Skip to main content

Product Updates

Engine
Surface
AI Workflows
Area
Release Status

Showing 61 - 70 of 445 updates

Closing the gap between code and runtime with SAST/DAST correlation

New

We're excited to introduce the first automatic solution for correlating static application security testing (SAST) and dynamic application security testing (DAST) findings. By connecting Snyk Code issues with Snyk API & Web results, we can now pinpoint the exact line of code responsible for a DAST vulnerability, helping you understand exactly where your code needs to be fixed and speed up your remediation process.

Vulnerabilities discovered during DAST can often be difficult and time-consuming for developers to locate within the source code. This update automates that manual search process. By using artificial intelligence to map runtime findings back to static code analysis, we're helping your teams reduce the mean time to remediate and focus on fixing issues rather than finding them.

In order to use our SAST/DAST correlation, you just need to link your Snyk API & Web targets to your Snyk Code projects and scan your API & Web targets the way you're used to. We'll do all the heavy lifting for you, and show you the corresponding SAST issue that matches our DAST finding, with the context and link directly to the code that needs to be fixed to mitigate the vulnerability.

Learn more about it here

Headshot of Ricardo Alves

Ricardo Alves | Director, Product Management

Analytics now available for groups and organizations

General availability

We’re expanding our analytics capabilities by making the analytics page available at the Group and Organization (Org) levels. Previously, this customizable view was only accessible at the tenant level. We've renamed the Reports page in the left navigation to Analytics at both the Group and Org levels. To access all reports, navigate to Analytics and select the Reports tab, which will display the Reports Catalog. We've also updated the URL path to use "analytics" instead of "reporting."

We want to provide Group and Org admins with a top-down, customizable view into their specific security data. By bringing the analytics page to every level of the hierarchy, we’re making it easier for you to gain insights without needing tenant-level access. This update allows you to build and customize dashboards that hone in on the specific metrics you care about, such as filtering by specific Orgs within a Group or tracking high-priority vulnerability trends across your immediate business units. This flexibility ensures you can focus on the risk data most relevant to your specific area of responsibility.

You can now build and view analytics dashboards tailored to your specific Group or Org. While we’ve removed the report selector dropdown, we’ve put redirects in place so your saved views and favorited pages continue to work. Under our current permission model, Group admins can view analytics for their specific group and all associated Orgs, while Org admins can focus on their individual Org data.

To learn more, visit Snyk Analytics in our user documentation.

Headshot of Sara Meadzinger

Sara Meadzinger | Staff Product Manager

Microsoft retires Azure global personal access tokens

Deprecated

Microsoft is phasing out global personal access tokens (PATs) and replacing them with more secure, scoped, and manageable credentials. These tokens currently grant access to every Azure organization that a user belongs to. You need to update your Azure Repos integrations with Snyk to organization-scoped tokens to maintain your connection.

Upcoming deadlines

  • March 15, 2026: Microsoft stops issuing new global personal access tokens.

  • December 1, 2026: Microsoft disables all existing global personal access tokens.

Update your connection

  1. Generate a new Personal Access Token (PAT) in Azure DevOps. Ensure the token is scoped specifically to the Azure Organizations you need. You can find guidance in the Microsoft documentation.

  2. Update the token at both the Groups level and the Organizations level.

    • Log in to Snyk.

    • Navigate to Group-level Integrations and find your Azure Repos integration settings. Create a single profile for each Azure organization and enter the new PAT. This is required for Asset discovery and enrichment.

    • Navigate to Org-level Integrations and find your Azure Repos integration settings. Clear the old token and enter the new PAT. This supports rest of the other Snyk features.

  3. If you are using a Snyk Broker, you will also need to follow the setup-specific documentation to set the PAT.

Read the Microsoft announcement for more information.

Headshot of Mayank Khera

Mayank Khera | Senior Product Manager

Merge with Confidence: Introducing Breakability Analysis for Pull Requests (Early Access)

Early access

We are excited to announce the Early Access launch of Breakability Analysis for Snyk Pull Requests, furthering our mission to help developers fix vulnerabilities without slowing down innovation.

We understand that the "fear of breaking the build" is a major blocker to keeping dependencies up to date. Updating a library to fix a security issue shouldn't feel like a gamble. That’s why we have introduced a new predictive risk assessment to help you distinguish between a quick fix and a complex upgrade.

Starting today via Snyk Preview, Snyk will analyze proposed dependency upgrades and assign a Breakability (Merge) Risk Score directly within the PR description:

  • 🟢 Low Risk (Safe to Merge): We have high confidence the upgrade contains only non-breaking changes (e.g., security patches or EOL runtime drops). These are strong candidates for auto-merging.

  • 🟡 Medium Risk: Caution is advised due to ambiguous change log data or environmental factors.

  • 🔴 High Risk (Action Required): We have identified likely breaking changes (e.g., API removals) that likely require code refactoring. These should be prioritized for a dedicated sprint.

This insight allows your team to burn down the backlog of "Low Risk" fixes quickly while preventing "High Risk" upgrades from silently breaking your builds.

This feature is available now in Early Access for supported ecosystems. You can enable it for your organization by navigating to Settings > Snyk Preview.

Read more about the assessment here.

Enjoy merging with confidence!

P.S. Please note that at this time, Breakability Analysis involves sending package information, including the current and proposed upgrade version, to an LLM. AI generated content may contain errors and should be reviewed for accuracy before use.

Tags:

Better risk mapping with OWASP Top 10 2025

Improved

We’re replacing the OWASP Top 10 (2021) report with the newly updated OWASP Top 10 (2025) report. This update ensures that your security reporting reflects the latest industry standards for web application risks. We’ve also resolved a bug where filters were not correctly applied when navigating from the report to the issue details page.

The Open Web Application Security Project (OWASP) updated their list of the ten most critical web application security risks in 2025. To help you maintain compliance and stay ahead of evolving threats, we’ve updated our reporting to map security issues to these current controls rather than the previous 2021 versions.

You can now view and filter security issues based on the frequency and severity cited in the 2025 OWASP rankings. To access this, navigate to Reports > OWASP Top 10 (2025). While the 2021 version of the report is no longer available in the dropdown menu, you can temporarily still access it via its direct URL if needed.

To learn more, visit OWASP Top 10 report in our user documentation.

Headshot of Sara Meadzinger

Sara Meadzinger | Staff Product Manager

Snyk Advisor insights are now part of security.snyk.io 🎉

Improved

We’ve completed the migration of Snyk Advisor into security.snyk.io, bringing package intelligence directly into the security experience.

Package pages now include Snyk Advisor insights alongside vulnerability data, providing a more complete and consistent view of open-source package health.

What’s new

  • Snyk Advisor metrics - Popularity, Maintenance, Security, and Community - now appear directly on package pages for supported ecosystems.

  • Package health insights can be explored without leaving security.snyk.io.

  • Advisor URLs now redirect to their corresponding package pages on security.snyk.io.

These updates make it easier to evaluate open source packages in context, supported by the same trusted data that powers Snyk Advisor.

To explore the updated experience, visit any package page on security.snyk.io. For more details, see Snyk Docs and the Blog post.


Headshot of Noa Yaffe-Ermoza

Noa Yaffe-Ermoza | Product Manager

Snyk Code - February 2026 Update

Improved

Snyk Code enhances analysis across multiple language ecosystems

We’ve updated Snyk Code to improve accuracy and coverage for many of the languages and frameworks you use. These enhancements help identify more true positive findings and remove false positives from your results, providing a more reliable view of your security posture.

Expanded language and framework support

The latest updates introduce support for several modern frameworks and libraries:

  • C# 14 and .NET 10: Analysis now includes the latest C# and .NET versions, which also covers VB.NET applications built on the .NET 10 framework.

  • Kotlin and Java: We improved support for Spring WebFlux and Jax-RS in Kotlin. We also added better coverage for grpc-spring based gRPC clients in both Java and Kotlin.

  • JavaScript and TypeScript: Snyk Code now supports the Sequelize library.

  • Go: We added support for the Fiber framework.

  • Swift: Analysis now includes the grpc-swift library for gRPC use cases.

These changes will be available as part of our general availability support for these ecosystems. You can see these improvements reflected in your scan results in the Web UI or CLI.

The changes will roll out on February 23, 2026.

To learn more, visit Snyk Code language and framework support in our user documentation.

Headshot of Sebastian Roth

Sebastian Roth | Senior Product Manager

Tags:

Blocking mode for Snyk API & Web CLI

Improved

We’ve introduced the follow-scan command to the Snyk API & Web (DAST) command-line interface (CLI) starting with version 0.0.1a15. This update allows the CLI to wait for a scan to finish before your CI/CD pipeline continues. We've also added new configuration options that let you set time limits for scans and define specific vulnerability thresholds that will automatically fail a build. After each run, we provide a direct link to your results for faster triaging.

You can now automatically block high-risk code from progressing through your CI/CD pipeline. By using the latest CLI version, you gain native control over build failures without needing to manage complex workarounds or manual checks.

To learn more, visit Snyk API & Web CLI documentation.

Headshot of Natalia Yurchenko

Natalia Yurchenko | Senior Product Manager

Announcing new versions of Snyk IDE plugins

New

We are pleased to announce the release of new stable versions for our IDE plugins.

The new versions are:

This release is focused on enhancing stability and reliability, with key updates including:

  • Automated Org Selection is now generally available: When enabled, Snyk will automatically select the most appropriate organization for your project based on context from your repository and your authentication. If an organization is configured manually, this feature will be overridden. If an appropriate organization cannot be identified automatically, the preferred organization defined in your web account settings will be used as a fallback.

  • New Unified Settings Page: We are rolling out a new unified design for our plugin settings across all our IDE plugins. Users can opt into this new experience early by following the instructions in the User Docs.

  • Risk Scores (Closed Beta): Customers in this closed beta will see a calculated risk score for Open Source issues in the issue details panel and will be able to filter issues by a risk score threshold, in conjunction with existing filters such as severity.

Note: For Visual Studio Code, new Settings will only appear after the application has been restarted.

Please refer to the changelog for each of our plugins for a more detailed list of additional bug fixes and enhancements. You can learn more about the Snyk IDE plugins in our Learn resources.

If you have any questions, feel free to reach out to the Snyk Support team.


Jeff Andersen | Director, Product Management

Tags: