Skip to main content

Product Updates

Engine
Surface
AI Workflows
Area
Release Status

Showing 1 - 10 of 20 updates

Announcing Snyk CLI v1.1307.4

Improved

We are pleased to announce Snyk CLI release, v1.1307.4

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • New experimental snyk studio command that sets up Snyk Studio in supported AI coding tools (Cursor, Claude Code, Codex, Copilot, Gemini, Kiro, and Windsurf), so the code they generate gets scanned in the background as it's written. This direct integration replaces the need for separate setup scripts (https://github.com/snyk/studio-recipes). Run snyk studio install --experimental to get started.

  • New snyk fix --agentic filtering flags: --severity-filter to fix only the severities you choose, --breakability-filter to fix only Open Source upgrades with the breakability you choose, and --exclude-ids to fix everything except the issue IDs you list.

  • snyk fix --agentic now keeps a failed fix's changes by default so you can review them, rather than reverting automatically. Pass --enable-revert to restore the automatic rollback behavior.

  • Fixed an issue where the --iac, --docker, --container, and --code flags on snyk test could be silently dropped for organizations on the unified test API, causing scans to fall through to an open-source test instead (which could fail with "No supported files found" or scan the wrong target). These flags now route to the correct scan again.

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Container: Go standard library vulnerability reporting

General availability

Snyk Container will begin reporting vulnerabilities from the Go standard library for all customers. Scans of container images built from Go binaries identify the standard library version the binary was compiled with and report known vulnerabilities against it.

Affected images gain a new stdlib dependency in the dependency graph, versioned to the Go release used for the build, for example stdlib@1.25.10. Detection works for standard, stripped, and CGo builds.

No configuration is required, and reporting is enabled automatically for all organizations. Standard library reporting in the Snyk CLI requires v1.1303.2 or later.

This change is scheduled to take effect on October 7, 2026.

Snyk Container reported vulnerabilities in third-party Go dependencies, but not in the Go standard library itself, the HTTP, TLS, JSON, and other libraries that ship with the Go toolchain rather than being installed as dependencies. Those vulnerabilities were visible only indirectly, through distro advisories, so teams shipping Go binaries in containers had no reliable way to see them.

That left two gaps: one between what Snyk Container reported and what Snyk Open Source already reported for the same code, and one in real coverage for any Go application running in a container - this change closes both.

If you scan container images built from Go binaries, your vulnerability counts will increase. Each affected project gains a fixed number of new findings, determined by the Go version the binary was built with. Older Go releases carry more.

Building with a current Go patch release substantially reduces or eliminates these findings. Images built with Go 1.25.13 or later, or Go 1.26.6 or later, report no new vulnerabilities from this change. We recommend reviewing the Go versions used in your build pipelines ahead of the release date.

Considerations and known limitations:

  • Snyk does not perform reachability analysis on standard library packages. Snyk reports all known vulnerabilities for the standard library version in your binary, rather than only those in packages your code imports. This is consistent with the approach taken by other container scanners.

  • Findings that are not relevant to your application can be ignored in Snyk as usual

For more information, see Application vulnerabilities in Snyk Container and Snyk Open Source in the Snyk user documentation: https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/application-vulnerabilities-in-snyk-container-and-snyk-open-source

Announcing Snyk CLI v1.1307.1

Fix

We are pleased to announce Snyk CLI release, v1.1307.1

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • snyk test again reports SNYK-CLI-0008 and exits with code 3 when a repository contains no supported manifest files, instead of a generic SNYK-CLI-0000 with exit code 2. snyk test --json writes the error document to stdout as expected.

  • Restored the moduleName, insights.triageAdvice, and functions_new fields in snyk test --json output, so tooling that consumes those fields works as before.

  • .snyk policy files are now handled correctly in the unified test flow. This covers empty, whitespace-only and comment-only policies, date-only timestamps, and other edge cases that could previously cause incorrect results or failures.

  • Commands that complete with findings (exit code 1) no longer produce duplicate or corrupt JSON output when an unrelated network error occurs during the run, improving reliability for automated pipelines that parse CLI output.

  • The debug-log scrubber now masks secrets consistently and no longer corrupts the surrounding JSON structure, making debug logs safer to share and easier to parse.

  • Container scans now surface source repository information for locally built images using BuildKit metadata.

  • Fixed vulnerabilities:

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Announcing Snyk CLI v1.1307.0

Improved

We are pleased to announce the latest stable Snyk CLI release, v1.1307.0.

We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • Secrets

    • snyk secrets test now supports exclusions — add files or paths to the exclude section of your .snyk file to skip them during secrets scanning.

  • Container

    • Container scans now surface image provenance attestations by default, so signed-image provenance metadata appears in results without any extra flag.

  • .NET/NuGet

    • snyk test can now analyze already-restored .NET/NuGet projects fully offline and no longer requires .NET 6 to be installed.

  • MCP

    • The full Snyk MCP profile now includes Snyk Secrets.

  • Code & Secrets

    • SARIF suppressions now include reviewedOn and reviewedBy metadata.

  • AI BOM

    • snyk aibom test --severity-threshold now filters the displayed and JSON results by severity, not only the exit code.

  • Agent-optimized CLI

    • New experimental snyk agent command space — a scanning surface built for AI coding agents, with token-optimized output and ergonomics. snyk agent test runs Snyk Open Source, Code, and Secrets together.

  • Additional Reliability and Performance Improvements

    • Adds support for scanning pnpm v11 pnpm-lock.yaml lockfiles.

    • Fixes a crash when scanning dependencies of Gradle 7.4–8.2 projects.

    • Fixes a bug where arguments after -- (for example snyk test . -- -s settings.xml) were treated as scan targets, which could silently drop the Risk Score.

    • Fixes scanning of projects using Hex versions newer than 1.19.

    • Excludes the .git folder from file discovery, preventing intermittent scan failures caused by changes to .git contents during a scan

    • Prevents a possible connection leak when the Snyk API returns an error response.

    • Updates dependencies to fix vulnerabilities.

Release notes can be found here.

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.

Matt Dolan | Senior Product Manager

Announcing Snyk CLI v1.1306.0

New

We are pleased to announce the latest stable Snyk CLI release, v1.1306.0.

We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • Doctor

    • Adds a new snyk doctor command, giving you a quick way to diagnose common CLI problems by generating a diagnostic report for your system or analyzing debug log output.

  • Container

    • Container scans now detect the Java runtime version across a wider range of JVM base images, and can find vulnerabilities in .NET application dependencies.

  • Snyk Studio MCP

    • The breakability evaluation tool in the Snyk MCP Server is now enabled by default and no longer requires an experimental flag.

  • SCA Test

    • Improves dependency detection for Gradle projects.

  • Additional Reliability and Performance Improvements

    • Shows a warning when a request is automatically retried due to rate limiting, instead of retrying silently.

    • Skips the reachability upload when no supported files are present, instead of failing.

    • Fixes dependency resolution for Swift Package Manager projects that reference packages by registry identity, so they're correctly matched to their GitHub source for vulnerability scanning.

    • Fixes scanning of sbt projects with custom Scala configurations.

    • Fixes a bug where scanning Yarn workspaces could report vulnerabilities from a workspace member's dev dependencies as production dependencies, when that member was consumed by a sibling package.

    • Updates dependencies to fix vulnerabilities.

Release notes can be found here.

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.

Matt Dolan | Senior Product Manager

Announcing Snyk CLI v1.1305.0

New

We are pleased to announce the latest stable Snyk CLI release, v1.1305.0.

We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • SBOM

    • Introduces the --allow-incomplete-sbom flag for snyk sbom, allowing the SBOM to be generated even when individual projects fail to resolve. Failed projects are surfaced as per-project errors alongside the successful results.

  • Container

    • Speed up snyk container monitor by sending dependency requests in parallel, configurable via the SNYK_REQUEST_CONCURRENCY environment variable.

  • MCP

    • Adds an experimental breakability evaluation tool to the Snyk MCP Server.

  • Static CLI binaries for Linux

    • Linux ARM64 and AMD64 binaries are now statically linked by default.

  • Additional Reliability and Performance Improvements

    • npm package aliases from lockfile now appropriately used in test command.

    • Fixes parsing of Python .whl files when scanning projects with --all-projects.

    • Updates dependencies to fix vulnerabilities

Release notes can be found here.

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.

Matt Dolan | Senior Product Manager

Expanded Container JVM Support

Improved

We are pleased to announce expanded JVM support for Snyk Container vulnerability scanning. Previously, detection for unmanaged Java container software was limited to OpenJDK 8 binaries. With this update, customers can now identify vulnerabilities in their container images for Java versions beyond OpenJDK 8.

This update includes the following:

  • Support for Eclipse Temurin and Adoptium OpenJDK distributions that follow the standard /opt/java/openjdk/release layout.

  • Automatic detection via file fingerprinting with no manual action required to enable it.

This feature is gradually rolling out to General Availability (GA) across CLI and Container Registry (CR) integrations.

If you have any questions, feel free to reach out to the Snyk support team.

Identify CISA KEV vulnerabilities for compliance

New

We added a new Known Exploited Vulnerabilities (KEV) filter to help you identify risks that the Cybersecurity and Infrastructure Security Agency (CISA) tracks as already exploited in the wild. While we already allow you to filter vulnerabilities and Common Vulnerabilities and Exposures (CVE) by their exploit maturity level, this update specifically targets the CISA KEV catalog. You can find this filter on any page where issue filters are available to help you manage your security backlog.

The CISA KEV catalog is a vital resource for meeting global security standards. For instance, FedRAMP requires strict remediation service-level agreements (SLAs) for any vulnerability listed in this catalog. Furthermore, the European Union Cyber Resilience Act (EU CRA) mandates that organizations actively monitor for vulnerabilities found in the CISA KEV catalog. We’re providing this filter to automate this visibility and help you maintain compliance across different regulatory environments.

You can now isolate vulnerabilities within the CISA KEV catalog with a single click. This helps you prioritize remediation based on documented real-world exploitation rather than just theoretical risk. By using this filter, you ensure your team addresses the specific issues that auditors and regulators prioritize, reducing the manual effort needed to cross-reference your backlog against federal and international mandates.

To learn more, visit Issue vulnerability details in our user documentation.

Headshot of Sara Meadzinger

Sara Meadzinger | Staff Product Manager

Announcing Repo Monitor Configuration

Early access

We are excited to be launching Repo Monitor Configuration, which allows for management of repository coverage and monitoring configurations centrally across your entire Snyk Group from the Group-level Inventory page. This means you can monitor and manage repositories without navigating between individual Snyk Organizations.

Repo Monitor Configuration provides the following capabilities:

  • Centralized asset monitoring: view monitoring status for all products, identify health status, and see required actions (such as enabling Snyk Code or resolving SCM integration issues) in one view.

  • Bulk import: import repositories directly from the Group Inventory page into specific Snyk Organizations.

  • On-demand retesting: trigger a retest for specific repositories directly from Inventory.

  • Actionable error resolution: clear guidance ia available when testing fails due to integration issues or entitlements. After the underlying issue is resolved, testing resumes automatically.

Nathan Hart | Senior Product Manager

Announcing Snyk CLI v1.1303.2

Fix

We have released a new CLI hotfix (v1.1303.2) to address the following:

  • Security Fixes

    • We have implemented a fix for a vulnerability identified in our underlying gRPC library

  • Snyk Open Source

    • Optimized Privilege Evaluation: Resolved a bug where the CLI repeatedly checked user feature flags when scanning multiple Go projects, resulting in smoother performance.

    • Enhanced PackageURL Handling: Fixed an issue where Go projects using a replace directive with relative paths would encounter formatting errors.

  • Snyk Container

    • Go Standard Library: This update introduces expanded support for the Go Standard Library within Snyk Container scans.

  • Snyk Evo (Agent Red Teaming)

    • Attack Profiles: Users can now leverage the --profile flag to choose from pre-configured attack goals, including fast, security, and safety profiles.

    • Improved Terminology: We have updated our internal naming conventions for goals, strategies, and attacks to provide a more intuitive user experience.

    • Improved Onboarding: Interactive wizard to guide users through Agent Red Teaming configuration and setup.

Release notes can be found here.

If you have any questions, please don’t hesitate to reach out to the Snyk support team.