationalize and scale use of Snyk with broad application visibility and ... - [snyk-filter](snyk-filter.md): The`snyk-filter`tool provides **custom filtering for Snyk CLI output**.`snyk-filter`takes the JSON-formatted outp... - [Snyk for Bazel](snyk-for-bazel.md): {% hint style="info" %} - [Snyk for Government (US)](snyk-for-government-us.md): [Snyk for Government (US)](https://snyk.io/government-security-solution/) enables US federal agencies to develop fast... - [Snyk Golang action](snyk-golang-action.md): This page provides examples of using the Snyk GitHub Action for [Golang](https://github.com/snyk/actions/tree/master/... - [Snyk Gradle action](snyk-gradle-action.md): This page provides examples of using the Snyk GitHub action for [Gradle](https://github.com/snyk/actions/tree/master/... - [Snyk Gradle-jdk11 action](snyk-gradle-jdk11-action.md): This page provides examples of using the Snyk GitHub Action for [Gradle (jdk11)](https://github.com/snyk/actions/tree... - [Snyk Gradle-jdk12 action](snyk-gradle-jdk12-action.md): This page provides examples of using the Snyk GitHub action for [Gradle (jdk12)](https://github.com/snyk/actions/tree... - [Snyk Gradle-jdk14 action](snyk-gradle-jdk14-action.md): This page provides examples of using the Snyk GitHub action for [Gradle (jdk14)](https://github.com/snyk/actions/tree... - [Snyk Gradle-jdk16 action](snyk-gradle-jdk16-action.md): This page provides examples of using the Snyk GitHub action for [Gradle (jdk16)](https://github.com/snyk/actions/tree... - [Snyk Gradle-jdk17 action](snyk-gradle-jdk17-action.md): This page provides examples of using the Snyk GitHub action for [Gradle (jdk17)](https://github.com/snyk/actions/tree... - [Snyk IaC CLI test results (v. 1.938.0 and earlier)](snyk-iac-cli-test-results-v-19380-and-earlier.md): {% hint style="info" %} - [Snyk IaC CLI test results (v. 1.939.0 and later)](snyk-iac-cli-test-results-v-19390-and-later.md): {% hint style="info" %} - [Snyk IaC integrations](snyk-iac-integrations.md): This section provides information about the following: - [Snyk IaC-specific CI/CD strategies](snyk-iac-specific-ci-cd-strategies.md): The best way to implement Snyk Infrastructure as Code in your pipeline is as part of the stages, but after the SCA an... - [Snyk IaC with Broker for self-hosted Git](snyk-iac-with-broker-for-self-hosted-git.md): Snyk Broker enables you to connect your local Git server to Snyk if the Git server is not internet-reachable. - [Snyk IaC](snyk-iac.md): With Snyk Infrastructure as Code (IaC), you can secure cloud infrastructure configurations before and after deployment. - [Snyk IDE plugins and extensions](snyk-ide-plugins-and-extensions.md): {% hint style="info" %} - [Consistent Ignores for Snyk Code IDE](snyk-ide.md): When you run tests in any of the [four supported Snyk IDE plugins](https://docs.snyk.io/developer-tools/snyk-ide-plug... - [Snyk Images and EOL image policy](snyk-images-and-eol-image-policy.md): This page outlines the Snyk end-of-life (EOL) policy for images provided by the Snyk Images build toolchain, which is... - [Snyk images guides to migration](snyk-images-guides-to-migration.md): Guides are available for the following: - [Snyk Images migration](snyk-images-migration.md): You can [create your own custom images](https://docs.snyk.io/developer-tools/snyk-ci-cd-integrations/user-defined-cus... - [Snyk Infrastructure as Code action](snyk-infrastructure-as-code-action.md): This page provides instructions for and examples of using the Snyk GitHub Action for [Infrastructure as Code](https:/... - [Snyk Jumpstart Basic Services Description](snyk-jumpstart-basic-services-description.md): A Snyk Consultant will provide services to help the Customer accelerate its setup of Snyk products through assisted a... - [Snyk Jumpstart: Basic versus Standard](snyk-jumpstart-basic-versus-standard.md): Snyk Jumpstart services accelerate Snyk product configuration through remote, consultant-led engagements. Both packag... - [Snyk Jumpstart Customer Prerequisites](snyk-jumpstart-customer-prerequisites.md): A Snyk Implementation Consultant will provide services to help the Customer accelerate integration of Snyk through as... - [Snyk Jumpstart Standard Services Description](snyk-jumpstart-services-description.md): A Snyk Consultant will provide services to help the Customer accelerate its setup of Snyk products through assisted a... - [Snyk Language Server](snyk-language-server.md): Snyk offers IDE integrations that allow you to use the functionality of Snyk in your Integrated Development Environme... - [Snyk Learn access controls](snyk-learn-access-controls.md): {% hint style="info" %} - [Snyk Learn API](snyk-learn-api.md): {% hint style="info" %} - [Snyk Learn assignments](snyk-learn-assignments.md): {% hint style="info" %} - [Snyk Learn - Learning Admin](snyk-learn-learning-admin.md): {% hint style="info" %} - [Snyk Learn reporting](snyk-learn-reports.md): {% hint style="info" %} - [Developer security education and Snyk product training](snyk-learn.md): [Snyk Learn](https://learn.snyk.io) offers lessons for developer security education and Snyk [... - [Snyk License Compliance Management](snyk-license-compliance-management.md): {% hint style="info" %} - [Snyk Maven-3-jdk-11 action](snyk-maven-3-jdk-11-action.md): This page provides examples of using the Snyk GitHub action for [Maven (3-jdk-11)](https://github.com/snyk/actions/tr... - [Snyk Maven action](snyk-maven-action.md): This page provides examples of using the Snyk GitHub action for [Maven](https://github.com/snyk/actions/tree/master/m... - [Snyk Node action](snyk-node-action.md): This page provides examples of using the Snyk GitHub action for [Node](https://github.com/snyk/actions/tree/master/no... - [Snyk Open Source Scans (SCA) of large manifest files, Docker setup](snyk-open-source-scans-sca-of-large-manifest-files-docker-setup.md): {% hint style="info" %} - [Snyk Open Source scans (SCA) of large manifest files, Helm setup](snyk-open-source-scans-sca-of-large-manifest-files-helm-setup.md): {% hint style="info" %} - [Snyk Open Source-specific CI/CD strategies](snyk-open-source-specific-ci-cd-strategies.md): These strategies are useful to teams using the Snyk SCA ([Software Composition Analysis](https://snyk.io/blog/what-is... - [Snyk Open Source](snyk-open-source.md): {% hint style="info" %} - [Snyk patches to fix vulnerabilities](snyk-patches-to-fix-vulnerabilities.md): Sometimes there is no direct upgrade that can address the vulnerability, or an upgrade is not possible due to functio... - [Snyk Penetration Testing Service Description](snyk-penetration-testing-service-description.md): The Snyk Penetration Testing service delivers an expert-driven, end-to-end security evaluation of your web applicatio... - [Snyk PHP action](snyk-php-action.md): This page provides examples of using the Snyk GitHub action for [PHP](https://github.com/snyk/actions/tree/master/php... - [Snyk pipe examples](snyk-pipe-examples.md): See the repository [documentation](https://bitbucket.org/snyk/snyk-scan/src/develop/README.md) for up-to-date usage e... - [Snyk pipe parameters and values (Bitbucket Cloud)](snyk-pipe-parameters-and-values-bitbucket-cloud.md): Configure the following Snyk pipe as part of a pipeline YAML file in order to include vulnerability scanning as part ... - [Snyk Platform credits](snyk-platform-access-credits.md): The Snyk Credits plan consolidates features into a single license for quick, flexible deployment. You can utilize you... - [Snyk Preview](snyk-preview.md): {% hint style="info" %} - [Snyk Projects](snyk-projects.md): Snyk Project information appears in the **Projects** listing, which you can display from the menu on the Snyk dashboa... - [@snyk/protect package](snyk-protect-package.md): The`@snyk/protect`[package](https://github.com/snyk/snyk/tree/master/packages/snyk-protect) (replaced the`snyk pro... - [Snyk Pull or Merge Requests](snyk-pull-or-merge-requests.md): In addition to fixing advice, Snyk can automatically create pull requests (PRs) on your behalf to upgrade your depend... - [Consistent Ignores for Snyk Code Pull Request Checks](snyk-pull-request-checks.md): When viewing a pull request (PR) check from Snyk in your integrated SCM, ignored findings do not contribute to the PR... - [Snyk Python-3.6 action](snyk-python-36-action.md): {% hint style="warning" %} - [Snyk Python-3.7 action](snyk-python-37-action.md): {% hint style="warning" %} - [Snyk Python-3.8 action](snyk-python-38-action.md): This page provides examples of using the Snyk GitHub Action for [Python (3.8)](https://github.com/snyk/actions/tree/m... - [Snyk Python action](snyk-python-action.md): This page provides examples of using the Snyk GitHub action for [Python](https://github.com/snyk/actions/tree/master/... - [Snyk release process](snyk-release-process.md): {% hint style="info" %} - [Snyk Residency Services](snyk-residency-services.md): Snyk Residency Services (hereinafter Residency Services) are remote consulting services that provide Snyk Customers w... - [Snyk Ruby action](snyk-ruby-action.md): This page provides examples of using the Snyk GitHub Action for [Ruby](https://github.com/snyk/actions/tree/master/ru... - [Snyk Scala action](snyk-scala-action.md): {% hint style="warning" %} - [snyk-scm-contributors-count](snyk-scm-contributors-count.md): This tool counts and prints a summary of the contributors count for the last 90 days for any of the following SCMs: - [Snyk Security in Jira Cloud integration](snyk-security-in-jira-cloud-integration.md): {% hint style="info" %} - [Snyk Security Scan task parameters and values](snyk-security-scan-task-parameters-and-values.md): The following describes the Snyk task configuration fields on the configuration panel in Azure Pipelines, the associa... - [Snyk Setup action](snyk-setup-action.md): The [Snyk Setup Action](https://github.com/snyk/actions/tree/master/setup) provides a way to install the Snyk CLI to ... - [Agentic security with Snyk Studio](snyk-studio-agentic-integrations.md): Agentic workflows accelerate software development and innovation but introduce security risks, for example, AI-genera... - [Secure at Inception with Snyk Studio](snyk-studio-and-secure-at-inception.md): To prevent the introduction of security issues during code generation, Snyk outlines a set of [directives](#custom-ru... - [Snyk terms of support and services glossary](snyk-terms-of-support-and-services-glossary.md): The following terms shall apply if and to the extent the Customer purchases the offerings below on an Order Form. The... - [Snyk test and snyk monitor in CI/CD integration](snyk-test-and-snyk-monitor-in-ci-cd-integration.md): Depending on your approach and goals for your Snyk Open Source Project, you may need to use both the`snyk monitor`a... - [snyk-to-html](snyk-to-html.md): The CLI provides a direct or automated way to fail the build and, by default, provides only summary information unles... - [Snyk Tools](snyk-tools.md): Snyk Tools help with specific pain points that may not be addressed by Snyk product functionality, regardless of whet... - [Snyk Vulnerability Database](snyk-vulnerability-database.md): The [Snyk Vulnerability Database](https://security.snyk.io) contains a comprehensive list of known security vulnerabi... - [Solutions for specific use cases](solutions-for-specific-use-cases.md): Snyk maintains a [repository](https://github.com/snyk-playground/cx-tools) of scripts and tools to solve specific use... - [Start scanning](start-scanning.md): You can use Snyk to scan your code manually and automatically using the Snyk CLI, the [Snyk we... - [Step 1: Download Azure app registration IaC template or script (API)](step-1-download-azure-app-registration-iac-template-or-script-api.md): Before you can create a Cloud Environment for an Azure subscription, you must **download** a Terraform infrastructure... - [Step 1: Download Azure app registration IaC template or script (Web UI)](step-1-download-azure-app-registration-iac-template-or-script-web-ui.md): Before you can create a Cloud Environment for an Azure subscription, you must **download** a Terraform infrastructure... - [Step 1: Download IAM role IaC template (API)](step-1-download-iam-role-iac-template-api.md): Before you can create a Cloud Environment, you must download an Infrastructure as Code (IaC) template declaring a rea... - [Step 1: Download IAM role IaC template (Web UI)](step-1-download-iam-role-iac-template-web-ui.md): Before you can create a Cloud Environment, you must download an Infrastructure as Code (IaC) template declaring a rea... - [Step 1: Download service account IaC template (API)](step-1-download-service-account-iac-template-api.md): Before you can create a Cloud Environment, you must download an infrastructure as code (IaC) template declaring a tig... - [Step 1: Download service account IaC template (Web UI)](step-1-download-service-account-iac-template-web-ui.md): Before you can create a Cloud Environment, you must download an infrastructure as code (IaC) template declaring a tig... - [Step 2: Create the Entra ID app registration (API)](step-2-create-the-entra-id-app-registration-api.md): {% hint style="info" %} - [Step 2: Create the Entra ID app registration](step-2-create-the-entra-id-app-registration.md): {% hint style="info" %} - [Step 2: Create the Google service account (API)](step-2-create-the-google-service-account-api.md): {% hint style="info" %} - [Step 2: Create the Google service account (Web UI)](step-2-create-the-google-service-account-web-ui.md): {% hint style="info" %} - [Step 2: Create the Snyk IAM role (API)](step-2-create-the-snyk-iam-role-api.md): {% hint style="info" %} - [Step 2: Create the Snyk IAM role](step-2-create-the-snyk-iam-role.md): {% hint style="info" %} - [Step 3: Create and scan a Cloud Environment (API)](step-3-create-and-scan-a-cloud-environment-api.md): {% hint style="info" %} - [Step 3: Create and scan a Cloud Environment for Azure (API)](step-3-create-and-scan-a-cloud-environment-for-azure-api.md): {% hint style="info" %} - [Step 3: Create and scan a Cloud Environment for Azure (Web UI)](step-3-create-and-scan-a-cloud-environment-for-azure-web-ui.md): {% hint style="info" %} - [Step 3: Create and scan a Cloud Environment for Google (API)](step-3-create-and-scan-a-cloud-environment-for-google-api.md): {% hint style="info" %} - [Step 3: Create and scan a Cloud Environment for Google (Web UI)](step-3-create-and-scan-a-cloud-environment-for-google-web-ui.md): {% hint style="info" %} - [Step 3: Create and scan a Cloud Environment (Web UI)](step-3-create-and-scan-a-cloud-environment-web-ui.md): {% hint style="info" %} - [Structure your account for high application performance](structure-your-account-for-high-application-performance.md): To ensure the best experience using Snyk, consider these guidelines when making decisions about your Snyk user accoun... - [Supported AWS resources for cloud context](supported-aws-resources-for-cloud-context.md): Snyk cloud context works with the following Amazon Web Services resource types: - [Supported Azure resources for cloud context](supported-azure-resources-for-cloud-context.md): Snyk cloud context works with the following Azure resource types: - [Supported Google resources for cloud context](supported-google-resources-for-cloud-context.md): Snyk cloud context works with the following Google Cloud resource types: - [Supported IaC languages, cloud providers, and cloud resources](supported-iac-languages-cloud-providers-and-cloud-resources.md): {% hint style="info" %} - [Supported languages list](supported-languages-list.md): - [Apex](/supported-languages/supported-languages-list/apex.md) - [Supported languages, package managers, and frameworks](supported-languages-package-managers-and-frameworks.md): Snyk offers support for various languages, customized depending on the Snyk product you are using. These pages focus ... - [Supported resources](supported-resources.md): Snyk IaC unmanaged resource scanning supports the resources listed on each page for these cloud providers: - [Supported workloads, container registries, languages, and operating systems](supported-workloads-container-registries-languages-and-operating-systems.md): The Snyk Controller can detect the following workloads in the cluster: - [Swift and Objective-C](swift-and-objective-c.md): {% hint style="info" %} - [Swift rules](swift-rules.md): Each rule includes the following information. - [Switch between Groups and Organizations](switch-between-groups-and-organizations.md): Snyk shows your preferred Organization by default when you log into the Snyk Web UI. Snyk also uses the settings for ... - [Labeling policy](tagging-policy.md): Categorize and label repository assets with [asset labels](https://docs.snyk.io/manage-assets/assets-inventory-compon... - [Targets](targets.md): {% hint style="info" %} - [Team implementation guide](team-implementation-guide.md): Accelerate your team performance by using Snyk. This guide aims to help you implement Snyk for your team. The team pl... - [Team Lead role template](team-lead-role-template.md): A Team Lead is equivalent to the default [**Organization Admin**](https://docs.snyk.io/snyk-platform-administration/u... - [TeamCity configuration parameters](teamcity-configuration-parameters.md): This page provides information about Snyk settings, Additional parameters... - [TeamCity integration: install the Snyk plugin](teamcity-integration-install-the-snyk-plugin.md): Follow these steps to install or upgrade the Snyk Security plugin. When the installation is complete, you can add a S... - [TeamCity integration: use Snyk in your build](teamcity-integration-use-snyk-in-your-build.md): For any Project, you can add Snyk to your build to scan the code while you build and to fail the build for vulnerabil... - [TeamCity (JetBrains) integration using the Snyk security plugin](teamcity-jetbrains-integration-using-the-snyk-security-plugin.md): Integrate the Snyk Security plugin with the JetBrains continuous integration (CI) tool, TeamCity, to embed open-sourc... - [Technical specifications and guidance](technical-specifications-and-guidance.md): Both Snyk Code and Snyk Open Source accept source code files in UTF-8 encoding. Consider converting source files to t... - [Tenant](tenant.md): {% hint style="info" %} - [TenantRole](tenantrole.md): {% hint style="info" %} - [Tenants](tenants.md): {% hint style="info" %} - [Terraform AWS Provider support](terraform-aws-provider-support.md): {% hint style="success" %} - [Terraform Cloud integration for Snyk IaC using Run Tasks](terraform-cloud-integration-for-snyk-iac-using-run-tasks.md): {% hint style="info" %} - [Terraform Enterprise integration for Snyk IaC](terraform-enterprise-integration-for-snyk-iac.md): [Terraform Enterprise](https://www.terraform.io/enterprise) (TFE) by HashiCorp is an offering that provides a private... - [Terraform files](terraform-files.md): With Snyk Infrastructure as Code, you can scan both your static configuration files and Terraform plan output using t... - [Terraform variables support](terraform-variables-support-current-iac.md): Support for Terraform (TF) variables is currently available only in the CLI. Snyk supports: - [Test public npm packages before use](test-public-npm-packages-before-use.md): You can use`snyk test`to **scrutinize a public package before installing it**, to see if it has known vulnerabiliti... - [Test the Snyk webhook connection](test-the-snyk-webhook-connection.md): The Snyk Webhook only updates when there is a new vulnerability found, but you can test your implementation using Pos... - [Test (v1)](test-v1.md): {% hint style="info" %} - [Test your IaC files](test-your-iac-files.md): {% hint style="info" %} - [Test](test.md): `snyk test []` - [Testing a rule](testing-a-rule.md): If you have generated the rules using the`template`command, as shown in [Writing a rule](https://docs.snyk.io/scan-... - [Tests](tests.md): {% hint style="info" %} - [The .snyk file](the-snyk-file.md): The`.snyk`file is a capability of Snyk that all users can employ locally or as part of their workflow to control Sn... - [Third-party dependency scanning (SCA, Snyk Open Source)](third-party-dependency-scanning-sca-snyk-open-source.md): In the Eclipse plugin version 2.0.0 and later, Snyk has enhanced integrations with the native flows of Eclipse: inlin... - [Tool: jira-tickets-for-new-vulns](tool-jira-tickets-for-new-vulns.md): `jira-tickets-for-new-vulns`provides the means to sync your Snyk-monitored projects and automatically open Jira tick... - [Tool: snyk-api-import](tool-snyk-api-import.md): Snyk helps you find, fix, and monitor for known vulnerabilities in your dependencies, both on an ad hoc basis and as ... - [Trial limitations](trial-limitations.md): You can try out Snyk functionalities in several ways: - [Troubleshoot certificate errors](troubleshoot-certificate-errors.md): Error message **Unable to get local issuer certificate** or something with certificate path. - [Troubleshoot fixing vulnerabilities with Snyk Open Source](troubleshoot-fixing-vulnerabilities-with-snyk-open-source.md): When you find a vulnerability, you have the opportunity to report that vulnerability to Snyk. For details, see [Discl... - [Troubleshoot PR checks](troubleshoot-pr-checks.md): The following table lists general issues with PR checks and how to address them. - [Troubleshooting and known issues with Visual Studio extension](troubleshooting-and-known-issues-with-visual-studio-extension.md): {% hint style="warning" %} - [Troubleshooting and limitations for custom PR templates](troubleshooting-and-limitations-for-custom-pr-templates.md): If you encounter an error, check your template and follow these instructions. - [Troubleshooting Broker](troubleshooting-broker.md): {% hint style="info" %} - [Troubleshooting C/C++ for open source](troubleshooting-c-c-for-open-source.md): No. The files are converted to a list of hashes before they are sent for scanning. - [Troubleshooting for the Eclipse plugin](troubleshooting-for-the-eclipse-plugin.md): {% hint style="warning" %} - [Troubleshooting for the JetBrains plugin](troubleshooting-for-the-jetbrains-plugin.md): {% hint style="warning" %} - [Troubleshooting for Visual Studio Code extension](troubleshooting-for-visual-studio-code-extension.md): {% hint style="warning" %} - [Troubleshooting IDEs](troubleshooting-ides.md): This section provides the following articles to help in using Snyk IDE plugins and extensions: - [Troubleshooting Snyk for .NET](troubleshooting-snyk-for-net.md): * [`Directory.Build.props`](https://docs.microsoft.com/en-us/visualstudio/msbuild/customize-your-build?view=vs-2022#d... - [Troubleshooting Snyk reports](troubleshooting-snyk-reports.md): If reporting is not loading in the Snyk UI, follow these troubleshooting steps that may help resolve the issue. - [Troubleshooting](troubleshooting.md): If you encounter issues with Snyk Studio or the integration using Snyk's MCP server, try the troubleshooting steps pr... - [Tutorial: create a Snyk App](tutorial-create-a-snyk-app.md): In this tutorial, we'll create a simple Snyk App using TypeScript to show users a list of their projects within Snyk. - [How to use Snyk webhooks with Zapier](tutorial.md): {% hint style="info" %} - [TypeScript](typescript.md): {% hint style="info" %} - [Understand Snyk Container CLI results](understand-snyk-container-cli-results.md): When Snyk Container detects vulnerabilities, they are presented in the output: - [Understand the IaC CLI test results](understand-the-iac-cli-test-results.md): {% hint style="info" %} - [Understand your issues](understand-your-issues.md): Snyk Issues works by understanding your vulnerabilities within the context of your application. You can see all the g... - [Unified IDE Configuration Dialog (experimental)](unified-ide-configuration-dialog-experimental.md): You can use only one IDE configuration dialog to configure all your IDEs. - [Universal Broker workflow diagrams](universal-broker-workflow-diagrams.md): The following workflow diagrams illustrate the steps that are implemented in the`snyk broker config`tool when you u... - [Universal Broker](universal-broker.md): The Universal Broker improves the management of Broker deployments and connections by supporting many connections of ... - [Update a cloud environment](update-a-cloud-environment.md): You can update the following attributes for a [cloud environment](https://docs.snyk.io/scan-with-snyk/snyk-iac/key-co... - [Update member roles using the API](update-member-roles-using-the-api.md): To migrate members of existing organizations to new roles, you must use the API. Follow the steps in each section of ... - [Update the Snyk Broker client](update-the-snyk-broker-client.md): Snyk regularly releases updated versions of the Broker client in order to provide new features, bug fixes, and more. ... - [Upgrade an Organization integration from Classic Broker to Universal Broker](upgrade-an-organization-integration-from-classic-broker-to-universal-broker.md): {% hint style="info" %} - [Upgrade dependencies with automatic PRs (Upgrade PRs)](upgrade-dependencies-with-automatic-prs-upgrade-prs.md): {% hint style="info" %} - [Upgrade open source dependencies with automatic PRs](upgrade-open-source-dependencies-with-automatic-prs.md): After you import Git repositories, Snyk continuously monitors these repositories by scanning them for vulnerabilities... - [Upgrade package versions to fix vulnerabilities](upgrade-package-versions-to-fix-vulnerabilities.md): Snyk will always recommend the smallest upgrade of a dependency to resolve a vulnerability. - [Usage analytics](usage-analytics.md): Snyk provides Snyk Studio usage analytics in the following report types: - [Usage settings](usage-settings.md): In your Group or Organization, select **Settings** > **Usage** to view Snyk usage details for your Group or Organizat... - [Usage](usage.md): snyk-scm-contributors-count - [Use a local IaC custom rules bundle](use-a-local-iac-custom-rules-bundle.md): {% hint style="info" %} - [Use a remote IaC custom rules bundle](use-a-remote-iac-custom-rules-bundle.md): After you generate your custom rules bundle, you can distribute it to one of the supported OCI registries by followin... - [Use cases for policies](use-cases-for-policies.md): Gain a better understanding of the policies you can use by going through the following use cases. These are only exam... - [Use Custom Base Image Recommendations](use-custom-base-image-recommendations.md): {% hint style="info" %} - [Use IaC custom rules with CLI](use-iac-custom-rules-with-cli.md): {% hint style="info" %} - [Use options to customize the snyk test command](use-options-to-customize-the-snyk-test-command.md): The Snyk CLI has many commands that enable you to perform various tasks and many options that enable you to customize... - [Use policies in the SDLC](use-policies-in-the-sdlc.md): You can apply policies across all stages of the SDLC, from the developer’s local development environment, in the IDE ... - [Snyk Code in the CI/CD pipeline](use-snyk-code-in-the-ci-cd-pipeline.md): You can use CI/CD integration to test your code for vulnerabilities and ensure your changes do not introduce new vuln... - [Use Snyk Container](use-snyk-container.md): To use Snyk Container from the Web UI, see the pages in this section. Information about using Snyk Container with the... - [Use the Snyk plugin to secure your Eclipse projects](use-the-snyk-plugin-to-secure-your-eclipse-projects.md): After the Eclipse plugin is downloaded and authentication is complete, the plugin starts the workspace scan. You may ... - [User-defined custom images for CLI](user-defined-custom-images-for-cli.md): Following Snyk announcements regarding [Snyk CLI Images](https://headwayapp.co/snyk-io-updates/deprecation-notice-for... - [User management with the API](user-management-with-the-api.md): {% hint style="info" %} - [User permissions and access scopes](user-permissions-and-access-scopes.md): Snyk SCM integrations may require different permission requirements based on the connection method. - [User role management](user-role-management.md): {% hint style="info" %} - [User roles](user-roles.md): {% hint style="info" %} - [Users (v1)](users-v1.md): {% hint style="info" %} - [Users](users.md): {% hint style="info" %} - [Using CLI releases before version 1.1230.0 on an Apple M1 or M2 machine](using-cli-releases-before-version-112300-on-an-apple-m1-or-m2-machine.md): **Beginning with version 1.1230.0**, the Snyk CLI supports Apple silicon, including M1 and M2 machines, so **you no l... - [Using FIPS-validated cryptography](using-fips-validated-cryptography.md): Support for use of FIPS-validated cryptography is limited to the Windows and Linux operating systems. - [Using Snyk Essentials with Snyk Broker](using-snyk-essentials-with-snyk-broker.md): If your SCM instance is not publicly accessible, you must use Snyk Broker to scan your repositories. - [Using specific Snyk APIs](using-specific-snyk-apis.md): This section provides information on how to use specific Snyk APIs. - [Using the API to set up a GitHub connection](using-the-api-to-set-up-a-github-connection.md): This page provides an example of using the API to set up a GitHub connection with the Universal Broker. Repeat connec... - [Using the API to set up Universal Broker](using-the-api-to-set-up-universal-broker.md): All flows available in the`snyk-broker-config`CLI tool are built on top of the public REST API. The workflows in th... - [Using the Issues UI](using-the-issues-ui.md): The following pages provide information and instructions on how to use the Issues UI. - [V1 API](v1-api.md): {% hint style="info" %} - [V1 Reporting APIs to Export API migration guide](v1-reporting-apis-to-export-api-migration-guide.md): {% hint style="warning" %} - [Validate your Snyk plan](validate-your-snyk-plan.md): Confirm your Snyk license has been applied correctly. Navigate to your Organization by clicking the Organization name... - [Validation and versioning of payloads](validation-and-versioning-of-payloads.md): All transports sent to your webhooks have a`X-Hub-Signature`header, which contains the hash signature for the trans... - [Variables list and description](variables-list-and-description.md): {% tabs %} - [Verifying Broker image signatures](verifying-broker-image-signatures.md): Beginning with version 4.169.1, all Broker container images are signed using Cosign. - [Verifying CLI standalone binaries](verifying-cli-standalone-binaries.md): You can verify both the shasum of downloaded binaries and their GPG signatures. - [Versioning schemas for custom base images](versioning-schema-for-custom-base-images.md): You must set a versioning schema for the first Project you mark as a custom base image in the image's repository. You... - [View, add, and remove environments](view-add-and-remove-environments.md): To view all Snyk environments in an Organization, navigate to your Organization **Settings** > **Cloud environments**. - [View analysis results from Visual Studio Code extension](view-analysis-results-from-visual-studio-code-extension.md): Snyk analysis shows a list of security vulnerabilities and code issues in the application code. Select a security vul... - [View analysis results from Visual Studio extension](view-analysis-results-from-visual-studio-extension.md): You can filter vulnerabilities by name or by severity. - [View and edit Project settings](view-and-edit-project-settings.md): Select the **Settings** tab on the Project listing or details page to view and edit Project settings: - [View cloud compliance reporting](view-cloud-compliance-reporting.md): Snyk IaC supports [compliance reporting](https://docs.snyk.io/manage-risk/reporting/available-snyk-reports#cloud-comp... - [View cloud issues in the Snyk Web UI](view-cloud-issues-in-the-snyk-web-ui.md): You can view cloud issues for an Organization through the Snyk Web UI. - [View cloud resources](view-cloud-resources.md): You can view all attributes for cloud resources in an Organization. This allows you to inventory all of your resource... - [View, create, and modify policies](view-create-and-modify-policies.md): {% hint style="info" %} - [View dependencies](view-dependencies.md): The **Dependencies** tab acts as a Bill Of Materials (BOM) for all dependencies in all Projects in the selected Organ... - [View exploits](view-exploits.md): An exploit is a demonstration of how a vulnerability can be taken advantage of. When an exploit is widely published, ... - [View licenses](view-licenses.md): The **Licenses** tab displays all licenses detected for your Projects, with summaries of all dependencies in your Pro... - [View Project details and scan results](view-project-details-and-scan-results.md): All workloads that you have imported for monitoring appear on the **Projects** page and are marked with a unique Kube... - [View Project history](view-project-history.md): Select the **History** tab on the Project details page to view the Project history, which shows results of previous s... - [View Project issues, fixes, and dependencies](view-project-issues-fixes-and-dependencies.md): The following Project information is available on the Snyk Web UI: - [View Snyk Code CLI results](view-snyk-code-cli-results.md): The Snyk CLI enables you to perform the following actions on the results of the`snyk code test`command: - [View Snyk IaC issue reports](view-snyk-iac-issue-reports.md): Set the **Issue Type** filter on [Snyk reports](https://docs.snyk.io/manage-risk/reporting/legacy-reports) to **Confi... - [Visual Basic rules](visual-basic-rules.md): Each rule includes the following information. - [Visual Studio Code extension configuration, environment variables, and proxy](visual-studio-code-extension-configuration-environment-variables-and-proxy.md): After the plugin is installed, you can set the following configurations for the extension. - [Visual Studio Code extension](visual-studio-code-extension.md): Integrating security checks early in your development lifecycle helps you pass security reviews seamlessly and avoid ... - [Visual Studio Code workspace trust](visual-studio-code-workspace-trust.md): As part of examining the codebase for vulnerabilities, Snyk may automatically execute code on your computer to obtain... - [Visual Studio extension configuration, environment variables, and proxy](visual-studio-extension-configuration-environment-variables-and-proxy.md): After the plugin is installed, you can set the following configurations for the extension. - [Visual Studio extension](visual-studio-extension.md): {% hint style="info" %} - [Visual Studio workspace trust](visual-studio-workspace-trust.md): As part of examining the codebase for vulnerabilities, Snyk may automatically execute code on your computer to obtain... - [Vulnerabilities with Social Trends](vulnerabilities-with-social-trends.md): Snyk Social Trends shows a **Trending** notification for issues that are being actively discussed on X (formerly know... - [Vulnerability fix types](vulnerability-fix-types.md): After you have imported one or more Projects into Snyk through an integration or by scanning with the CLI, Snyk lists... - [Vulnerable conditions](vulnerable-conditions.md): Vulnerabilities that are not exploitable are unlikely to pose a security threat to your application and can therefore... - [Webhooks APIs](webhooks-apis.md): This section includes the following: - [Webhooks (v1)](webhooks-v1.md): {% hint style="info" %} - [Webhook events and payloads](webhooks.md): Webhooks are delivered with a`Content-Type`of`application/json`, with the event payload as JSON in the request bod... - [What counts as a test?](what-counts-as-a-test.md): {% hint style="info" %} - [What's new?](whats-new.md): The most recent updates include significant changes to the user docs, such as features added or removed, structural c... - [What's Snyk?](whats-snyk.md): Snyk is a platform that allows you to scan, prioritize, and fix security vulnerabilities in your code, open-source de... - [Windsurf guide](windsurf-guide.md): Access [Snyk Studio](https://docs.snyk.io/discover-snyk/getting-started/glossary#snyk-studio), including Snyk's MCP s... - [With a Lambda Function URL](with-a-lambda-function-url.md): The goal of this option is to avoid the need of AWS API Gateway and expose the Lambda function directly with the help... - [With API Gateway](with-api-gateway.md): The goal of this option is to use AWS API Gateway to trigger the Lambda function every time a new event is received. - [Working with Kubernetes configuration file test results](working-with-kubernetes-configuration-file-test-results-current-iac.md): After you have imported your configuration file, Snyk continuously monitors the repository for any related changes, r... - [Working with Snyk](working-with-snyk.md): Snyk is dedicated to the secure and responsible handling of user data, with a strong emphasis on privacy and complian... - [Workspaces](workspaces.md): {% hint style="info" %} - [Writing a rule](writing-a-rule.md): Rules are written in Rego. When you are writing Rego, you do two things: - [Writing rules using the SDK](writing-rules-using-the-sdk.md): To get you started with the SDK, you will learn how to: - [XML rules](xml-rules.md): {% hint style="warning" %} - [Your learning](your-learning.md): You can see all of the lessons and learning paths available at . You can search or us...